Linked by Thom Holwerda on Tue 14th Dec 2010 23:55 UTC, submitted by Oliver
Thread beginning with comment 453670
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[2]: So much for the mythical "one thousand eyes"
by google_ninja on Wed 15th Dec 2010 13:54
in reply to "RE: So much for the mythical "one thousand eyes""
RE[3]: So much for the mythical "one thousand eyes"
by dylansmrjones on Wed 15th Dec 2010 14:33
in reply to "RE[2]: So much for the mythical "one thousand eyes""
Bullshit, and nice trolling btw.
Companies have little financial incentive to audit their code, not even when explicitly paid for it. They will audit the code exactly as little as they can get away with - and no more. There's a reason the most insecure software packages are proprietary packages. Because they cannot be effectively audited.
FLOSS projects have an incentive that no proprietary project will ever have: Street credit.
RE[3]: So much for the mythical "one thousand eyes"
by TheGZeus on Wed 15th Dec 2010 15:39
in reply to "RE[2]: So much for the mythical "one thousand eyes""
RE[3]: So much for the mythical "one thousand eyes"
by ichi on Wed 15th Dec 2010 18:03
in reply to "RE[2]: So much for the mythical "one thousand eyes""





Member since:
2006-01-24
Well, with open source you CAN audit, if you don't then obviously it's no safer than closed source. With closed source you don't have that option at all.