3 ms·
> community-vetted i wonder if this sort of confidence makes you less-safe. something like this should've prevented heartbleed, in theory, right?
by abiox 9y ago
> community-vetted
i wonder if this sort of confidence makes you less-safe. something like this should've prevented heartbleed, in theory, right?
- oliwarner 9y agoIt's not confidence that I'm secure, it's a belief that this software development process makes me more secure. You and your friend down there seemingly have more faith that a closed source process, what, would have identified this bug before it was deployed? Why? That it would have been found by good actors first? Why? That it would have been fixed promptly? Why? Announced with disclosure of its existence and ramifications? Why? It's not a money question for this stuff either. There are hundreds if not thousands of paid engineers for known good-actors all working to break and responsibly disclose security issues in the same software stack I use. The only thing you know about the comings and goings of closed source software is when public disclosure happens (and it's later fixed). Why would I be more confident in that process? It's not good enough.