Hacker News new | past | comments | ask | show | jobs | submit login

How can we know there's no backdoor in it?



I don’t think it’s a bad question and don’t see why this is being downvoted.

Security can only scale via one’s network, and if you don’t have any it can be hard to figure out what’s secure and what’s not!

FWIW a little googling and you can see that filippo is pretty well known in the security/crypto community for positive contributions, same goes on for tqbf who’s all over this thread endorsing the tool.

I would also trust the thing without looking at it, but I might take a look at the code someday to see what’s going on :)


It seems you can read the source code?


It's OSS?


Yeah. So all you need is a 10+ year experience in crypto algorithms and weeks of close inspection of the code to verify it!


Sooo you need to trust someone that does have that experience to do the verification. What alternative are you suggesting? Is there some cool way to write your crypto so that a layman can successfully verify the integrity of a binary?


> What alternative are you suggesting?

One solution might be if some big corporation or even a government, or why not Bill Gates himself, offered a big ongoing bug-bounty for this Open Source Software.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: