I'm not speaking of this project in particular.
Just saying, just because something is open source doesn't mean it has no vulnerability or backdoor in it's code.
There is plenty of example of vulnerabilities that existed for years in major open source projects. And there is definitely people that discover some zero day and straight up sell them and stay quiet.
If you look at some of the businesses in the market of zero day vulns you can see what they offer for good vulns.
Who cares if the NSA uses it. Or if they say they use it. They gain nothing in saying they use a specific product. But that's a good way to encourage others to use it. I certainly wouldn't trust the NSA on anything they say publicly.
You can backdoor a product just for you and still release it so other people you might be interested in will give you cool data. In cryptography this is not really an issue to have backdoors that only some people can use.
I had issues in the past with opensubtitles serving malware through fake download buttons on the site.
You had like 6 different buttons to download with only one legit.
Sent them an email and they removed them...
I hardly trust this site and really don't appreciate they use open in their name and pull up shit like this.
I wish we had some sort of P2P sub hosting... So we don't have to deal with sites like opensubtitles.