4 ms·
There isn't
by mratsim 3y ago
There isn't
- mratsim 3y agoAnd here 2 years to find a buffer overflow vulnerabity in glibc that was found via a fuzzer: https://news.ycombinator.com/item?id=39194093 https://news.ycombinator.com/item?id=39194093 In a library used on billions of devices.
- realusername 3y agoif that was a private project at some company, it would still probably be there. In the long run openness always win for reviews. That's what inevitably happens in a world where the knowledge is accessible to anybody. The only way to go against that is pour some tremendous amount of money and the result isn't even guaranteed.
- mratsim 3y agoIt's a project used by millions of people yet it took 2 years. What about projects used by 10~50 people?
- realusername 3y agoWhat kind of strange argument is this? If it wasn't public, it would have never been found at all. I'm going to trust more a project peer reviewed by the best devs on the planets compared to some homebrew homemade software where the devs allegedly know better than everybody else (and they don't)
- mratsim 3y agoYour argument is that asking for professional auditor is not necessary for open-source code. My argument is that open-source is not enough when high-assurance is needed and devs or end-user should still ask for a professional audits.
- realusername 3y agoI'm not saying professional auditors are useless, just that they will never reach the feedback you get from peer reviews and are not a replacement for peer reviews anyways. We're not in the 90s anymore and it's time to acknowledge that the software world and even the world in general has changed. Knowledge is now spread and the most knowledgeable devs aren't working at an audit firm and might not even hold a computer degree!
- mratsim 3y agoThe people who found the bug in glibc worked at an audit firm. Peers aren't enough. Finding vulnerabilities require training and an adversarial mindset that is rare. There is a reason why in cryptography people say "don't roll your own crypto"