[{"data":1,"prerenderedAt":103},["ShallowReactive",2],{"blog-post-en-GB-open-source-has-to-include-the-servers":3},{"post":4,"translated":95},{"id":5,"title":6,"author":7,"body":8,"date":89,"description":90,"draft":91,"extension":92,"meta":93,"minutes":94,"navigation":95,"path":96,"seo":97,"stem":98,"tags":99,"__hash__":102},"blog_en\u002Fblog\u002Fopen-source-has-to-include-the-servers.md","Open source has to include the servers","Erik Bjerke",{"type":9,"value":10,"toc":79},"minimark",[11,15,20,23,27,30,33,36,40,43,46,50,62,65,69,76],[12,13,14],"p",{},"A lot of privacy-focused companies describe themselves as open source. Usually\nwhat that means is the apps are public and the backend is not. That is better\nthan nothing, and it is much less than it sounds.",[16,17,19],"h2",{"id":18},"what-an-open-client-proves","What an open client proves",[12,21,22],{},"Quite a lot, actually. If the client is open and reproducibly built, you can\nverify that it encrypts before sending, that the keys are derived where the\ndocumentation says, and that it does not contain a third-party analytics SDK. For\nend-to-end encrypted content, this is most of the story: if the ciphertext leaves\nyour device correctly, the server's honesty matters much less.",[16,24,26],{"id":25},"what-it-does-not-prove","What it does not prove",[12,28,29],{},"Everything about the parts that are not end-to-end encrypted, which is always\nmore than the marketing implies.",[12,31,32],{},"Metadata is the obvious one. Who you email, when, how often, from which IP, and\nhow large the message was. None of that is in the client's threat model, and all\nof it is retained or not retained by code you cannot see. \"We do not log IP\naddresses\" is a sentence about a config file you are not allowed to read.",[12,34,35],{},"Then there is everything operational: retention windows, backup lifetimes,\nwhether deletion is real, which third parties the service calls, and what happens\nto an account flagged for abuse. All decided in a repository you have no access\nto.",[16,37,39],{"id":38},"the-uncomfortable-version","The uncomfortable version",[12,41,42],{},"The reason server code stays closed is rarely that it contains secrets. Secrets\nbelong in a vault, not in source. It stays closed because it is where the\ncompromises live: the analytics that were supposed to be temporary, the vendor\nthat needed plaintext, the retention window that is longer than the policy page\nimplies.",[12,44,45],{},"I am not accusing anyone in particular. I am saying that \"trust us, the server is\nfine\" is the one claim in a privacy pitch that cannot be checked, and it is\nconsistently the claim that is left uncheckable.",[16,47,49],{"id":48},"what-we-are-doing-about-it","What we are doing about it",[12,51,52,53,57,58,61],{},"Every Numori server is public under the AGPL-3.0. ",[54,55,56],"code",{},"Numori-CRDT"," is the sync\nrelay, ",[54,59,60],{},"Numori-Auth"," is the identity service, and both are readable today. The\nAGPL matters here rather than a permissive licence: it means anyone can run\nNumori as a service, but they have to publish their modifications too. If we are\never acquired and someone decides the sync relay should start keeping a little\nmore, the licence makes that visible.",[12,63,64],{},"This does not make us trustworthy. It makes us checkable, which is a more useful\nproperty, because it does not depend on our intentions staying good.",[16,66,68],{"id":67},"the-catch-stated-plainly","The catch, stated plainly",[12,70,71,72,75],{},"Publishing the server does not prove that the code we published is the code we\nare running. That gap is real and I am not going to pretend otherwise. Closing it\nproperly needs reproducible builds and attestation, which is on the roadmap for\n",[54,73,74],{},"Numori-Updater"," and is genuinely hard.",[12,77,78],{},"What publishing does give you is a specification precise enough to hold us to, an\nindependent implementation you can run yourself, and the ability to leave for\nyour own server without losing anything. That is a much better position than\ntaking a policy page at face value.",{"title":80,"searchDepth":81,"depth":81,"links":82},"",3,[83,85,86,87,88],{"id":18,"depth":84,"text":19},2,{"id":25,"depth":84,"text":26},{"id":38,"depth":84,"text":39},{"id":48,"depth":84,"text":49},{"id":67,"depth":84,"text":68},"2026-08-04","Publishing a client while the server stays closed proves almost nothing. Here is what an open client actually tells you, and what it does not.",false,"md",{},5,true,"\u002Fblog\u002Fopen-source-has-to-include-the-servers",{"title":6,"description":90},"blog\u002Fopen-source-has-to-include-the-servers",[100,101],"principles","open-source","otfuyB2w5qHulKJ3ckmNfUKC8qph4SATA-xYe7rNy4Y",1788170792070]