External audit of code for Ubuntu Mate?

There doesn’t seem to be any audit externally of any of this code.

How do we know that it isn’t tracking us?

I ask for badges to be implemented that show that the code has passed ISO standard and has been audited by an external company for effectiveness and efficiency and does not track you.

I hope that there is a quality control audit by an external company soon?

1 Like

Ubuntu MATE and the various flavors and remixes are made of dozens if not hundreds of independent packages and components. They are all developed independent of each other, with different versions being available in Ubuntu in timelines and distributions that are not as “rapid” as upstream developers will release fixes (see “Why don’t the Ubuntu repositories have the latest versions of software?” on Ask Ubuntu for some explanations why this is the case).

Effectively, your request is that you want “every piece of software possible in the repositories and world” audited for compliance by a third party company, which is what is necessary for full and proper ISO certification of software and such.

Unfortunately, that is not feasible in any sense because of the scale that it’s requiring. If you are looking for ISO standards certification, that is typically not doable for Open Source at the OS scale. It’d be like asking for Debian to undergo ISO standard certifications. Which is equally not-feasible.

7 Likes

How do you know that such an external organisation can be trusted? And how much are you prepared to pay for the audit? It is the old question. Who is watching the watchers?

One of the founding principles of FOSS is to allow anyone access to the source code. It is why many security vulnerabilities are identified and fixed before criminals can find them and take advantage of them.

I do not know if Ubuntu Mate has something similar to Ubuntu System Settings> privacy & Security but a lot is already done to give the user control of their system.

Have you studied the Ubuntu Privacy Policy?

Ubuntu Data-Privacy policy

We also have official publicity documents

Ubuntu security

For years now Canonical has been positioning itself as a supplier and maintainer of Enterprise Quality software. All this work benefits ordinary users of Ubuntu and the Flavours of Ubuntu.

Canonical

Some years ago I read that a motor vehicle is held together by thousands nuts. But it only takes one nut behind the wheel to break the vehicle.

Regards

1 Like

With respect if Ubuntu mate is so popular and well put together and used by a lot of people; I think you are giving excuses and I think that external auditing should be common place in that it represents a gold badge in attaining trust in the community.

Mark Shuttleworth has 500 million pounds and I think a proper audit wouldn’t be much north of £250K so like I say I think you need to go and ask him how to proceed with a proper review (respectfully).

If an external audit report would be established on a 5 year basis then I think people would see that they can actually trust the software, because it has been validated in public. When it is in public the coders can then see the fruit of their work.

Otherwise it is just one person saying ‘it’s okay we’re the good guys’

-ask mr shuttleworth for an audit?

This is my feedback, pal.

“But it only takes one nut behind the wheel to break the vehicle.“

I hope that you are not saying that i am in some way mentally incapable?

1 Like

This topic is temporarily suspended for staff review.

Upon review, we’re going to keep this closed.

The argument that only an external audit will ensure safety and security is specious.

Anyone is welcome to audit the code. It is open source.

6 Likes