Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Ask Lemmy
  3. Would you trust an open source software maintained by a developer who you disagree with politically (or otherwise don't like the developer)?

Would you trust an open source software maintained by a developer who you disagree with politically (or otherwise don't like the developer)?

Scheduled Pinned Locked Moved Ask Lemmy
asklemmy
110 Posts 82 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M [email protected]

    Oh I would not trust software from a developer who does not understand the importance of MFA.

    I mean, there's probably nothing wrong with it, but that's such a basic security issue that I would have zero faith they built the rest right.

    rikudou@lemmings.worldR This user is from outside of this forum
    rikudou@lemmings.worldR This user is from outside of this forum
    [email protected]
    wrote last edited by
    #70

    Well, its importance is IMO overblown. MFA as it's usually implemented:

    • sms
    • email
    • TOTP

    Sms and email are not really secure and TOTP is basically just a second password except you don't use it directly, but use numbers derived from the password.

    The more secure alternatives (hardware keys) are really uncommon even among tech people, let alone the general population.

    Not saying I think it's useless, I use MFA everywhere (because two passwords are better than one) but all in all it's much less secure than people assume.

    _ 1 Reply Last reply
    1
    • A [email protected]

      'Open source' is a deliberately ambiguous phrase, engineered to derail libre software.

      rikudou@lemmings.worldR This user is from outside of this forum
      rikudou@lemmings.worldR This user is from outside of this forum
      [email protected]
      wrote last edited by
      #71

      It's not, it's a term that means very specific things. Most people don't even know that, but both free software and open source are not some catch all phrases. And in fact they don't even mean the same thing.

      You can for example have an open source software that's not free software. The reverse is harder, but IIRC I've seen some license that would qualify (it's been years, maybe I'm misremembering cause I can't find it anymore).

      A 1 Reply Last reply
      0
      • D [email protected]

        Tbf, accessing a a software running on some server (which is not my machine) over Tor isn't exactly the same as, say, installing a software with admin privileges on my computer.

        P This user is from outside of this forum
        P This user is from outside of this forum
        [email protected]
        wrote last edited by
        #72

        True that...

        Then lemme try to give the answer you were asking for.

        Let's start with Linux. The kernel itself has hundreds, if not thousands, of contributors. Next there's the pieces of software that run on it, each with its own set of contributors.

        There's no way you can do anything meaningful by going thru this huge list just to see what their political backgrounds are. I'm sure there are controversial people contributing to the very pieces you are running right now.

        Even if you did find some problematic backgrounds, what are you gonna do anyway? Stop using it? Do you think it would affect them? It's not like you're paying them. On the contrary, you're probably just gonna make your life harder.

        1 Reply Last reply
        4
        • E [email protected]

          You always have to trust others. If a key person can not be trusted anymore, the option to constantly check the code is not really an option.

          T This user is from outside of this forum
          T This user is from outside of this forum
          [email protected]
          wrote last edited by
          #73

          Ref. the famous Ken Thompson hack. At some point you're forced to trust someone.

          1 Reply Last reply
          1
          • D [email protected]

            "Trust" as in: trust it enough to run it on your machine.

            (And assuming that you can't understand code yourself)

            H This user is from outside of this forum
            H This user is from outside of this forum
            [email protected]
            wrote last edited by
            #74

            Really depends on the level of disagreement. If its total idiocy like maga or monarchist or something I would likely stay away. If they don't think ubi is a good idea I can get passed that.

            B 1 Reply Last reply
            11
            • H [email protected]

              Really depends on the level of disagreement. If its total idiocy like maga or monarchist or something I would likely stay away. If they don't think ubi is a good idea I can get passed that.

              B This user is from outside of this forum
              B This user is from outside of this forum
              [email protected]
              wrote last edited by
              #75

              past, not passed

              H 1 Reply Last reply
              5
              • B [email protected]

                past, not passed

                H This user is from outside of this forum
                H This user is from outside of this forum
                [email protected]
                wrote last edited by
                #76

                no um I mean like I can't get the political philosophy passed to me so like I would drop it and not run to the goal line and..... ok I did it wrong.

                1 Reply Last reply
                9
                • D [email protected]

                  "Trust" as in: trust it enough to run it on your machine.

                  (And assuming that you can't understand code yourself)

                  M This user is from outside of this forum
                  M This user is from outside of this forum
                  [email protected]
                  wrote last edited by
                  #77

                  No. Fuck that guy.

                  1 Reply Last reply
                  2
                  • M [email protected]

                    Honest question. How?

                    Proton Mail is built in a way that makes that near impossible.

                    blurb@sh.itjust.worksB This user is from outside of this forum
                    blurb@sh.itjust.worksB This user is from outside of this forum
                    [email protected]
                    wrote last edited by
                    #78

                    What makes you say that? Any e-mail provider can intercept and read any e-mail they want to. This explanation by cock.li is pretty good on this issue:

                    How can I trust you? You can't. Cock.li doesn't read or scan your e-mail content in any way, but it's possible for any e-mail provider to read your e-mail, so you'll just have to take our word for it. No "encrypted e-mail" provider is preventing this: even if they encrypt incoming mail before storing it, the provider still receives the e-mail in plaintext first, meaning you're only protected if you assume no one was reading or copying the e-mail as it came in. When possible, you should use X.509 or GPG with your mail correspondents to encrypt your message content and prevent it from ever being handled in plaintext on our servers. You should also download and delete your mail from our servers regularly, which alone is almost as good as encrypting your mail.

                    1 Reply Last reply
                    1
                    • O [email protected]

                      I used to feel this way but I need more nuance now.

                      If I had a global (or national, or statewide, or even citywide) platform of any kind, and there were momentous things happening in the world that I felt were wrong, and that I felt needed more awareness, how could I not use my platform?

                      I used to be so sick of celebrities with their political statements until one day that hit me. How could you, in good conscience (and this is true even of opinions I don't agree with) find yourself with millions of people willing to listen to you, how could you not use your platform if you feel strongly enough that there is a moral or ethical obligation to speak up?

                      L This user is from outside of this forum
                      L This user is from outside of this forum
                      [email protected]
                      wrote last edited by
                      #79

                      It's a matter of trust, I can't trust magats to be competent.

                      O 1 Reply Last reply
                      0
                      • D [email protected]

                        "Trust" as in: trust it enough to run it on your machine.

                        (And assuming that you can't understand code yourself)

                        rushlana@lemmy.blahaj.zoneR This user is from outside of this forum
                        rushlana@lemmy.blahaj.zoneR This user is from outside of this forum
                        [email protected]
                        wrote last edited by
                        #80

                        Most of the time : Yes

                        But it depends on a lot of things :

                        Is there any viable alternatives ?
                        What's the nature of the disagreement ?
                        Is there a possibility of a fork emerging ?
                        Etc...

                        I hate google but I can't replace Android studio at work or ask my employer to stop releasing updates on google play.
                        If the disagreement is about project governance, I would support forking, see CoMaps or Forgejo.
                        I will avoid projects for a variety of reason, two good examples are Manjaro and Hyperland, I avoid the former because of their collaboration politics and the later because they are plain bigots.

                        Politics can encompass a lot of thing and open source is a very political subject.

                        1 Reply Last reply
                        1
                        • D [email protected]

                          "Trust" as in: trust it enough to run it on your machine.

                          (And assuming that you can't understand code yourself)

                          witchfire@lemmy.worldW This user is from outside of this forum
                          witchfire@lemmy.worldW This user is from outside of this forum
                          [email protected]
                          wrote last edited by
                          #81

                          No. If I disagree with someone politically it's likely because they want me and anyone like me dead. Those people are dead to me.

                          P 1 Reply Last reply
                          12
                          • D [email protected]

                            "Trust" as in: trust it enough to run it on your machine.

                            (And assuming that you can't understand code yourself)

                            K This user is from outside of this forum
                            K This user is from outside of this forum
                            [email protected]
                            wrote last edited by
                            #82

                            https://en.wikipedia.org/wiki/ReiserFS

                            Reiser was convicted of the first-degree murder of his wife, Nina Reiser

                            1 Reply Last reply
                            2
                            • L [email protected]

                              It's a matter of trust, I can't trust magats to be competent.

                              O This user is from outside of this forum
                              O This user is from outside of this forum
                              [email protected]
                              wrote last edited by
                              #83

                              You might have replied to the wrong guy. I really didn't touch on that.

                              1 Reply Last reply
                              0
                              • M [email protected]

                                If it was state funded by a functioning state I would agree with you, but I wouldn't be surprised if Russia was kicking these guys a modest living to undermine American social media companies.

                                I mean, I got banned personally by Dessalines from lemmy.ml for mildly suggesting that a meme felt like it was a Chinese op designed to provoke in-fighting in western countries.

                                Not rudely, not aggressively, literally just questioning whether it could be in the comments below.

                                G This user is from outside of this forum
                                G This user is from outside of this forum
                                [email protected]
                                wrote last edited by
                                #84

                                Tbh, I think most people just don't understand that Lemmy is where all the quote un quote "tankies" that got banned or felt disenfranchised with reddit ended up in. They truly believe in whatever they are saying. Some of these people tend to be pro China and or even Russia, AND are real people who actually believe in their ideology and what they are saying, and aren't just foreign agents. As for undermining American social media companies? Tiktok is already one of the most popular social media sites out there.

                                1 Reply Last reply
                                1
                                • D [email protected]

                                  "Trust" as in: trust it enough to run it on your machine.

                                  (And assuming that you can't understand code yourself)

                                  heythisisnttheymca@lemmy.worldH This user is from outside of this forum
                                  heythisisnttheymca@lemmy.worldH This user is from outside of this forum
                                  [email protected]
                                  wrote last edited by
                                  #85

                                  it depends on what the software is doing i guess

                                  1 Reply Last reply
                                  6
                                  • wreckedcarzz@lemmy.worldW This user is from outside of this forum
                                    wreckedcarzz@lemmy.worldW This user is from outside of this forum
                                    [email protected]
                                    wrote last edited by
                                    #86

                                    That's basically my understanding, I thought there was another layer to it that I wasn't aware of. I wouldn't say 'avoid' but I would say 'caution' to others, currently.

                                    I am planning to try mulvad at the end of my proton vpn subscription, which is the only proton service I use (+ a dead mailbox too, just in case I forgot a site when transferring out a few years ago). I run my own vpn through a vps, but for stuff that I need full disassociation I'll still fire up proton, for now. 3y subs and all that.

                                    1 Reply Last reply
                                    1
                                    • D [email protected]

                                      "Trust" as in: trust it enough to run it on your machine.

                                      (And assuming that you can't understand code yourself)

                                      B This user is from outside of this forum
                                      B This user is from outside of this forum
                                      [email protected]
                                      wrote last edited by
                                      #87

                                      I'd see it as a seal of quality if the developer is a crank.

                                      1 Reply Last reply
                                      1
                                      • quill7513@slrpnk.netQ [email protected]

                                        i'm so excited about the progress piefed is making and my home instance's plans to migrate

                                        S This user is from outside of this forum
                                        S This user is from outside of this forum
                                        [email protected]
                                        wrote last edited by
                                        #88

                                        Wait. How similar is piefed to Lemmy? Does Voyager work with it?

                                        quill7513@slrpnk.netQ M 2 Replies Last reply
                                        2
                                        • S [email protected]

                                          Wait. How similar is piefed to Lemmy? Does Voyager work with it?

                                          quill7513@slrpnk.netQ This user is from outside of this forum
                                          quill7513@slrpnk.netQ This user is from outside of this forum
                                          [email protected]
                                          wrote last edited by
                                          #89

                                          extremely similar with some serious quality of life improvements and better dev leadership. the api, per my understanding, is similar to lemmy, but not wholly compatible. voyager, i do not think, does not support piefed currently (i will need to switch apps)

                                          1 Reply Last reply
                                          2
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups