Hacker News new | ask | show | jobs
by k3a 3135 days ago
Good point. But I still prefer open free software, because there you HAVE the OPTION to inspect it!

If you paid someone (even multiple people/companies) to do professional audit over OpenSSL, it would be prevented.

Now, with closed software you are lost and the only thing you have is a TRUST the SW developer. Because inspecting blbs is much more difficult. And I don't trust them.