# Security-wise: closed-source tech giant app vs FOSS of a single developer

**URL:** https://discuss.privacyguides.net/t/security-wise-closed-source-tech-giant-app-vs-foss-of-a-single-developer/20645
**Category:** Questions
**Tags:** software
**Created:** 2024-09-06T14:20:21Z
**Posts:** 6
**Showing post:** 6 of 6

## Post 6 by @Iluvinatum — 2024-09-06T18:39:10Z

I read a thread from recommendations

> [@Does anyone check the code of FOSS apps? How do I know?](https://discuss.privacyguides.net/t/does-anyone-check-the-code-of-foss-apps-how-do-i-know/18604/5):
>
> Open source means that the code is available for security evaluation, not that it necessarily has been evaluated by anyone. This is an important distinction. Understood. My question is, how do I know if it has been evaluated by anyone. And when somebody evaluates the code, and finds a problem, is Github the place where it will be reported?

It seems I should better lean to tech giants or **highly** popular FOSS with many eyes watching. So the chance someone indeed cares about security is higher. At least making sure that libraries with severe CVEs are updated.  
[AmazeFileManager](https://github.com/TeamAmaze/AmazeFileManager) looks like one I can trust.

Regarding threat model, I consider remote attacks, not physical access. I skip apps with no updates for \>1y, simply to “stay updated”. I don’t know technicalities of it, just follow general safety recommendations like this. Exploits can be bizarre and you would never guess it’s even possible to hack this with that.

---

_[View the full topic](https://discuss.privacyguides.net/t/security-wise-closed-source-tech-giant-app-vs-foss-of-a-single-developer/20645)._
