Skip to content

Comment on XZ: Repo maintainer Lasse Collin responding on LKMLparent

Comments

AFAICT, open source software has a better security track record, in general.

iirc Studies was done on this and there was no measurable difference in security issues when it comes to open vs closed source.

Just because the code is visible doesn't mean much, as you need to have the right eyes to actually notice security issues and a lot of open source projects don't have this.

Also closed source projects have the advantage where if they have a massive company behind them, that company has the resources (i.e. $$$) to hire highly specialised people to look the security of the software. Open source projects usually don't have such resources, heartbleed and xz are indicative of that.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.