• 0 Posts
  • 83 Comments
Joined 3 years ago
cake
Cake day: June 12th, 2023

help-circle














  • The idea you’re getting at is ‘security by obscurity’, which in general is not well regarded. Having secret code does not imply you have secure code.

    But I think you’re right on a broader level, that people get too comfortable assuming that something is open source, therefore it’s safe.

    In theory you can go look at the code for the foss you use. In practice, most of us assume someone has, and we just click download or tell the package manager to install. The old adage is “With enough eyes, all bugs are shallow”. And I think that probably holds, but the problem is many of the eyes aren’t looking at anything. Having the right to view the source code doesn’t imply enough people are, or even meaningfully can. (And I’m as guilty of being lax and incapable as anyone, not looking down my nose here.)

    In practice, when security flaws are found in oss, word travels pretty fast. But I’m sure more are out there than we realize.






  • My parents weren’t very restrictive. But one time, to get me to stop asking for a new game, my Dad said I couldn’t get any new ones until I beat the last game I got.

    I think about that a lot still. I think it would have been a good rule, outside of some edge cases like games that were endless or too easy.

    But it was off the cuff, he didn’t remember saying it. By the time I finished some game and brought it up, I think he said something like “well don’t you have other games you never finished?”