> I'd rather they open up the entire OS and software though. People need to know this is secure and not just trust someone, again
With open source software, too, you have to trust someone. In this case this someone is the people who review it. Of course it's always possible to check the source code yourself, but I doubt that most people would invest the time to audit a codebase that has been worked on for two years or more, by several developers. And even if they invest the time, chances are that weaknesses are overlooked (see, for example, Cryptocat). And even if the source code does exactly what is claimed to do, how do you know that the compiler works correctly? Does the machine code really correspond exactly to the source code?
It always comes down to trusting _some
one_. With open-sourced software, that person is usually "someone on the internet". With Plug, you have to trust the people who produce it. It is their business interest to provide a relatively secure product, and from kickstarter they got a lot of resources to put into this.
I for one would rather trust a company with a financial interest in providing a secure product, than a couple of volunteers who are in it for other reasons.
With open source software, too, you have to trust someone. In this case this someone is the people who review it. Of course it's always possible to check the source code yourself, but I doubt that most people would invest the time to audit a codebase that has been worked on for two years or more, by several developers. And even if they invest the time, chances are that weaknesses are overlooked (see, for example, Cryptocat). And even if the source code does exactly what is claimed to do, how do you know that the compiler works correctly? Does the machine code really correspond exactly to the source code?
It always comes down to trusting _some one_. With open-sourced software, that person is usually "someone on the internet". With Plug, you have to trust the people who produce it. It is their business interest to provide a relatively secure product, and from kickstarter they got a lot of resources to put into this.
I for one would rather trust a company with a financial interest in providing a secure product, than a couple of volunteers who are in it for other reasons.
Edit: Grammar