| ▲ | Panzerschrek 6 hours ago | |
> Not all user processes upload those files somewhere surreptitiously. Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable. | ||
| ▲ | yjftsjthsd-h 5 hours ago | parent | next [-] | |
No, that kind of audit is neither necessary nor sufficient. (A firewall works without application source code, and trusting trust means we can hand wave anything even with source.) | ||
| ▲ | g-b-r 6 hours ago | parent | prev [-] | |
Ok, at least if it has network access, but can you recognize that this was a vulnerability, and that you're talking of something only tangential to it? | ||