"When he reached the New World, Cortezh burned hish ships. Ash a reshult hish men were well motivated." —Capt. Ramius, played by Sean Connery in The Hunt for Red October
True. It is plausible. At the same time I have to think that if the human race hasn't evolved to factor cooperation in tribes in most cases, we wouldn't be here discussing this.
Some of the trust comes from eyes on the project thanks to it being open source. This thing got discovered, after all. Not right away, sure, but before it spread everywhere. Same question of trust applies to commercial software too.
Ideally, PR reviews help with this but smaller projects esp with few contributors may not do much of that. I doubt anyone has spent time understanding the software supply chain (SSC) attack surface of their product but that seems like a good next step. Someone needs to write a tool that scans the SSC repos and flags certain measures like the # of maintainers.
PS: I have the worst allergies I've had in ages today and my brain is in a histamine fog so maybe I shouldn't be trying to think about this stuff right now lol cough uuugh blows nose
I get where you're coming from but is he managing his risk or not?
Does he understand the risk? If yes, good. No? Bad.
Is he ignoring the risk? If yes, bad. No? Good.
Is he weighing the risks against the benefits he receives of using these apps and taking appropriate steps to mitigate those risks? If yes, then good. No? Bad.
Cyber security isn't "lock everything down at all costs". Otherwise I would insist you throw your phone in an incinerator along with all your computers, live in a bunker reinforced against nuclear attack with a small army to guard you, never leave it, never talk to anyone... Etc.
It is enabling one to achieve their goals with a tolerable amount of risk. That level of tolerable risk is different for everyone.
"When he reached the New World, Cortezh burned hish ships. Ash a reshult hish men were well motivated." —Capt. Ramius, played by Sean Connery in The Hunt for Red October