• drosophila@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    1
    ·
    16 days ago

    I trust a random internet stranger that in theory is doing their work in public

    There’s no ‘in theory’ about it.

    I’ve actually had an extension I was using be revealed as spyware (it was hoverzoom, I immediately switched to an alternative afterward).

    I don’t read every line of every piece of software I use because that would be impossible, but I do actually look at some of it and modify it to suit my needs. It was because there are many thousands of people like me that do this that the problem in hoverzoom was caught. It’s been ten years, so I don’t have the best memory of the event, but I think it only took a few days to catch it as well, despite the fact that the offending code was left out of the GitHub repo and was only in the compiled extension.

    The state of open source isn’t perfect (not everything has reproducible builds yet) but in general I ‘trust’ that every other programmer in existence isn’t in on a conspiracy to screw me over specifically.