- Is being open source, and some eager and independent security researchers having done an audit enough to convince you (or some other well-informed part on the thread) that no clever flaws are intentionally in the source?
- Do the funding or institutions which support the development of a piece of tech change the answer to the above question? E.g. I've been encouraged to avoid Signal b/c it was created partly with US State Dept funding (via the Open Technology Fund). The main point made during that conversation was that the US supports projects like Signal and Tor as a means of supporting dissidents in other countries. But a side implication was that it may be naive to rely on tools (indirectly) provided by the state to avoid surveillance by the state.