Earlier quoted context omitted.
Whichever story you are talking about, this one or the guardian one, it doesn't address the closed-source point. There is theoretically a way to verify WhatsApp even though it's closed source, but it's practically impossible. It's hard enough to verify software even when the source is open, you built it yourself and the whole platform and toolchain is trusted. A bunch of the potential NSA crypto backdoors were totall…
I'm sorry, but this simply isn't true. Software of far, far greater complexity than WhatsApp has been reverse engineered comprehensively by hobbyists and amateurs. Meanwhile, professionals have pretty sophisticated tools for doing this work at scale.
(Almost always) when someone mentions the 'impossibility of analysis' of closed-source programs they are actually referring to the difficulty in doing so -- not actually stating that it's impossible.
It is easier to look through source code.
Now, if we're progressing through this conversation according to script, it will be mentioned that open source projects have had tremendous security problems, too. (OpenSSL comes to mind..)
But that's beside the point expressed.
The only point, and it's the point that was originally expressed, is that open source code is easier to look through than a closed code base.
The hurdles posed by closed source, although not impossible to jump, significantly hinder the progress of analysis.
Is this not true?