Would their software be safer if it was open source? Probably. Open code is rarely a loss for security. But it's not easy to say how much safer. Probably less than you think.
Would their software be safer if it was open source? Probably. Open code is rarely a loss for security. But it's not easy to say how much safer. Probably less than you think.
And indeed; very few companies spent as much money as Microsoft on their entire SDL. Sadly never had the chance to get a look into Google's kitchen but I'm hearing that they're great too.
They're also not dealing with the kind of backwards compatibility that Microsoft is dealing with which helps them out a lot too.
>One programmer wrote an article on it saying it was actually good code.
"one programmer" commenting about 30+ million lines of code. Yeah. uh-huh. Anyway, you can still find the kernel's source if you care to dig around. Its the Windows Research Kernel but it's mostly unchanged from the commercial codebase.
>The problem areas seem to be little hacks they had littered everywhere to keep 3rd party hardware or software from breaking.
Those are mostly relegated to the compatibility shim layer. You can turn it off, in any case.
Yeah, my inability to evaluate the skill level or character of source was main drawback of claim. I gave a little credence to it because I knew that they were ramping up QA due to image problems and potential lost sales. Steve Lipner... who did high-assurance security with legendary Paul Karger... came in to turn it around with the SDL. Massive investment in professional programmers to find quality issues across the lifecycle implies it would have fewer issues than average software.
https://msdn.microsoft.com/en-us/library/ms995349.aspx
""one programmer" commenting about 30+ million lines of code. Yeah. uh-huh."
You can tell a lot by glancing at random samples while digging into a bit fewer. Good, well-commented code with various security checks stands out for people that spend years looking at the opposite. All such a review could say, though, was that people were putting in effort. Actual security would need thorough review.
"Anyway, you can still find the kernel's source if you care to dig around. Its the Windows Research Kernel but it's mostly unchanged from the commercial codebase."
Will do. Appreciate the tip.
CDCFKW.zip not saying anything.. just sayin :P