• booksEnglish
    arrow-up
    7
    arrow-down
    1
    ·
    8 months ago
    link
    fedilink

    Point a has always me me wonder, is that accurate? Are there actually people going through the code to make sure open source isn’t malicious? I can barely read my coworkers code Let alone a strangers.

    • xorEnglish
      arrow-up
      6
      arrow-down
      0
      ·
      8 months ago
      link
      fedilink

      people are definitely going through the code on a project as popular as audacity
      less well known stuff is much less scrutinized, of course

    • aidanEnglish
      arrow-up
      3
      arrow-down
      0
      ·
      8 months ago
      link
      fedilink

      Its way less work than going through the code to check for telemetry unless it is an intentionally hidden attack- just use Wireshark and check if there is network traffic other than checking for an update on program start.

    • lemmeeeEnglish
      arrow-up
      2
      arrow-down
      0
      ·
      8 months ago
      link
      fedilink

      If a project is popular people will make changes to it every day. But you can look at the repo and judge for yourself.