Same with aviation software.
Anything that deals with public safety should be audited by the public.
Same with aviation software.
Anything that deals with public safety should be audited by the public.
General folks and even most devs do not have the skills to audit code.
I think if you release code related to important everyday things like cars, everyone who is able will want to take a look. And you never know who will think outside the box and stumble across something they can then escalate and investigate with other people who are more capable. It happens in open source all the time.
> Everyone who is able will want to take a look.
This is not true. Auditing is very skill intensive and time intensive. There needs to be compensation for it either direct (you pay for professional auditors) or indirect (you're an academic and you get reputation and grants for breaking WPA3, SGX, Mega or SIKE, or fame for breaking the PS3).
You can easily get in a situation with "The Emperor has no clothes" where everyone thought open-source code must have been audited by someone because it's open, when in fact no one did because they didn't care or had no incentives.
The knowledge nowadays is spread.
In a library used on billions of devices.
What about projects used by 10~50 people?
I'm going to trust more a project peer reviewed by the best devs on the planets compared to some homebrew homemade software where the devs allegedly know better than everybody else (and they don't)
My argument is that open-source is not enough when high-assurance is needed and devs or end-user should still ask for a professional audits.
We're not in the 90s anymore and it's time to acknowledge that the software world and even the world in general has changed. Knowledge is now spread and the most knowledgeable devs aren't working at an audit firm and might not even hold a computer degree!
Peers aren't enough. Finding vulnerabilities require training and an adversarial mindset that is rare.
There is a reason why in cryptography people say "don't roll your own crypto"
Whenever the output of software is offered as evidence against you in court, you should be entitled to the source code of the software.
Maybe it should be like Copyright or patents, you can keep things private for a while for an advantage, but then you would need to release all code as open source / public domain or similar? It should also be available before that to be reviewed by professionals following a formal process of some sort.
Yes.
I can't wait.