Browser, handling so much important stuff, being closed source is a bit of... just no.
Browser, handling so much important stuff, being closed source is a bit of... just no.
Something being open source doesn't automatically mean it is secure. On the other hand, any software running on your pc requires you to put trust in the developers. I think it would be easier to just setup monitoring (like preventing outgoing traffic or identifying DNS lookups etc) and limiting permissions on what particular software can do, be it black or white box. White box of course allows running some analyzers, but... do any non-contributors actually do it?
I remember seeing some tool here, don't remember - was it Microsoft made or what? That scanned the code and tried to identify what accesses software makes.
I can already hear some of you starting to type a rant about how this actually is a C problem and not something that would happen in a modern language like ${YOUR_FAVORITE_LANGUAGE:-rust}; and to an extent it is true that C is especially vulnerable to this particular vector of attack, but like it or not a lot of open source software if it isn't written in C, depends on libraries that are. This includes the Linux kernel, OpenSSL, cURL. WebKit is written in C++ which might as well be C for the sake of this discussion. Other languages have other attack vectors, like the fractal-like dependency tree of NPM for example, something that has been demonstrated time and time again to be more than a hypothetical security risk.