Are you arguing for the sake of it? I am so confused. What does CIS controls have to do with it(and I feel for you with all that box checking).
> As part of C2 communication, attackers have tried to mimic SolarWinds communication method by using JSON format for the HTTP communication. Following is the code for creating JSON format
The threat actors used their own C2 infra, they merely mimicked solarwinds' traffic!
> and if you tell me that this would have gotten by a regular pull request review on any project that uses a protected main branch, I am laughing
Why would I tell you that, what does this have to do with cloud vs self hosting. Is that a random comment?
> Log4Shell would most likely not have been possible if the project receives actual funding...
I agree but again I ask, why are you talking about the root cause for it? How does that help your self-hosting argument?
> no but when my government pais for its development, they should use open source projects
Who cares? Hoe is being opensource relevant?
> So yeah my original point still stands. If they would have used an open solution to this, which does not require a centralised control server itself, this would not have happened
Ok, I think I see the problem, in your opinion, anything not opensource is cloud???
Just for context, I use/support opensource in a corporate environment, it is hell. Begging opensource devs when your livelihood depends on their cooperation is very unpleasant. Commercial orgs demand reliability, hiring skilled people to support opensource (especially given crappy gov salaries) isn't viable and opensource devs nearly always refuse to provide paid support and SLA.
I would like to see you backup your argument by comparing the number of abandoned opensource projects vs companies abandoning their products. I am currently spending time I don't have supporting opensource sofware abandoned by its creators. Nothing says you don't know the state of foss security more than claiming it is more secure simply by being opensource.
> This would have been found by any tool using static code analysis for security simply because its encoded. At least flagged.
Maybe, that's a big maybe, I see encoded content in .net code all the time. And someone needs to actually review what is flagged. Simply reviewing commits would have caught it too. But what's your point? This thread is not RCA analysis. You are distracting with that to avoid the fact that it was self hosted!
> self hosted does not mean you install it. otherwise slack is self hosted. or that facebook is self hosted just because i install the app on my phone
It means you manage and operate infra it is hosted on. You don't run slack infra but you run solarwinds infra.
> There was no reason for the firewall to even allow this in the first place unless they were using a service outside of their control.
You realize you contradicted your own claims there right? The fact that the self-hosted firewall on random companies needed to block the traffic is why it is called self-hosted, exactly as your wikipedia quote is telling you.
I fear you have picked this hill to die on though.