Security Reviews and Feedback

Reviews and feedback about the security of Kicksecure.
Contents
Definition of Audit
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Definition_of_Audit
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Definition_of_Audit|Definition of Audit]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Definition of Audit](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Definition_of_Audit)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Definition of Audit](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Definition_of_Audit)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Definition_of_Audit]Definition of Audit[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
The term "audit" in the context of computer security is frequently used without a clear definition. It is often referenced as a general concept, with little consideration for what an audit entails or how it is conducted. Many discussions assume that an audit is a simple, standardized process. An item to be checked off a list without a thorough understanding of its scope, methodology, or significance.
Lack of Formal Audits
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Lack_of_Formal_Audits
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Lack_of_Formal_Audits|Lack of Formal Audits]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Lack of Formal Audits](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Lack_of_Formal_Audits)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Lack of Formal Audits](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Lack_of_Formal_Audits)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Lack_of_Formal_Audits]Lack of Formal Audits[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Kicksecure has not been subject to a full formal audit, but that has little significance. At the time of writing, other security/privacy-focused distributions like TAILS and Qubes have not been audited either. Even major operating systems such as Debian, Arch, and Fedora have not had public, published audits to date.
Absence of Recognized Experts
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Absence_of_Recognized_Experts
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Absence_of_Recognized_Experts|Absence of Recognized Experts]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Absence of Recognized Experts](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Absence_of_Recognized_Experts)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Absence of Recognized Experts](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Absence_of_Recognized_Experts)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Absence_of_Recognized_Experts]Absence of Recognized Experts[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
We are unaware of any serious research concerning the above distributions. Furthermore, no recognized experts, such as Bruce Schneier in cryptography, exist for conducting a security-focused operating system review.
Limitations of Published Audits
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Limitations_of_Published_Audits
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Limitations_of_Published_Audits|Limitations of Published Audits]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Limitations of Published Audits](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Limitations_of_Published_Audits)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Limitations of Published Audits](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Limitations_of_Published_Audits)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Limitations_of_Published_Audits]Limitations of Published Audits[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Even the usefulness of any published audit must be considered. Audits of software and operating system platforms are necessarily carefully defined and limited in scope due to the vast complexity of such an undertaking. There are no all-encompassing audits that thoroughly examine or evaluate every possible aspect of security.
Examples of Formal Security Audits of Other Software
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Formal_Security_Audits_of_Other_Software
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Examples_of_Formal_Security_Audits_of_Other_Software|Examples of Formal Security Audits of Other Software]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Examples of Formal Security Audits of Other Software](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Formal_Security_Audits_of_Other_Software)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Examples of Formal Security Audits of Other Software](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Formal_Security_Audits_of_Other_Software)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Formal_Security_Audits_of_Other_Software]Examples of Formal Security Audits of Other Software[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
There have been formal audits of cryptocurrency wallets.
Examples of Partial Security Audits
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Partial_Security_Audits
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Examples_of_Partial_Security_Audits|Examples of Partial Security Audits]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Examples of Partial Security Audits](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Partial_Security_Audits)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Examples of Partial Security Audits](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Partial_Security_Audits)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Partial_Security_Audits]Examples of Partial Security Audits[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Independent researchers occasionally conduct partial security audits, a practice often referred to as security research.
- Ledger Hardware Wallet: Keylabs
performed a partial audit as part of wallet.fail
, which was presented in
35C3 - wallet.fail
.
Libbitcoin Explorer
(bx
): Distrustand independent researchers conducted a partial audit known as Milk Sad Disclosure
.
- Kicksecure: ProudmuslimDev
(xcancel
) performed an audit of a single script (whereas a Linux distribution consists of potentially hundreds of thousands of scripts and programs): privilege escalation issue (Twitter)
(xcancel
) (upgrade-nonroot privilege escalation issue (forums)
).
- Tails
: Critical security fixes
.
Typically, researchers identify areas of interest either through their own investigations or by being directed to them by others. If a particular issue captures their attention, they may examine a few specific aspects in greater detail. White hat hackers who uncover security vulnerabilities may choose to publish a full public disclosure for the benefit of the community.
Security researchers often refer to themselves as such rather than as security experts or auditors. This distinction may be intentional, recognizing the additional weight and implications associated with the latter titles.
These independent researchers are usually not hired by the software projects they analyze, which can be beneficial as it helps maintain their impartiality. However, they do not claim to conduct full formal audits. Instead, they typically provide evidence of the security issues they discover while avoiding broad statements such as "we performed a full formal security audit" or "we found no security issues."
Examples of Security Research
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Security_Research
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Examples_of_Security_Research|Examples of Security Research]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Examples of Security Research](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Security_Research)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Examples of Security Research](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Security_Research)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Security_Research]Examples of Security Research[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Nothing comparable exists for security-focused Linux distributions.
Examples of Unaudited Software
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Unaudited_Software
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Examples_of_Unaudited_Software|Examples of Unaudited Software]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Examples of Unaudited Software](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Unaudited_Software)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Examples of Unaudited Software](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Unaudited_Software)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Examples_of_Unaudited_Software]Examples of Unaudited Software[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
To explore this issue in further detail, consider the GNU wget
computer program, which retrieves content from web servers. Has wget
ever been fully, formally audited? Even if it has, what did the audit entail? A professional company providing software security audits as a service, or some kind of certification? At present, no such entities exist to provide this service within the Free Software and Open Source ecosystem, meaning there are no official quality seals for Linux distributions.
If the reader is aware of any such examples, please get in contact or edit this section. Also, consider whether it is reasonable to expect a reputable organization or individual to make statements like: "GNU wget
has been audited, and no security vulnerabilities were found." In reality, it usually happens the other way around; when someone reviews the source code and finds nothing wrong, nothing is reported. On the other hand, if a vulnerability is found, it may bring recognition. Essentially, anyone who claims beforehand to have found no security issues does not receive a boost to their reputation but, in fact, risks looking bad if problems are discovered later on after their previous statements about no security issues.
Call for Audits
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Call_for_Audits
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Security_Reviews_and_Feedback#Call_for_Audits|Call for Audits]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Call for Audits](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Call_for_Audits)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Call for Audits](https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Call_for_Audits)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Security_Reviews_and_Feedback?direction=prev&oldid=91524#Call_for_Audits]Call for Audits[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Anybody undertaking an audit of Kicksecure is kindly asked to edit this section or get in contact so the outcome can be linked here.


Copy as Wikitext

for Discourse, reddit, GitHub

Copy as Markdown

Copy as phpBB Click below ↴ = Open social URL with share data











We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!