If openSSL was closed-source and a vulnerability was found in it, couldn't it have been patched without revealing what the issue was? This seems to be a big security issue with open-source.
No, unless it's the sort of software that doesn't need to be distributed at all. Security patches to widely-used software are attractive targets for reverse engineering.
Comments
If openSSL was closed-source and a vulnerability was found in it, couldn't it have been patched without revealing what the issue was? This seems to be a big security issue with open-source.
No, unless it's the sort of software that doesn't need to be distributed at all. Security patches to widely-used software are attractive targets for reverse engineering.