this post was submitted on 03 Sep 2025
112 points (91.2% liked)

Ask Lemmy

34471 readers
1830 users here now

A Fediverse community for open-ended, thought provoking questions


Rules: (interactive)


1) Be nice and; have funDoxxing, trolling, sealioning, racism, and toxicity are not welcomed in AskLemmy. Remember what your mother said: if you can't say something nice, don't say anything at all. In addition, the site-wide Lemmy.world terms of service also apply here. Please familiarize yourself with them


2) All posts must end with a '?'This is sort of like Jeopardy. Please phrase all post titles in the form of a proper question ending with ?


3) No spamPlease do not flood the community with nonsense. Actual suspected spammers will be banned on site. No astroturfing.


4) NSFW is okay, within reasonJust remember to tag posts with either a content warning or a [NSFW] tag. Overtly sexual posts are not allowed, please direct them to either !asklemmyafterdark@lemmy.world or !asklemmynsfw@lemmynsfw.com. NSFW comments should be restricted to posts tagged [NSFW].


5) This is not a support community.
It is not a place for 'how do I?', type questions. If you have any questions regarding the site itself or would like to report a community, please direct them to Lemmy.world Support or email info@lemmy.world. For other questions check our partnered communities list, or use the search function.


6) No US Politics.
Please don't post about current US Politics. If you need to do this, try !politicaldiscussion@lemmy.world or !askusa@discuss.online


Reminder: The terms of service apply here too.

Partnered Communities:

Tech Support

No Stupid Questions

You Should Know

Reddit

Jokes

Ask Ouija


Logo design credit goes to: tubbadu


founded 2 years ago
MODERATORS
 

"Trust" as in: trust it enough to run it on your machine.

(And assuming that you can't understand code yourself)

top 50 comments
sorted by: hot top controversial new old
[–] pastermil@sh.itjust.works 20 points 1 week ago (1 children)

I know you do.

Well, you're here, aren't you?

[–] DeathByBigSad@sh.itjust.works 8 points 6 days ago (1 children)

Tbf, accessing a a software running on some server (which is not my machine) over Tor isn't exactly the same as, say, installing a software with admin privileges on my computer.

[–] pastermil@sh.itjust.works 7 points 6 days ago

True that...

Then lemme try to give the answer you were asking for.

Let's start with Linux. The kernel itself has hundreds, if not thousands, of contributors. Next there's the pieces of software that run on it, each with its own set of contributors.

There's no way you can do anything meaningful by going thru this huge list just to see what their political backgrounds are. I'm sure there are controversial people contributing to the very pieces you are running right now.

Even if you did find some problematic backgrounds, what are you gonna do anyway? Stop using it? Do you think it would affect them? It's not like you're paying them. On the contrary, you're probably just gonna make your life harder.

[–] MrQuallzin@lemmy.world 14 points 6 days ago

Who's out here trying to figure out the political or other beliefs of developers? I've got around 50 docker containers running on my server, there's no way I'm going through people's profiles to see if they're morally aligned with me.

[–] zxqwas@lemmy.world 18 points 6 days ago

Depends on the software. I'd not trust a vpn that was made in an authoritarian state. I'll play a game made in one.

As for the developer if they are more famous for their political views than the software I'd probably not install it.

[–] HubertManne@piefed.social 16 points 6 days ago (1 children)

Really depends on the level of disagreement. If its total idiocy like maga or monarchist or something I would likely stay away. If they don't think ubi is a good idea I can get passed that.

[–] BlameThePeacock@lemmy.ca 8 points 6 days ago (1 children)
[–] HubertManne@piefed.social 11 points 6 days ago

no um I mean like I can't get the political philosophy passed to me so like I would drop it and not run to the goal line and..... ok I did it wrong.

[–] Witchfire@lemmy.world 15 points 6 days ago (1 children)

No. If I disagree with someone politically it's likely because they want me and anyone like me dead. Those people are dead to me.

[–] pressanykeynow@lemmy.world 2 points 6 days ago (2 children)

I'm pretty sure we'll disagree politically on many issues but I don't want you or anyone like you dead. I hope people in the US will stop viewing politics as cults and start to communicate with people disagreeing with them.

For the first 40+ years of my life, sure. For the past 10...we are suffering from a cult.

[–] Witchfire@lemmy.world 2 points 6 days ago* (last edited 6 days ago) (1 children)

Do you support trans rights? Do you support immigration? Do you support the demilitarization of police and complete restructuring of the current US "justice" system? Do you know why credit scores exist? Do you support using taxes to provide for our most vulnerable? Do you know what diversity, equity, and inclusion are?

If you said no to any of those, then I doubt we share common ground

load more comments (1 replies)
[–] chicken@lemmy.dbzer0.com 10 points 6 days ago

Yes, since not liking or disagreeing with someone isn't the same thing as likelihood they are pushing malicious code. If something is open source that's a really good sign, because they could also push closed source code and be more likely to get away with it that way. More points if it clearly has other eyes on it; even if I am not checking over the code myself, someone probably is for a lot of projects.

It's like "separate art from artist" except even more so because software tends to be even more quantifiable as its own independent thing than art is.

[–] HeyThisIsntTheYMCA@lemmy.world 11 points 6 days ago

it depends on what the software is doing i guess

[–] RushLana@lemmy.blahaj.zone 8 points 6 days ago

Most of the time : Yes

But it depends on a lot of things :

Is there any viable alternatives ? What's the nature of the disagreement ? Is there a possibility of a fork emerging ? Etc...

I hate google but I can't replace Android studio at work or ask my employer to stop releasing updates on google play. If the disagreement is about project governance, I would support forking, see CoMaps or Forgejo. I will avoid projects for a variety of reason, two good examples are Manjaro and Hyperland, I avoid the former because of their collaboration politics and the later because they are plain bigots.

Politics can encompass a lot of thing and open source is a very political subject.

[–] mrgoosmoos@lemmy.ca 6 points 6 days ago

if it is open source and sources I trust approve of it, sure

[–] GreenKnight23@lemmy.world 6 points 6 days ago (1 children)

no.

IMO conservatives are untrustworthy and can't identify fact from fiction.

would you run software from a dev who has a problem discerning reality? do you think a schizophrenic person writes stable maintainable code?

mental health is an important part of gaining trust in your product. ironic that they continue to trust and support a geriatric nazi-wannabe, but goes to show how compromised conservatives are when it comes to their decision making skills.

[–] doofy77@aussie.zone 2 points 6 days ago (1 children)
[–] GreenKnight23@lemmy.world 1 points 6 days ago

technically the guy went crazy because of the project.

[–] sturmblast@lemmy.world 5 points 6 days ago

it depends entirely on the context, what the software is, alternatives... etc

[–] Lumisal@lemmy.world 4 points 6 days ago

Only if they specifically seem fascist, because that's the one political group that likes to know everything you do and censor any dissenting opinion.

[–] ArsonButCute@lemmy.dbzer0.com 4 points 6 days ago* (last edited 6 days ago)

I mean... I used reiserFS for years and that guy killed his wife, I'm not too keen on that.

I guess its fine as long as its not actively malicious code, its not like I'm letting them into my brain.

On that though, I find it unlikely someone who differs from me politically would have the same priorities, and as such their projects are much less likely to show up on my radar.

Edit: spelling correction, Autocorrupt, ykwim?

[–] Knock_Knock_Lemmy_In@lemmy.world 5 points 6 days ago (1 children)

https://en.wikipedia.org/wiki/ReiserFS

Reiser was convicted of the first-degree murder of his wife, Nina Reiser

load more comments (1 replies)
[–] mesamunefire@piefed.social 5 points 6 days ago

There's such different views on life that I don't think its possible to get software designed close to what you or I believe in.

If the source is open, the code is viewable. So yes I think I can trust, at least the code.

Also there's a saying "trust but verify". So actually check to see if the binaries your getting actually behave the way you think.

[–] benni@lemmy.world 3 points 6 days ago

I'd see it as a seal of quality if the developer is a crank.

[–] Montreal_Metro@lemmy.ca 2 points 6 days ago

No. Fuck that guy.

[–] rikudou 2 points 6 days ago

I can't really apply "you don't understand the code yourself" because I do.

So I do check the code if it's something critical, but otherwise don't bother. For example the Lemmy server I'm running I didn't really check much because it can't really do any harm to me.

But if I was running Lemmy somewhere on my home network, I'd either isolate it or thoroughly check it (but probably just isolate it from the rest of the network and put it in a VM, nobody's got the time to read other people's source code).

Since you're asking specifically for "on my machine" I usually put stuff I don't fully trust in a VM.

for me, it generally boils down to "show me the work, then i decide".

some works are more influenced by politics like art pieces and written works. some, like architecture, plumbing and network stacks, much less so.

in this case, even if you don't know code but can be a good appraiser of political taint then you can decide on your own what to endorse or not.

[–] viking@infosec.pub 1 points 6 days ago

I trust the Lemmy developers enough to use their platform hosted on external servers despite them being Marxist clowns, but I wouldn't self host without a thorough code review.

And I'm seriously just waiting for a decent piefed app in order to ditch the platform altogether. So far voyager is the most functionally complete one, but doesn't look very appealing.

load more comments
view more: next ›