3 ms·
"All bugs are shallow given enough eyeballs". This can apply to intentional security exploits as well. Of course, a small free project may not have enough eyeba
by Fargren 13y ago
"All bugs are shallow given enough eyeballs". This can apply to intentional security exploits as well. Of course, a small free project may not have enough eyeballs, but at least in a bigger one that does generate some trust.
- MaulingMonkey 13y agoAn oft repeated phrase, but I need only point to the Debian OpenSSL keygen debacle -- and how long it went uncaught -- to note just how easily extremely serious bugs in code known to be extremely security critical can go uncaught despite the "number of eyeballs". Bigger projects lead to bigger attack surfaces -- I'd trust the small free project more than I would the bigger one. Less code to review, fewer contributors one must simultaneously trust (I'd model project trust as each contributor being a potential single point of failure) and -- all other things being equal -- the same number of eyeballs per LOC. I'd qualify neither Firefox nor Chrome as small projects.
- dllthomas 13y agoOft repeated because it contains some truth. Also, overweighted. Availability of source code is not a substitute for security audit and good practices in development. It does help a little, directly. Indirectly, it helps a lot, because it means now you (or anyone else) can pay anyone to perform that audit. You can choose who you trust, beyond simple blind trust in the person providing the software.