At 16:51 4/20/2001, Nick Andriash wrote:
>On April 20, 2001, at 5:16:17 AM, Robert Guerra wrote:
>
> > the thing is..do we know for certain that the code will be
> > published..and if so, will there be people who will actually have the
> > time to check that nothing mysterious exists..
>
>That to me encapsulates the entire argument about whether one bases their
>trust on open source, or on the Developement Team. As you mention, who
>will actually have the time... and expertise to check the source... and
>when they report... do we believe them? What are their credentials? Why
>would we believe or trust them over NAI?
simple, have an independent 3rd party audit/code review done. use three
teams, take a 2/3rds majority vote on everything.
>Nick
>
> ________________________________________________________
> -=N.J. Andriash | Vancouver, B.C. Canada=-
> PGP-Basics List Moderator | PGP Key ID: 0x7BA3FDCE
>GnuPG v1.0.4-2 (MingW32) | TB! v1.52 Beta 1 | Win98 SE
> ________________________________________________________
=====================================================================
Sean Rooney;
President and Chief Technical Officer
ColdStream Associates Ltd.
"Just when you learned that IT wasn't safe;"
www.coldstream.ca
416-516-8998
416-374-8823
======================================================================