Re: How regularly is the GnuPG source code examined?

Crypto_at_S.M.S
Date: 09/27/05


Date: Wed, 28 Sep 2005 06:09:12 +1000

tomstdenis@gmail.com wrote:

>
> As far as I know no open source project has EVER gone through a proper
> verification cycle. In many cases this is ok because a bug or failure
> is not harmful, just annoying. But in the case of cryptography it can
> be a nightmare.
>
> Tom
>

When you say "no open source project has EVER gone through a proper
verification cycle", do you mean that the source code was not really
inspected by the authors' peers? Isn't this the reason why some think
that open source is so important? If nobody really audits the source
code, how does distributing it help make the system more secure?

Just because somebody *could* have looked at it doesn't mean they did.



Relevant Pages

  • Re: Open Source quality better then closed?
    ... If I know something is going into an open source project, ... trivia is time spent not fixing important things. ... find that your open source work looks very different than your closed ...
    (comp.lang.java.programmer)
  • Re: AccHelp future development - discussion please
    ... You can view Open Source as a kind of meritocracy, ... Any Open Source project must have an owner who is ultimately ... subcomponents of the project to group leaders, who do the bulk of the ...
    (comp.databases.ms-access)
  • General advice for starting a new open source project
    ... I am thinking of starting a new open source project using PHP/MySQL to ... other applications such as Turbo Lister, Warehouse control systems, ... install packages, use of DEFINE files etc., upgrade packages when users ...
    (php.general)
  • Re: What is Forth best at?
    ... open source ... Do the Ogg Vorbis interfaces suck? ... you find fault with a specific open source project that all open source ... example want a function to compress/decompress a buffer. ...
    (comp.lang.forth)
  • Re: How regularly is the GnuPG source code examined?
    ... > When you say "no open source project has EVER gone through a proper ... > verification cycle", do you mean that the source code was not really ... how does distributing it help make the system more secure? ...
    (sci.crypt)