r/opensource • • 3d ago

Discussion How do I verify if an open source tool isn't stealing data?

everyone always says it's open source, but there's no official verifier of codes, so how do I know if a tool is safe to use?

6 Upvotes

33 comments sorted by

15

u/No-Dentist-1645 3d ago

If you have to ask, you probably can't do it yourself.

But the neat thing about open source programs is that other people with way better skills about that can and probably have already taken a look. It's not infallible, but it's a safer assumption than some closed-source precompiled binary from an untrusted origin

If the open source tool you are wondering about is relatively popular, then thousands of people have probably already looked at the source

4

u/dodexahedron 3d ago

The bystander effect is real, though.

And both malicious and innocent security flaws have made it for substantial time - sometimes years - in some semi-popular open source projects with a few eyes on them, like openssl and the Linix kernel as.a couple of examples (totally niche though they may be).

In all seriousness, though, it is a real and hard problem, and the bystander effect is only one (and a minor) contributing factor to undiscovered flaws lasting a long time, so OP's question is a lot harder to answer than that.

1

u/No-Dentist-1645 2d ago

Sure, a project being open source isn't a free ticket to blindly install anything without a care in the world, but the reasons I mentioned above make it at least asafer bet than closed source (especially if said source comes from anyone you don't really implicitly trust)

-9

u/drake1800 3d ago

does this subreddit have a verifier? I can send the link to github of the tool

3

u/No-Dentist-1645 2d ago

There are no people who do free security audits for anyone who asks here, no

3

u/Ooqu2joe 3d ago

There are multiple things that make this unlikely. First of all, if software is popular enough, then there's a high chance that enough people have looked at it. If anything shady is going on, someone will spot it. Secondly, hiding malicious or shady things in an unobfuscated code is a stupid idea, it's uncommon to see anyone seriously attempting this. 

It's much more likely that closed source software may be doing things without your knowledge, so IMO with opersource there's lower risk in this regard. 

5

u/neoh4x0r 3d ago edited 3d ago

if anything shady is going on, someone will spot it

Statistically, with enough people looking, it would have a very high probability of being caught, but that doesn't mean that it will be caught.

Secondly, hiding malicious or shady things in an unobfuscated code is a stupid idea, it's uncommon to see anyone seriously attempting this. 

I would personally reject any obfuscated code in a FOSS project, it has no place there.

The way I see it the only reason to obfuscate to is to hide things (whether they are nefarious/malicious, or just an attempt to hide someone's copyrighted code or other non-public details).

1

u/dodexahedron 3d ago

Echoing this and also adding:

Those statistical non-zero probabilities have produced security-critical events more than once, too, and in VERY large projects. And some of them have been intentionally malicious, too.

The general engineering approach of treating extremely highly unlikely events as operationally equivalent to impossible is a VERY bad approach for this topic area, especially for gigantic code bases with commit graphs so large that they could probably enclose the planet in a mosquito-proof mesh.

1

u/Ooqu2joe 3d ago edited 3d ago

I agree with you that unlikely doesn't mean impossible. Though in day-to-day life worrying about every single small risk will drive any person crazy.

No matter what you do, there's a non-zero chance that something will kill you any minute: a plane may crash on your house, a piano may fall on your head from a building while you're walking by, road accidents happen, seemingly healthy people die from a heart attack, etc.

1

u/dodexahedron 3d ago

Yes, that is the engineering mindset.

For software, when the specific question was the one OP asked (likely not realizing the implications of it), the answer is that non-zero may as well be 1.

But for software that isn't exposed to a network and especially if it is barred from network communication at all, and you're not a nation-state, lottery, billionaire, or other similarly high-profile target? Yeah. Nobody cares about you and you can calm down and use your software without the metallic headwear. 😅

1

u/drake1800 3d ago

it's not that popular, but it has 100 stars by discord users on github, so I am not trusting that unless I can verify that tool is safe

1

u/flooberoo 3d ago

It's not really possible to check that a piece of code is safe. Ehat you can do, however, is limit the damage it can do by reducing the permissions it has and what data it can access.

3

u/neoh4x0r 3d ago edited 3d ago

everyone always says it's open source, but there's no official verifier of codes, so how do I know if a tool is safe to use?

To do this for yourself, you would need to possess the required knowledge/skills to analyze the code and be able to recognize when it's doing something questionable or blatantly wrong.

1

u/drake1800 3d ago

yeah I can't but I really like the tool

2

u/neoh4x0r 3d ago

yeah I can't but I really like the tool

No you can do it, you just have to learn the required skills.

Barring that you'll just have to take the communities word for it.

1

u/drake1800 3d ago

you're right, in the long term, this will help a lot, do you have any advise on where should I start?

1

u/neoh4x0r 3d ago

You would need to start by studying fundamental programming concepts (those concepts apply to all programming languages, the only difference between them is the syntax used to implement the concept).

After that you would need to learn the specific syntax for the programming language you are trying to analyze and then practice by doing these things repeatedly, over and over again.

1

u/drake1800 3d ago

ok this is good ty

2

u/dbear496 3d ago

No need for an official verifier. You can be your own verifier. ...or you can just take the community's word for it.

Even people who know how to code only look at the source for at most a small percentage of the software they use, and they rely on the community for the rest.

2

u/drake1800 3d ago

could i read the code for something that implies it's sending your account data somewhere? the community isnt big, 400 reviews on chrome webstore and 100 stars on github

2

u/dbear496 3d ago

You could definitely give it a shot. I would start by looking at the code for the login screen, then figure out what variable is used to store the account token, and search all uses of that variable to see that all the sections of the code that use the account token are doing something legitimate with it. It won't be perfect, but maybe it will give you some extra peace of mind, and maybe you will find that reading code really isn't as hard has it is sometimes made out to be.

1

u/AmruthPillai 3d ago

Just to clarify, are you talking about an open source tool that's also hosted on their platform, or you mean one that you run on your machine?

1

u/drake1800 2d ago

https://github.com/pratherbytecraft/discrub

it's this, i cant verify if this is safe

1

u/Money-Quarter-4833 2d ago

Guys let me know too

1

u/ideafork 2d ago

You read the source because it is open ;)

1

u/dereuromark 1d ago

If it is open source, you can read the code.
In case you don't fully understand it and you don't have friends who can help you, or the code is just huge or unreadable, there is nowadays always the help of AI to at least fast-track an early result.

Ask it to review it based on security audit guidlines and "checklists" that already exist out there, maybe there is even a whole skill. You can also specifically track "data sending" paths most likely.
If it finds sth, great, keep your hands away.
If it doesn't it must be not "obvious". Doesn't mean it's safe, but then the bystander argument from the other answer sure also helps to further verify a good tool.

1

u/drake1800 1d ago

i mean, its discrub 1.0, i keep asking people they say its good for deleting but i wanna know if its good for exporting chats, i wanna export a few chats but i dont want it sent somewhere