• 0 Posts
  • 12 Comments
Joined 2 years ago
cake
Cake day: June 22nd, 2023

help-circle
  • Also keep in mind that employees of companies that release closed source software are obligated to keep secret any gaping security vulnerabilities. This obligation usually comes with heavy legal ramifications that could be considered “life ruining” for many of us. e.g. Loss of your job plus a lawsuit.

    Often, none of the contributors to open source software are associated with each other and therefore have no obligation to keep discovered vulnerabilities a secret. In fact, I would assume that many contributors also actively use the software and have a personal interest in getting security vulnerabilities fixed.