top | item 5838928

(no title)

anonyfuss | 12 years ago

Most people never review source code, and they certainly don't disassemble and review all the binaries. 'Many eyes' is a security fallacy in cases like this.

discuss

order

steveklabnik|12 years ago

Tails is ridiculously well known; if something was bad in it, it would be big news.

mseebach|12 years ago

If it was found. Which is the point.

Debian, which is much better known and in much wider circulation than Tails generated weak SSH keys for two years. Yes, it was indeed very big news. When it was found. After two years.

Oh, and tin-foil-hat on: Do we know (actually know-know, not just assume, think, trust) that the weakness wasn't planted there?