Menu

Is it safe to use plugins without source code?

Shisui
2021-08-30
2021-08-30
  • Shisui

    Shisui - 2021-08-30

    I am using WinKee and the experience is great, but I noticed that the author did not provide the source code?
    I am not an expert in this area, I am curious if it is safe?

     
  • Paul

    Paul - 2021-08-30

    Not having source code does not make anything either safe or unsafe.

    The source code is available from the same location as the plug-in.
    https://keepass.info/plugins.html#winkee

    cheers, Paul

     
    👍
    1
    • Shisui

      Shisui - 2021-08-30

      Thank you very much for your answers.
      Usually plug-ins are open source on GitHub, obviously I ignored the link directly provided by the author.

       
  • Rookiestyle

    Rookiestyle - 2021-08-30

    Just as food for thoughts...

    Access to the source code makes a plugin more secure if

    1. You can review the source code and check for security leaks or malicious code
    2. You build the plugin yourself using the source code
      "You" in this case means "You personally or a trusted entity like yur well-trusted best friend or wisdom of the crowd"

    Only seeing the source code and not being ble to check it isn't a big security gain.
    Not building the plugin yourself using the checked source code isn't a big security gain either.

    In both cases you essentially trust that the provided source code is secure and that this provided source code actually was used to build the plugin which essentially means: Either you trust the author or you don't

     
    👍
    1

Log in to post a comment.

MongoDB Logo MongoDB