I agree with it, but it would disrupt a whole industry.
I know for sure this is a controversial point of view, but to me it is obvious (even if I can see the reasoning behind hard-line Free Software advocacy).
(What would probably do more good for both Open Source and Free Software in my opinion would be to get rid of CLAs as far as possible since they create a unhealthy relationship where the strong part is constantly tempted to relicense contributed code.)
No, it doesn't: https://en.wikipedia.org/wiki/Free_software.
Where possible, the programs should be written in a more data-driven manner, where the actual classified portions are contained in data files that are separated from the program source code. This permits you to release the source code without issue (it tells you very little about the actual systems), and then you only have to keep classified the data used by the program and assembled (data + executable) system.
If the program cannot be properly separated from something warranting classification, modular programming is the solution. Divide the program into an unclassified and classified portion. Keeping the former in the public domain and visible (at least with no more than a FOIA request, ideally with less effort) and the latter properly secured.
Even the un-classified stuff is mind-blowing, including thinking about how to even begin running/building a system like that. Software code would reveal way too much of that, even after being sterilized.
Regarding running/building, sure, it's harder. But mostly because of expense, the specific examples were military and US DOD and its contractors buy compilers. So buy a license for Green Hills or similar and you can build it. Buy an ARM development board and you can run it. "ARM?!?!?" Yes, ARM. Embedded systems in the modern era (that is to say, after 2000 but starting sometime in the 1980s) use off-the-shelf chips, perhaps hardened versions for things like satellites. "Hardened" doesn't necessarily change the architecture, mostly just ties them to an old version of it. If the software is from pre-1990 there's a good chance it is running on a bespoke architecture, but after that point, and certainly after 2000, it became rarer.
Now, whether they will release the code is another matter. Doing this determination requires good upfront engineering or a lot of analysis before releasing it. But good engineering has been known to happen from time to time, even by the government. More practically, though, the software will mostly be developed by contractors who will retain the copyright and so it won't be public domain.
Even just exposing data structures will reveal capabilities by virtue of the data created by them.
If an fighter pilot's battlefield/ situational awareness software makes calls to 4 known methods of battlefield communication, and also to an additional unknown one, then that reveals info, even without knowing anything else about it.
Maybe you're intending that all of these types of inquiries, or data sharing capabilities be redacted or sanitized somehow, but that seems like a huge undertaking in itself, especially if you expect a working product.
And then what would that resulting skeleton product's remaining value be, for the extra effort put into releasing it?
Besides potentially helping other countries close the capability gap.
2. Every similar law has exceptions concerning classified information.
S-by-O got a bad reputation due to people imagining it was the last word in security, when it really is just the beginning.
Passwords are literally purified security-by-obscurity.
I can't think of any security technology or method that doesn't have a security by obscurity component. Or that isn't enhanced with an additional layer of it.
It does suggest that a common usage of the term "security by obscurity" can mean security ONLY by obscurity. Which I made clear was not my usage.
The other mis-use of the term is the opposite overreaction is to forget that obscurity does remain an indispensable component of practical security. Its most common form being as a password (or biometric) used to unlock an otherwise impenetrable (for practical purposes) system.
Without an obscured backdoor (password, biometric, ...) the an otherwise completely secure system would not even be accessible to its owner.