Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's how the theory goes, but how often does this really happen though? See: OpenSSL


The simple reality is that when it comes to vulnerability research, Microsoft : Windows :: Google : Open Source.


Google's Project Zero has found quite a number of Microsoft bugs. Unfortunately, Microsoft has not reciprocated the favor.


Hehe, "favor"


Well, the kernel, right? Many many major corporate contributors. Kind of the opposite of OpenSSL, I guess, which everyone uses and no one seems to maintain.


On the other side, e.g. Egor Homakov hacked GitHub a few times through vulnerabilities in Rails. GitHub paid him bounties anyway. I'm no expert, but it appears to me that at times it does work, just not always.


Is github itself open source tho?


No, but a company paid a bounty for a leak in Rails, which is open source. Isn't that what this topic was about?


Well I think the source code is included (since it's Ruby, but encrypted) with the Github Enterprise image. But that's "source code available", not "open source" (ie, under a copyleft license)


> But that's "source code available", not "open source" (ie, under a copyleft license)

It's proprietary. Also, there are many free software (or "open source" if you prefer) licenses that are not copyleft. MIT, Apache, Revised BSD, zlib, etc are all examples.


Encrypted with a widely known (people have blogged it) key.


You say that like Heartbleed was the end of the story. Since then, "the Linux Foundation launched the Core Infrastructure Initiative (CII) as a way of getting resources to those projects. That has helped OpenSSL, among others, to get back into a healthy state." which includes a ton of funding from many companies that depend on OpenSSL like AWS, Google, Intel, Microsoft.

https://lwn.net/Articles/702751/


See: BoringSSL




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: