Don't get me wrong, an audit will always be an even better situation either in FOSS or proprietary case
This is correct but my opinion is that if the user base is large enough there are people out there who are expert enough on the topic to spot the issues. On the other side of the coin, there are hackers out there trying their hardest to find a flaw so I assume the "white hat"(good) ones are doing the opposite. Then again, this is what I think,
Not a correct analogy since corporate accounting books are not public information. I do not see Apple putting out how much they pay each employee, or how much it costs to build an iphone, or how much they spent on toilet paper. Even if they did you can't affirm the numbers by going back to the corporate and checking the ins and outs of their bank accounts.
They do not put that information out in public, do they?
agreed, in Bitwarden's case specifically they do but There are others who I wouldn't trust as much like KeePass since its much more obscure although they claim they have their own recommendations from official sources.
I can't comment on the contributors of the code I am just assuming among the community there are people skilled enough to look and criticise the code, kind of like when an architect puts a house plan online there are other architects out there who can see it and criticise it or if pharmaceutical published a formula for a medication there are chemists and doctors among us that can comment on that.
Especially when it comes to software there are a lot of coders who are "foss warriors" like FSF and all the people working on LibreOffice, GIMP, FireFox, Linux distros, Blender, Fossdroid, GrapheneOS...list goes on. I do not assume that all those people have no idea what they are doing.
I would rather trust an audit then assume someone in the community would spot a vulnerability.
This is correct but my opinion is that if the user base is large enough there are people out there who are expert enough on the topic to spot the issues. On the other side of the coin, there are hackers out there trying their hardest to find a flaw so I assume the "white hat"(good) ones are doing the opposite. Then again, this is what I think,
There's a reason why corporate finances are audited, as some people could simply say, corporations have a community of people over seeing the finances and don't need an independent evaluation.
Not a correct analogy since corporate accounting books are not public information. I do not see Apple putting out how much they pay each employee, or how much it costs to build an iphone, or how much they spent on toilet paper. Even if they did you can't affirm the numbers by going back to the corporate and checking the ins and outs of their bank accounts.
They do not put that information out in public, do they?
I think password managers, and privacy minded companies that provide services are in a better position if they decide to have their work audited - that's just me.
agreed, in Bitwarden's case specifically they do but There are others who I wouldn't trust as much like KeePass since its much more obscure although they claim they have their own recommendations from official sources.
I disagree in the case of security software like the password managers we're discussing.
Earlier in this thread I reported that I reviewed the work by those contributors. Most of it was of a trivial nature. I didn't find a single pull request related to deeper cryptography issues. I admit that I only looked for 15 minutes or so.
Take a look at https://bucket.agilebits.com/securi...ssword_8_for_Mac_Security_Assessment_v1.1.pdf. It makes it clear that very specialized skills are required to do the kind of security audit that is justified. I don't doubt Bitwarden has employees with such skills. But, an independent audit is really needed. It's way easier to catch mistakes when you're not the one making them.
I can't comment on the contributors of the code I am just assuming among the community there are people skilled enough to look and criticise the code, kind of like when an architect puts a house plan online there are other architects out there who can see it and criticise it or if pharmaceutical published a formula for a medication there are chemists and doctors among us that can comment on that.
Especially when it comes to software there are a lot of coders who are "foss warriors" like FSF and all the people working on LibreOffice, GIMP, FireFox, Linux distros, Blender, Fossdroid, GrapheneOS...list goes on. I do not assume that all those people have no idea what they are doing.