Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Agreed. I would not consider running a closed source shell because it's not auditable.


Yeah, I've worried about this a lot. Perhaps there's someone I could hire to give hucksh a clean bill of health. I wonder how much Bruce Schneier would charge? :) (That's a joke; I'm confident that, even if he'd do it, I couldn't afford him. But something like that is what I'm thinking of.)

Googling "security audit my code" finds several companies that offer such a service. My concern would be (aside from the admittedly non-trivial benefit of just having better code), would it make a difference to anybody that was on the fence about it? I suspect that the matrix of "potential customers" vs "what auditing service they'd trust" is large.

Thank you for the comment.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: