3 ms·
Just to be clear, 7zip, gzip, bzip2 and others all have their own CVE's with arbitrary code execution. Open source software is not immune from these flaws. You
by Strom 3y ago
Just to be clear, 7zip, gzip, bzip2 and others all have their own CVE's with arbitrary code execution. Open source software is not immune from these flaws.
You can argue for your political beliefs, sure, but let's be honest and not claim that there are any security benefits.
- gorenb 3y agoOpen source does have some security benefits. If billions of (mostly) good people who want to help can read the code, they can find vulnerabilities more easily. Having so many contributors does help.
- Strom 3y agoThat is a popular fantasy story. The reality of almost all open source software is that nobody reads the code and the primary author is struggling to find the time to keep up with maintenance. What's more, doing security review is very hard. You can't just casually read a bit of code. You need to deeply understand the surrounding context. People who have the capability to do that aren't going around providing that service for free. -- More reading for the curious: https://www.explainxkcd.com/wiki/index.php/2347:_Dependency https://www.explainxkcd.com/wiki/index.php/2347:_Dependency
- arboles 3y agoWell I'm quite motivated to fix this vulnerability in WinRAR, but I can't.