So many (consumer-focused) FOSS products have huge, obtuse quirks in them that prevent their widespread adoption, and uber-tech-literate people tend to overlook this because they really want to believe that FOSS can succeed.
In reality, a lot of these quirks come about because of the non-commercial nature of the projects[1]. When a business produces software, the aim is to get as many people as possible to use it. This means a smooth (enough) user experience or death.
For software written by volunteers, the aim is to (generally) satisfy the intellectual curiosity of the people writing it. This means huge issues for users, and QA in basically all forms, are overlooked in favour of working on cool/interesting things for developers.
[1] Yes, I know commercial FOSS exists. I run a reasonably large commercial FOSS project myself. However, the overwhelming majority of FOSS projects out there are volunteer-led and run.
Also, terrible obtuse quirks are certainly not unique to FOSS products. Go ask someone who deals with, I don't know, the software used to run hospitals and healthcare systems (electronic health records, or EHR's) as but one example.
You can do stupid things in Linux, but if you stay on the rails (I only upgraded to Ubuntu 20.04 last week) you're fine. Windows will just mess your system up every so often without you even doing anything except installing the updates it tells you to.
https://www.debian.org/doc/manuals/apt-guide/ch2.en.html
What guesswork is needed?
I think that's fair.
If you say yes, it is not an accident but 1. your own decision 2. it is easily reversible.
Maybe some user can be unaware of what is happening with OSS, but the community as a whole will always have accurate information of what is what (unlike this case where everyone is guessing).
OpenSSL audit would like to have a word with this mythical community. log4j vulnerability, too.
For starters, the obvious implied suggestion is that these types of vulnerabilities don't exist in commonly used closed-source systems. That's been proven hilariously false time and again.
Secondly, commercial vendors have seen fit to adopt opensource where it suits them in order to take advantage of (and offload responsibility for) what these components do. You're effectively saying "Open Source community doesn't have accurate information because look at X and Y" and ignoring that "X and Y" were also not discovered to have problems by any closed-source using dependent commercial entities.
I never implied that, obviously or not.
> Secondly, commercial vendors have seen fit to adopt opensource where it suits them in order to take advantage of
Commercial vendors adopted opensource due to lower cost of ownership, not due to perceived lack of problems or because "community knows exactly what is what"
The number of people who can properly analyse complex software to uncover what it actually does is a line asymptotically approaching zero. While OpenSSL is an overused example, it still remains a good one.
Besides, you’ll never know if the code you’re looking at abuses some compiler quirk without studying the binary.
- a modern OS has anywhere upwards of 50 million lines of code (Linux kernel alone is ~30 million lines of code) [1]
- a modern browser is anywhere upwards of 30 million lines of code [2]
- there are over 3.5 million individual packages available for the various Linuxes [3]
And so on. The pretence that there are people and resources readily available to analyse those sources, and understand them well enough to uncover complex vulnerabilities is just that: a pretence, a myth. As evidenced by high-profile bugs that existed in popular codebases for years.
Does the availability of source code make analysis somewhat easier? Yes. There's a difference though between reviewing left-pad on GitHub and auditing OpenSSL, for example. There are thousands of people who can do the former, and perhaps 5 who can do the latter.
That is why "the number of people who can properly analyse complex software to uncover what it actually does is a line asymptotically approaching zero".
[1] https://www.linux.com/news/linux-in-2020-27-8-million-lines-...
[2] https://www.openhub.net/p/chrome/analyses/latest/languages_s...
I doubt that. And even the people who are good at analyzing binaries probably prefer to have the source code available to save a lot of time.
It is certainly a trade off, and everyone will have their own reasoning. There is no objectively correct answer.
That depends on your definition of nefarious.
But how do I know the source code I check is the binary my machine runs? Even if I build from source I could have a malicious gcc that takes clean source and outputs a malicious binary.
Unless you are running jit or something you can't really know what your computer is running even if you use open source.
On the other hand all my blackhat friends have a really bad time with closed source software. This is the primary reason black box security testing is dying.