View Single Post
Posts: 2,076 | Thanked: 3,268 times | Joined on Feb 2011
#338
Originally Posted by MartinK View Post
You don't know much about security, do you ? ;-)

(hint: Most security critical algorithms and libraries are public & open source and a target of a very strict pear review. Closed source components, which can't be reviewed in a similar way, are often considered untrusted by default.)
pear review...
yeah, problem is NSA has a hundred hackers to throw at it the instant it drops, peer review and audit can be performed with GRU help before dropping to the public, want to make those holes available to NSA first?

edit: just to be clear, not promoting security through obscurity, but open sourcing is not a remedy, you need to pay people to make proper audit (see truecrypt audit funding), NSA already has such people and they pay them monthly. Closed source can be secure, most banks use MS solutions and somehow it works, but yeah, once they open source go at it and find all the bugs

Last edited by szopin; 2015-07-01 at 11:07.