Hacker News new | ask | show | jobs
by rmdashrfstar 2251 days ago
This is why the assumption that “open source code is more likely to be closely audited for vulnerabilities” is not true (even for incredibly core/important projects with a wide scope) and is potentially dangerous to rely on.
2 comments

> This is why the assumption that “open source code is more likely to be closely audited for vulnerabilities” is not true...

That is a safe assumption, otherwise you'd have to believe that non-open source code is more closely audited - at greater expense, because businesses secretly prioritize security.

It is not 100% and always. But practically. Especially unexpected leak.