I'm sure Vivaldi has no intentions of becoming "evil" like Google, but because of its closed source nature it wouldn't be hard to slip a tracker or two in the browser and regular users would be none the wiser.
I'm sure Vivaldi has no intentions of becoming "evil" like Google, but because of its closed source nature it wouldn't be hard to slip a tracker or two in the browser and regular users would be none the wiser.
If you want a truly open source modern browser, the only options are chromium or firefox these days, AFAIK ? (If you know an alternative I'm interested !)
On Android I can recommend Lightning: https://github.com/anthonycr/Lightning-Browser
As for other modern open-source browsers, http://otter-browser.org/ is still in relatively early development AFAIK, but sort of like Vivaldi, it's trying to recreate Opera 12.
The latter, so-called copyleft-licenses, actively prevent someone from adding closed-source code to the open-source code-base or to relicense the entire code under a less strict license.
Vivaldi's license does not. They could start shipping non-readable code at any point.
I don't trust people who are more code-savvy than I am (that's most people) not to insert or exploit weaknesses in open-source software or other open code. With closed-source software, I know the origin point of the software I install, I know the names of the individuals or teams who developed it, and therefore I know who stands behind it, because their reputation is based on that released software working. If something goes wrong, I can take clear action because I know who is to blame, e.g. Vivaldi, Microsoft, etc. With open-source software, that liability for the software developer is thus offloaded to "the community", and users have no viable recourse - meaning that attacks on open-source software are a lot safer for the individual attacker.
I support 100% closed-source development and extended release schedules. Open source & rapid development / release scares the daylights out of me. Too many people can see it, too many people can make changes, and it's happening way too fast.
Closed Source:
- Team behind it could add trackers, backdoors, etc that are difficult to detect.
- Attackers could find an exploit that will go unnoticed and unfixed for an indeterminable length of time. Or perhaps use the team's own aforementioned exploits/backdoors.
- Can't tell if their app is well-tested and well-written, which means it could be a buggy hot mess from the get-go. Which is the most common reason for hiding source from my anecdotal experience.
Open Source:
- Much easier for anyone to find a bug, including attackers. You'd hope the maintainers/community will find the bug before them, or at least take less time to fix it than if it were closed-source.
- Attackers could add their own exploit that will go unnoticed or unfixed for an indeterminable length of time.
I think the conclusion to draw from is:
Closed Source = less likely for attackers to find bugs, but more likely for bugs to persist. Can only trust in the company's reputation for code quality.
Open Source = more likely for attackers to find bugs, but less likely for bugs to persist. Don't need to trust the company's reputation for code quality.
But you need to trust the entire community not to insert bugs/backdoors and/or weed out such code. Not to mention Open Source contributors arguably have a lesser incentive than closed-source development being done by a company.
Ofc the above argument assumes contributors are allowed to make changes to the codebase, instead of just reviewing the code
That's why not everyone has commit access* (for both open and closed source projects) and there's always* a code review performed by independent peers. This neither protects you from accidental security issues nor highly obfuscated malicious exploits (only sufficient skills of the reviewer does), but that holds true to both open and closed source projects. For the former, the "indeterminable length of time" until exploits are found may be much shorter than for closed source projects due to increased eyeballing for large projects.
* Let's ignore those who ignore common sense. If you care about the security of the software you use, you want the developer(s) to follow basic rules of software development. And you can even verify that in open source projects without needing to know how to code. For closed source projects you can't, you can only trust the company to do so. How's that different to trusting the skills of the open source developers?
That applies to closed-source software as well. With (popular) open-source software, on the other hand, you can be confident that "people who are more code-savvy than you are" can examine the code for inserted weaknesses. Existing vulnerabilities can and with be exploited if there's an incentive to so so, regardless of whether or not the source is available.
> With closed-source software, I know the origin point of the software I install, I know the names of the individuals or teams who developed it
That seems like the exception, rather than the rule. Consider browsers, for example. I can see exactly which people have commit access on the open-source Firefox or Chromium projects. When it comes to a closed-source browser such as Microsoft Edge, on the other hand, I only know that "the Edge team" develops it. I have absolutely no idea who is currently on this team, or the quality of any individual member's work.
> and therefore I know who stands behind it, because their reputation is based on that released software working
This doesn't mean that closed-source software is intrinsically less vulnerable than open-source software. Microsoft's reputation may be based on Windows working, but that didn't stop WannaCry - nor will it stop future exploits.
> If something goes wrong, I can take clear action because I know who is to blame, e.g. Vivaldi, Microsoft, etc.
Realistically speaking, what action can you take, besides switching to other software?
> With open-source software, that liability for the software developer is thus offloaded to "the community"
You're conflating open-source software with software developed solely by the community. Many open-source projects, such as Chromium, Firefox, and Linux, do have specific organizations that are either involved or responsible for their development. Closed-source software only gives you an opaque team or organization to blame, while open-source software can give you a specific commit - diff, date, and author.
> Too many people can see it
Direct access to the code may make finding vulnerabilities easier, but as shown by the number of security vulnerabilities in well-known and well-funded closed-source projects (Windows, iOS, etc), it will not stop determined attackers from finding and exploiting them.
> too many people can make changes How many is "too many"? If you're referring to the number of people with commit access, then you're almost never be able to know that number for closed-source software. If you're referring to the number of contributors, then it's not much different from trusting the core development team in the first place. Regardless of where the code originally comes from, you're trusting the maintainers to be able to recognize bad and/or vulnerable code, whether done accidentally or maliciously.
> and it's happening way too fast
Do you have a specific project or projects in mind here? This seems very similar to the issue of "too many people can make changes" - you can only make an informed guess, at best, as to the development rate of closed-source software. Unlike open-source software, you can never know exactly how many changes went into a particular release.
But to be honest, as soon as such company would go public, get major funding from one of the big companies, or get a new, famous CEO - run away.
Haha yeah, as opposed to close source, where no one spots it. Or if they do, you have no idea whether it ever gets fixed or not. Not exactly a better alternative.