• simone@lemmy.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      2 days ago

      Open source software you don’t code review and build yourself can also contain spyware.

      • TerHu@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        10
        ·
        edit-2
        2 days ago

        while it can, there probably is some arch user who runs the program too and notices it suddenly takes 2ms longer to do something thusly finding the xz attack.

        so, yeah foss isn’t inherently safe, but most probably saf er

        • simone@lemmy.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 days ago

          Projects that have lots of attention and assuming you always compile from source. But someone could easily distribute a binary that is different than the source.

          People should do frequent audits, especially network traffic. I had this one file manager that was kinda like Midnight Commander. Someone on a forum said “check out me app” etc. immediately on launch it made network requests…… why? Anyway, definitely don’t use that for long!!

      • TerHu@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 days ago

        no, he’s right in some way. claude desktop is spyware, but it only spies through chromium based browsers, so if you don’t use chrome, you’re safe … for now. until they install their backdoor in safari/ firefox based browsers too

        • prenatal_confusion@feddit.org
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 days ago

          No, not really solved. The problem is still Claude trying to install spyware and by extension the user that is trying to install Claude.