Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or as I like to put it, at the end of the day you have to trust someone, somewhere in the chain.

In the case of software vendors, you have to trust the vendor.

You cannot independently verify everything. You do not have the expertise nor the bandwidth.

Edit: and if you have the software audited, are you not then trusting the auditor?



I don't like this argument. It's not necessarily you who has to audit your software. You can pay other people to do it. Big companies can pay for it. Your government's institutions can pay for it. If on the other hand the software is closed-source, then that's not an option. And especially for governments and for big companies Windows is a security liability.


True, but there's no logical fallacy in writing off companies and products if they're consistently untrustworthy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: