842
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 16 Mar 2026
842 points (99.0% liked)
Open Source
45475 readers
853 users here now
All about open source! Feel free to ask questions, and share news, and interesting stuff!
Useful Links
- Open Source Initiative
- Free Software Foundation
- Electronic Frontier Foundation
- Software Freedom Conservancy
- It's FOSS
- Android FOSS Apps Megathread
Rules
- Posts must be relevant to the open source ideology
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
- !libre_culture@lemmy.ml
- !libre_software@lemmy.ml
- !libre_hardware@lemmy.ml
- !linux@lemmy.ml
- !technology@lemmy.ml
Community icon from opensource.org, but we are not affiliated with them.
founded 6 years ago
MODERATORS
How do you know that your OS installation doesn't include malware? Like there have been many cases in the last few years where
npmmodules were found to contain malware. Who says that's not also the case in some modules that are a part of your OS?And more importantly, who is legally liable if malware actually does cause harm? E.g. malware acts on your behalf and sends your money to some criminal organization. Not only did you lose money, but now you're a suspect of supporting a criminal organization!
Of course that issue might be alleviated if you simply don't have any money to send anywhere in the first place. That might be a viable alternative, but it only works for some people, i'd say. Or you could also set a daily transaction limit of say $100 that you can use to buy groceries; to limit your losses that way. The limit ofc cannot be changed from your phone alone, you need to go to a bank physically to change it or sth. Otherwise malware could again change it on your behalf.
One possible way to deal with this and very nearly return to the former freedom-to-tinker status quo is to send the bank your custom OS along with a computer-checkable formal proof that the bank's app, while running on your OS, behaves as it would be expected to under the stock OS. With homomorphic encryption, it might be possible to do this without revealing your custom OS, only its one-way hash. The bank can then verify that the proof is correct and then accept transactions with attestation from your custom OS. This would enable installing a custom ROM that can be used for online banking without having to go through some cabal/consortium. The only caveat is something of this magnitude has never been done before. It's a research project for sure. It would take many man- and compute-hours. But it would be very cool.
And who guarantees that your PC doesn't have malware?
Seriously, people will gobble up all the shit served to them without a question asked or giving it a second thought.
Microsoft is legally responsible if the software they provide is found to actually contain malware.
You don't understand what you're talking about. You've made that very clear twice now.