this post was submitted on 07 Jul 2023
1671 points (92.9% liked)
Memes
45731 readers
1039 users here now
Rules:
- Be civil and nice.
- Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I'm not mad, just disappointed.
In all seriousness though, I just disagree and I think it's important to note the inaccuracy of thinking that a bug, which is famous only because it was deliberately publicized and deliberately open source, is anything but a huge win compared to what would likely have played out had the most popular SSL library in the world been proprietary and closed.
What do you disagree with? Heartbleed was a vulnerability in OpenSSL. It affected millions of computers.
The only person in the whole thread talking about proprietary software is that guy.
This is a thread about how the accepted wisdom that many eyes make open source software more secure is based on the assumption that someone else is effectively auditing the code base which has been proven over and over again not to be true.
E: I just looked at this thread and now everyone is talking about proprietary software. It would be cool if the progression of time made fools of us all, but it looks like it’s just me this time.