Hacker News new | ask | show | jobs
by finid 4207 days ago
> Can be reviewed doesn't mean has been reviewed.

Well, you can't blame them if nobody bothers to review their code.

> Not the side, that every evil minded person can look through the source code, abuse it, before we were able to counter/fix etc it.

The same can be said of any other Free Software/Open source project. the Linux kernel and Apache are prime examples.

1 comments

Can't blame them for that indeed. But the fact this is 'how' they guarantee security. Perhaps after years of development, widely usage and actual reviews :-)

And yes this is a valid question whenever somebody considers to use OSS (or for prop. software, how likely chance will be an exploit will be found without source code at hand, and/ or how big of a hole it burns in your budget & wallet).