3 ms·
> everything is open to them, source included Certifiers typically don't review source code. They are operating at least two levels of abstraction away: they r
by ef4 10y ago
> everything is open to them, source included
Certifiers typically don't review source code. They are operating at least two levels of abstraction away: they review documents that describe procedures that are supposed to ensure quality.
> If the code was open-sourced, don't expect to find lots of buffer overflow attack vectors
That is a big fat citation needed. Researchers working without access to source code have demonstrated multiple vulnerabilities in safety-critical medical devices. We have no way of knowing how many more they would find if they also had access to the source.