Hacker News new | ask | show | jobs
by anigbrowl 3971 days ago
How many people have the time or inclination to validate everything that way?
2 comments

Not many, but the effort is parallelizable. If you find a security problem and report it in public, others can verify it, and still others can benefit from the fix even if they never would have bothered to look for themselves.
It doesn't take many. The problem is making sure that someone is doing it (cf., OpenSSL).