It's a nice way to alleviate the barrier to monetization that open-source-as-security poses. In short, instead of having lamdba user trusting 'the community' for security audits, now each user has to implement security measures.
This leaves users holding the bag. Well, it should work for you but remains subpar.
In my experience "the community" cannot be trusted for security audits, as far as most FLOSS goes. In fact if a program can be "made secure" by yourself just by firewalling it properly, I'd be more inclined to trust that measure over any FLOSS community audit.
Having said that, the idea of running software I mistrust so much that I haveto firewall it on my network is unacceptable.
Comments
It's a nice way to alleviate the barrier to monetization that open-source-as-security poses. In short, instead of having lamdba user trusting 'the community' for security audits, now each user has to implement security measures.
This leaves users holding the bag. Well, it should work for you but remains subpar.
Congrats nonetheless.
In my experience "the community" cannot be trusted for security audits, as far as most FLOSS goes. In fact if a program can be "made secure" by yourself just by firewalling it properly, I'd be more inclined to trust that measure over any FLOSS community audit.
Having said that, the idea of running software I mistrust so much that I have to firewall it on my network is unacceptable.
I agree wrt security-through-community and its weaknesses. And indeed turning your guns inwards seems like the wrong move.