When were the apps code last checked? #99
-
Forgive me if this is a silly question, I've little expertise in these things. I used SimpleMobileTools apps for years, they were streets ahead of the competition, and, like others, I was disappointed to find they'd been sold, then delighted to find them back in the open source realm (thanks so much!). Given that my trust in the project was, to say the least, a little damaged by the sale - has anyone checked the code since the transfer? I know that the security of open source is pretty much dependant on good people such as yourselves all keeping an eye on the code to make sure it has nothing untoward in it, and non-code-savvy users such as myself have to just trust you. I had no problem with that trust until recently... Having the main author happily sell the user-base, I'm now far less trusting that his code is safe, and I don't have the skills to check it myself. So basically, I wanted to start that trust process again with the new team. Do you vouch for this code in these versions, it's not just blindly copied from the old versions assuming it's fine, have people checked the privacy claims previously made for these apps are actually sound? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 13 replies
-
I don't know if any full audit of the code has been done, but from what I know:
|
Beta Was this translation helpful? Give feedback.
-
Private and Secure are two different things. Private: I have worked with pretty much all the SMT apps and I can say with some confidence that all the apps are safe to use from a privacy perspective. You don't need to worry about your personal data being stolen or worse. All Fossify apps still don't have any access to the internet as you can verify here so they can't send any data even if a piece of code wanted to. This might change if we decide to add support for RCS but even then, we won't be tracking users or selling data. Secure: I would say not having the internet permission reduces the attack surface considerably and if there are any vulnerabilities or back doors in any of the apps released by Fossify, I can assure you it is not intentional. By the way, there's a fun poll about this by Broadie Robertson: https://www.youtube.com/post/UgkxbSSrd1b1FV59p-Ry6jcaCaTAVD07Odrk |
Beta Was this translation helpful? Give feedback.
Private and Secure are two different things.
Private: I have worked with pretty much all the SMT apps and I can say with some confidence that all the apps are safe to use from a privacy perspective. You don't need to worry about your personal data being stolen or worse. All Fossify apps still don't have any access to the internet as you can verify here so they can't send any data even if a piece of code wanted to. This might change if we decide to add support for RCS but even then, we won't be tracking users or selling data.
Secure: I would say not having the internet permission reduces the attack surface considerably and if there are any vulnerabilities or back doors in any of the apps r…