At least with Linux we have thousands of open source developers keeping an eye on things, chances are much higher that an issue would be caught with Linux since Windows is closed source.
At least with Linux we have thousands of open source developers keeping an eye on things, chances are much higher that an issue would be caught with Linux since Windows is closed source.
A bit of pithy sarcasm for your morning: Those thousands of eyes worked so well with OpenSSL, didn’t it?
Those eyes are less vigilant than you might think, especially when the eyes aren’t being paid to monitor a particular chunk of code.
That there have been two major OpenSSL security fumbles (first was the Debian OpenSSL fiasco, second Heartbleed) sort of suggests that the value of "many eyes" for ensuring security is vastly overrated.
And not to mention that Windows - the explicitly called out alternative from this article - makes their source available for security companies (as well as general developers who sign up for their MSDN program).
Why? Heartbleed was discovered by fuzzing the compiled binaries, not by eyeballing the source code.
Nothing prevents you from performing the exact same research on proprietary software.
That’s all utterly irrelevant when ElementaryOS doesn’t even offer reproducible builds.
Besides, source code access doesn’t make finding bugs much easier. Usually you’ll be auditing binaries anyway.