The company behind the Signal clone used by at least one Trump administration official was breached earlier this month. The hacker says they got in thanks to a basic misconfiguration.
I’m pretty sure that the licence also requires that you link to the source code. You can’t just have it up “somewhere” and just expect people to find it.
6d) Convey the object code by offering access from a designated place (gratis or for a charge), and offer equivalent access to the Corresponding Source in the same way through the same place at no further charge. You need not require recipients to copy the Corresponding Source along with the object code. If the place to copy the object code is a network server, the Corresponding Source may be on a different server (operated by you or a third party) that supports equivalent copying facilities, provided you maintain clear directions next to the object code saying where to find the Corresponding Source. Regardless of what server hosts the Corresponding Source, you remain obligated to ensure that it is available for as long as needed to satisfy these requirements.
I’m pretty sure that the licence also requires that you link to the source code. You can’t just have it up “somewhere” and just expect people to find it.
Yep. Relevant sentence bolded by me below
The requirement in the licence is that the source code or a link to it is distributed along with the binaries
“yeah my code is open source, it’s somewhere on this site I’m just not gonna tell you where it is.”