Skip to content

Ease security vetting by publishing security scan reports and/or publishing in AppStore #4463

Description

@WesleyBlancoYuan

I like this software and want to use it in my company. As per regulations and compliance requirements, every software needs to bypass internal security scan; but even before that, manual human review is done by the cybersecurity team.
They don’t refuse me immediately, maybe due to this software is:

  • actively maintained and contributors are not few
  • is OOS
  • free of charge
  • public licensed and OK for commercial usage

But they remain skeptical, mentioning that it’s a keyboard event monitor and along with screenshot creators, are among the most sensitive applications regarding Intellectual property rights. Also, it is not available in AppStore, meaning the supply chain risks cannot be offloaded onto Apple part. About user data uploading, keylogging like behavior and elevated privilege problem, they haven’t scanned, as I understand that requires extra effort. But they told me that as it’s OOS, I can also scan it myself, which I don’t need as I love it, trust it and use it daily.

So here I would like to know, if this software has any plans to be released in AppStore?

Of course this is just a suggestion. I am thinking to make it, for example, like Sublime Text, free for personal evaluation but needs a license for continued use, and put no limit of time for personal evaluation. It seems to me that it even becomes easier for cyber security team to believe it’s safe, when it requires a paid license. I also understand publishing it to AppStore is an extra effort and cost. I am just thinking maybe it would make the software a little bit more “trustworthy” in the context of cyber security, legal, IP, compliance and auditing, if other aspects of the software as mentioned by these people are not possible to change, due to the nature of the software.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions