I am using WinKee and the experience is great, but I noticed that the author did not provide the source code?
I am not an expert in this area, I am curious if it is safe?
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
Access to the source code makes a plugin more secure if
You can review the source code and check for security leaks or malicious code
You build the plugin yourself using the source code
"You" in this case means "You personally or a trusted entity like yur well-trusted best friend or wisdom of the crowd"
Only seeing the source code and not being ble to check it isn't a big security gain.
Not building the plugin yourself using the checked source code isn't a big security gain either.
In both cases you essentially trust that the provided source code is secure and that this provided source code actually was used to build the plugin which essentially means: Either you trust the author or you don't
👍
1
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
I am using WinKee and the experience is great, but I noticed that the author did not provide the source code?
I am not an expert in this area, I am curious if it is safe?
Not having source code does not make anything either safe or unsafe.
The source code is available from the same location as the plug-in.
https://keepass.info/plugins.html#winkee
cheers, Paul
Thank you very much for your answers.
Usually plug-ins are open source on GitHub, obviously I ignored the link directly provided by the author.
Just as food for thoughts...
Access to the source code makes a plugin more secure if
"You" in this case means "You personally or a trusted entity like yur well-trusted best friend or wisdom of the crowd"
Only seeing the source code and not being ble to check it isn't a big security gain.
Not building the plugin yourself using the checked source code isn't a big security gain either.
In both cases you essentially trust that the provided source code is secure and that this provided source code actually was used to build the plugin which essentially means: Either you trust the author or you don't