Question about website safety
by gayass - Tuesday March 5, 2024 at 04:28 PM
#1
If i were to build a website, would it be safer to build it and post the source of it on github, making it open source, or keeping the source of it private?
Reply
#2
If you have secrets to protect, keep your code in the safe, otherwise keeping it open source can build trust among users and also invite others to contribute to its development.
Reply
#3
This is double-edged sword. You will get more eyes on the project, but you can't choose if these eyes will be malicious or not

I would say publish the source, but have backup of everything and don't keep anything sensitive on the server, so even in worst case you won't lose much
Reply
#4
all that matters if someone gives a fuck. if no one gives a fuck, then you are fine open source or not. if someone cares then they will find vulnerabilities whether your site is open sourced or not.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#5
(Mar 05, 2024, 05:15 PM)Bookworm Wrote: If you have secrets to protect, keep your code in the safe, otherwise keeping it open source can build trust among users and also invite others to contribute to its development.

This right here.
"Universal appeal is poison masquerading as medicine. Horror is not meant to be universal. It's meant to be personal, private, animal"
Reply
#6
(Mar 05, 2024, 06:45 PM)Croquet Wrote: This is double-edged sword. You will get more eyes on the project, but you can't choose if these eyes will be malicious or not

I would say publish the source, but have backup of everything and don't keep anything sensitive on the server, so even in worst case you won't lose much

Oh yeah that's true. I'd keep more sensitive information probably in another place so nothing gets leaked 
Can never take enough precautions lol.

(Mar 05, 2024, 07:00 PM)ramsey Wrote: all that matters if someone gives a fuck. if no one gives a fuck, then you are fine open source or not. if someone cares then they will find vulnerabilities whether your site is open sourced or not.

I mean, there will always be a vulnerability waiting to be exploited, but i'm having the idea to open-source it so even if people want to exploit it, there would still be lots of ppl helping out to patch that vulnerability too.
Reply
#7
There's no reason to open source your website unless it's a fun project with nothing value locked behind it. You can invite feedback and stuff. If you have a database with worthwhile data then yeah, they can just run some tools to see if there are vulnerabilities to leverage.
Everyone has covered it, it's all up to you to assume risks but if you're unsure then don't put anything valuable up to begin with.
Reply
#8
It depends on the scope of the project and how well you can code.

There shouldn't BE vulnerabilities.

Do note, open source does mean that an attacker has more surface area to test out.

But, generally? It's fine.
Buffer Overlord
Deploying Precision in Every Line.
PGP Fingerprint: C1F5 5935 4992 A77B 69E1 B626 7556 1F6B 453C B36F
https://pastebin.com/raw/6k1RJQie
Reply
#9
Deciding between open source and private source depends on what matter most to u. 

Open source invite community input but also more risk. Keeping it private reduce community engagement and transparency. 

Choose based on what go best with ur project's aim. and how much risk u are willing to take.
Reply
#10
If you have any kind of data to protect i'd say your best option is not to open source it. If not, go for it.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Participating in Extortion.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  A collection of deepweb sites [2025] dg7ka 106 2,736 7 hours ago
Last Post: nosec67
  FREE 3 UNCENSORED HACKING LLM QaboosbinSaidAlSaid 68 1,571 Today, 02:22 AM
Last Post: Microban
  Telegram Opsec Guide Synaptic 47 1,780 Yesterday, 07:59 PM
Last Post: thebinarymonk
  Looking for experienced hacker 99992 0 153 Apr 28, 2026, 10:59 PM
Last Post: 99992
  I'M LOOKING FOR AN INTELX API orkidd 1 309 Apr 27, 2026, 05:16 PM
Last Post: orkidd

Forum Jump:


 Users browsing this forum: 1 Guest(s)