It's open source code so every discovered vulnerability is public knowledge.
Well, there is public knowledge, and there is actual action. Several examples come to mind. OpenSSL, which has been available for a very long time, does not have that good a track record. There is the example of 10-year old vulnerabilities disclosed in TOSSA that only recently came to light. The BEAST attack's underlying target was written about before.
From the point of view of labeling anything to be "secure" (whatever that means), I like to think what Steve Brown used to say about some new output from his science lab: "Not known not to work". Translated to the security world, "Not known to have security vulnerabilities."
Comments
It's open source code so every discovered vulnerability is public knowledge.
Well, there is public knowledge, and there is actual action. Several examples come to mind. OpenSSL, which has been available for a very long time, does not have that good a track record. There is the example of 10-year old vulnerabilities disclosed in TOSSA that only recently came to light. The BEAST attack's underlying target was written about before.
From the point of view of labeling anything to be "secure" (whatever that means), I like to think what Steve Brown used to say about some new output from his science lab: "Not known not to work". Translated to the security world, "Not known to have security vulnerabilities."