Ungoogled-chromium: Code Audits?

Created on 2 Feb 2020  路  2Comments  路  Source: Eloston/ungoogled-chromium

Is your feature request related to a problem? Please describe.
I really like the idea of this project, and really want to make this my primary browser. The developer has done some really great work. However, how do I know that there is no malicious code being inserted by the developer? I can't really trust it to do things like my online banking.

Describe the solution you'd like
Make a company out of this project. There is more than enough demand (I think). This could be like the chromium equivalent of Firefox. Rely on donations to generate revenue. Once you establish a company, you will build your credibility and hopefully can have external 3rd parties audit the code changes you are making.

Describe alternatives you've considered
Blindly trusting the dev.

Additional context

discussion

Most helpful comment

This is issue is fundamentally about trust. In that case, I don't know if creating a company would actually help solve the trust issue, even though they could help us get code audits. Perhaps a non-profit organization or even some donation system would be better, as those also show a bigger commitment/responsibility.

I wanted to chime in on this. I think that forming some sort of organization going forward is going to be the next major step for the whole idea of an Ungoogled Chromium browser, regardless of who is developing it. Right now, we're relying on a bunch of insiders coming together on a insider Git repo to build an insider build of Google Chrome. We're way too loose and too few in numbers. Having an organization would not only serve as a rally point for organizing devs behind the cause, but it could also strengthen the project enough so it becomes a successor to Google Chrome. Basically like starting the next Mozilla but instead of Netscape we're using Chromium.

My only caveat is that I would like to see it USA, CAN, or EU based. There's too much riff raff coming from CHN and RUS lately, so incorporating in those parts of the world would be a bad idea for Western adoption.

All 2 comments

A few things:

  • I agree that code audits are good, because they get more people to look critically through the code, which helps attract more people to the project. However, I don't think code audits are the only way to build trust, or even the best way to build trust for a project that is constantly changing (because Chromium is constantly evolving).
  • This is issue is fundamentally about trust. In that case, I don't know if creating a company would actually help solve the trust issue, even though they could help us get code audits. Perhaps a non-profit organization or even some donation system would be better, as those also show a bigger commitment/responsibility.

This is issue is fundamentally about trust. In that case, I don't know if creating a company would actually help solve the trust issue, even though they could help us get code audits. Perhaps a non-profit organization or even some donation system would be better, as those also show a bigger commitment/responsibility.

I wanted to chime in on this. I think that forming some sort of organization going forward is going to be the next major step for the whole idea of an Ungoogled Chromium browser, regardless of who is developing it. Right now, we're relying on a bunch of insiders coming together on a insider Git repo to build an insider build of Google Chrome. We're way too loose and too few in numbers. Having an organization would not only serve as a rally point for organizing devs behind the cause, but it could also strengthen the project enough so it becomes a successor to Google Chrome. Basically like starting the next Mozilla but instead of Netscape we're using Chromium.

My only caveat is that I would like to see it USA, CAN, or EU based. There's too much riff raff coming from CHN and RUS lately, so incorporating in those parts of the world would be a bad idea for Western adoption.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Chilcout picture Chilcout  路  3Comments

Eloston picture Eloston  路  4Comments

tonowoe picture tonowoe  路  3Comments

usernamenotexist picture usernamenotexist  路  4Comments

lipici picture lipici  路  3Comments