Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You have no evidence that they do either, so you can't trust them.


Trust by definition is not evidence-based. Even if it were "open source", you would have no proof that the actual production code was the open source version. I understand and even subscribe to the default attitude of lack of trust, but it is not an actionable attitude when it comes to the web and saas.


> Even if it were "open source", you would have no proof that the actual production code was the open source version.

There are ways to prove that. You can provide reproducible builds, where someone who builds the software will end up with bit-for-bit identical binaries to the production version. Then, anyone can verify that the available binary matches the available source.


One could argue that trust is only relevant when evidence is absent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: