17 ms·
You've obfuscated a good point. Open-source is a necessary, but not sufficient condition for openness. Actual human beings must also understand the source well
by simpaticoder 3y ago
You've obfuscated a good point. Open-source is a necessary, but not sufficient condition for openness. Actual human beings must also understand the source well enough to audit it and modify it. If heartbleed occurred in closed source, it would still be an active problem. The vendor would be reluctant to even admit the flaw, because it makes them look bad. And the whole world realized that one guy was maintaining OpenSSL, and he was on the edge of poverty. It was a wake-up call. Thousands of devs looked at the code, and understood it well enough to patch and fork.
It's also true that, because of historical accidents, we have several more examples of https://xkcd.com/2347/ https://xkcd.com/2347/. However, that's not an argument against open source. It's an argument that we all should take ownership of what we ship, all the way down, without exception. An open CPU definition is a necessary, but not sufficient, requirement for this level of ownership.