• Johanno@feddit.de
    link
    fedilink
    arrow-up
    40
    arrow-down
    2
    ·
    1 year ago

    The difference is the timing.

    Exploit found in closed source software:

    Probably years of usage by intelligence agencies and criminals until someone notices. (with no possible way to know for anyone that there even is a exploit). And even then it might take months for them to fix it.

    Exploit found in oss: Depending on the usage of the software several people are looking for security holes and they usually get fixed ASAP. Of course it is possible that there’s an exploit nobody finds and a criminal uses, but it is not more likely because he can read the code. If your code must be secret to be secure your code is anything but secure