Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Security professionals tend to care about open source over closed source much less than many other factors.

Things that seem more important^:

- Well known and vetted data structures/algorithms etc

- Vulnerability history

- Large install base

- well regarded, well funded security team vetting the project

- capacity and history of fighting expensive legal battles on behalf of its users.

Its possible that there are android phones that meet these criteria but there are many that do not. The iphone on the other hand does. So rather than having very specific android phone recommendations its generally easier to just say use iPhone. So much so that most of the security professionals I've talked to view it as the most secure, commonly available computing platform period.

^Not a security professional, but I drink with a couple.



I see. I think there might be some distinction in regards of what different people view as "secure". Say, your phone produced by my company may be completely transparent to me and completely impenetrable to, say, tptacek. As I understand, in that narrative it is considered secure as you (the user) are supposed to trust me (the manufacturer). That's why iPhone is considered secure in comparison to Android, which is similarly backdoored, but in addition more penetrable to tptacek (the 3rd party).

Correct?


No. Closed source binaries are not impenetrable to researchers. For a security audit you have to study the binary in any case so open source is a bonus not a requirement.


I didn't imply otherwise. I'm just wondering how it is iPhone is considered secure when it is happily sharing your data with Apple. Or doesn't it?


It's only sharing stuff with Apple if you allow it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: