← Field Notes · Trust
Why Auditable Code Matters More Than Marketing Claims
Security software asks for more trust than almost any other category of program. Very little of it earns that trust the same way.
Antivirus software occupies an unusual position on a computer: it runs with elevated privileges, inspects files across the entire system, and, in many commercial products, phones home with telemetry about what it finds. Users are asked to trust that this access is used exactly as described, and for most of the industry's history, the only evidence offered for that trust has been a vendor's own privacy policy and reputation.
Cryptography solved a version of this problem more than a century ago. In 1883, the Dutch cryptographer Auguste Kerckhoffs argued that a cipher should remain secure even if everything about its design is known to an adversary, except the key. The modern restatement, sometimes called Shannon's maxim, is blunter: assume the enemy knows the system. The principle reshaped cryptography because it forced designers to stop relying on secrecy of design as a security property, since secrecy of design cannot be verified by anyone outside the organization that holds it, and history is full of proprietary encryption schemes that turned out to be weak the moment someone outside the vendor finally examined them.
Software security absorbed a version of the same lesson more slowly, through the open-source movement, and through what programmer Eric S. Raymond called Linus's Law in his essay on open development: given enough eyeballs, all bugs are shallow. The claim is not that open-source software is bug-free, it demonstrably is not, but that code visible to many independent readers has a shorter average path to having its flaws found than code only its own authors can see. ClamAV, an open-source antivirus engine first released in the late 1990s and still widely used, particularly on mail servers, is a direct, long-running example of the model applied to this specific category of software.
Open source is not a synonym for secure, and code visibility alone does not guarantee anyone is actually reading it. But it does something closed source structurally cannot: it lets an independent party verify a specific, checkable claim, such as whether a program's only network activity is downloading a public hash list, rather than asking that claim to be taken on faith from the company that benefits from it being believed.
For a category of software that asks for elevated system access and continuous trust, that difference is not a minor technical preference. It is close to the whole argument. A vendor that says its product does not upload user files or monitor behavior for any purpose beyond local detection is making a claim. A vendor whose source code is public, and whose claim can be checked against that code by anyone who chooses to look, is making a claim that can be tested rather than simply believed.