In general, people sometimes ask this question about FOSS and security. Isn't FOSS bad for security, they say, since attackers can look at your code and find the holes so they can break in? What this assumes is that the holes are inevitable and obvious, and all anyone needs to break in is find them. It turns out that this isn't true, as many security-sensitive open source projects from OpenBSD to Mozilla Firefox have demonstrated. Security holes shouldn't exist; help from the community to prevent this is key. The hope that code will be more secure if we only keep it secret - otherwise known as "security through obscurity" - is a pipe dream.