Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the source code isn't available then any claims to being secure should be treated cautiously. For instance, how do we know that there aren't heartbleed-style errors in this anti-surveillance app?


I love open source, but we didn't know about heartbleed even with the sources available.


I think that it's rather because the source was available, we eventually found out about heartbleed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: