4 ms·
> - Attackers could add their own exploit that will go unnoticed or unfixed for an indeterminable length of time. That's why not everyone has commit access* (f
by fbender 9y ago
> - Attackers could add their own exploit that will go unnoticed or unfixed for an indeterminable length of time.
That's why not everyone has commit access* (for both open and closed source projects) and there's always* a code review performed by independent peers. This neither protects you from accidental security issues nor highly obfuscated malicious exploits (only sufficient skills of the reviewer does), but that holds true to both open and closed source projects. For the former, the "indeterminable length of time" until exploits are found may be much shorter than for closed source projects due to increased eyeballing for large projects.
* Let's ignore those who ignore common sense. If you care about the security of the software you use, you want the developer(s) to follow basic rules of software development.
And you can even verify that in open source projects without needing to know how to code. For closed source projects you can't, you can only trust the company to do so. How's that different to trusting the skills of the open source developers?