But what proof do we have that they're running their servers correctly? They have a LOT less to lose from server intrusions than Apple.
Don't get me wrong, Standard Note looks nice - but you have to trust them that they're doing everything right on the back end ..... pretty much the SAME as Apple. Seems a little eyebrow raising to me to trust a small no-name company with this over something like Apple.
And I can program - I have for many years. Despite this I've never actually opened open source source code to verify stuff (and I've used a fair number of Open Sourcecode applications).
Just me.I'd trust the company that has a lot more to lose. Or, none (local only).
I heard this arguemnet before that there is no way you can confirm the software on the server, but I also heard it is possible. IDK. To answer your question:
Has Standard Notes completed a third-party security audit?
We've completed four (4) security audits to date by industry-leading security firms, which cover the entirety of our ecosystem. You can review the results below. * SERVER BACKEND PENETRATION TEST AND SECURITY ASSESSMENT — 2022 This audit covered our server applications and services...

-
You are right about not trusting the small and obscure guys but here is the current situation:-
* I trust community and smaller project that are popular between the privacy conscience crowd + FOSS. I do pick and choose based on popularity of the product and how much its trusted by others and general media.
* Big tech does not care about your privacy. In fact they tell it in your face in their privacy policy that they will collect and share information so they do not get tangled in lawsuits. Privacy breaching big techs are making more money than ever (Meta, Google, TikTok, Uber, Alexa, Microsoft) . They even have been sent to court and paid fines, they still don't care.
Apple shared customer data with US government in a record-high 90% of cases, even as Trump administration complains it's not doing enough
While I am not asking Apple to break the law, if they had chosen to encrypt the information of their users, even handing the information over would be useless because the encrypted information are nearly uncrackable. Thats what Proton.me does!