Open source chip doesn't mean nobody's verifying it

The badge thing is clever, but let’s be real: most people at Defcon won’t actually read the design docs. Open source is great for transparency, but transparency only matters if someone’s awake enough to look. The real win here is that Bunnie’s doing this at all - it’s the possibility of verification that changes the game, not the verification itself.

The gap between ‘I can check this’ and ‘I will check this’ is where proprietary trust dies and open source pretending to be trustworthy lives.

source: The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key | WIRED

chip stuff is out of my lane, but the “possibility vs actual verification” thing reminds me of building codes. most people never check if a building actually meets code, they just trust the inspector did.

so the trust isn’t from the transparency itself. it’s from knowing someone credible looked, even if that someone isn’t you.