3 ms·
Yes. The security wins of being opensource are really only there if the project is being engaged with and reviewed by security conscious developers, improvement
by robomc 5y ago
Yes. The security wins of being opensource are really only there if the project is being engaged with and reviewed by security conscious developers, improvements are being merged in, and the new improvements are being distributed. Otherwise it's usually going to lower your security by some degree.
- lucideer 5y ago> lower Using the word "lower" here implies you're comparing open source software to something (closed source software), in which case you'd be implying that closed source software is engaged with and reviewed by security conscious developers. If you think that's the case just because you've heard of a few high-profile open source vulnerabilities, I've got news for you...
- dathinab 5y ago> going to lower your security by some degree. Not really, the security is the same. You just make the work for attackers a bit faster=>cheaper. But IMHO for an experienced attacker it's just a matter of "a bit faster" (like their attack comes a few days earlier), not a matter of "being more secure" (like their attack doesn't come at all).
- deleted 5y ago[deleted]
- Spooky23 5y agoLook at the lists of CVEs that come out every month for closed source software. How did they fix them? You don’t know. I can tell you that that my colleagues have found cases where major vendors don’t “fix” a defect - they prevent the public exploit from executing. With open source, you can see exactly what was fixed and how. You don’t lower or raise security.