97
Is Stremio a honeypot?
(sopuli.xyz)
1. Posts must be related to the discussion of digital piracy
2. Don't request invites, trade, sell, or self-promote
3. Don't request or link to specific pirated titles, including DMs
4. Don't submit low-quality posts, be entitled, or harass others
📜 c/Piracy Wiki (Community Edition):
FUCK ADOBE!
Torrenting/P2P:
Gaming:
💰 Please help cover server costs.
![]() |
![]() |
---|---|
Ko-fi | Liberapay |
Is every open source app audited? Look at the XZ near disaster. And XZ is pretty critical software. Open source doesn't mean it's safe by default, it means that the code can be read.
The XZ topic was way more complicated than that and overly exaggerated by some people. Open source is still the closest thing we have to "safe by default".
Still, as someone else stated, if you're not hosting it's not truly open source as you can't really verify the actual code running behind the server.
IMO the XZ thing shows the strength of open source, some turbo pedant found the backdoor within about an hour of it being released because a program took 0.3 seconds longer to start. That wouldn't be possible in a closed source app that can't be debugged properly.
Yeah, but usually with open-source software you get like 150 Github comments complaining and outlining their shady business practices... If there's something to complain about.
The XZ disaster is an example for sth else. There are probably more backdoors in proprietary software that we just don't know about. And they can just keep it hidden away and force the manufacturers to do so. No elaborate social engineering like in the XZ case needed... And no software is safe. They all have bugs and most of them depend on third-party libraries. That has nothing to do with being open or closed source. If so, being open provides you with more of a chance to catch mischievous behaviour. At least generally speaking. There will be exceptions to this rule.