Earlier quoted context omitted.
Yep, yep, and yep. I've said it enough to sound like a broken record: Transparency is a dependency of trust. If you can't see how it works, then it's objectively impossible to trust it to do the right thing. This applies to everything on a computer, really. Is your browser transparent? Is your operating system transparent? What about the drivers? Device firmware? That "security" solution that unexpectedly ushered in…
> Transparency is a dependency of trust. I think you go too far here. Trust is a dynamic spectrum, not binary. Transparency is one potential avenue to add trust, but is neither necessary nor sufficient in most cases. Every instance must be evaluated in light of its specific details, threat scenarios, and available tradeoffs. > If you can't see how it works, then it's objectively impossible to trust it to do the right…
For someone like me, who is somewhat technically competent, but not a security expert, openness means that names and figures I do trust have the chance to examine whatever I intend to use and comment on it, observe it, and make assessments, including shaming poor implementations claiming traits they have no right to. Turns out there are plenty of people more competent than me that can catch these things.
Transparency also allows less hiding of incompetency in otherwise commercial and/or proprietary designs.