Found late, and found in a an error-prone environment.
This weakens the oft-implied "proof by open-sourceness", and has brought up some criticism on how open source projects are ran and incentivized.
Doesn't mean "Open Source sux", just some nuanced criticism, ok?
I assume that no one in its right mind would refute a nuanced criticism of Open Source, but the grandparent just didn't think it necessary to be nuanced or elaborate or make some concrete point at all. He just went for the quick pun and is being down-voted for it.
agreed
The audit occurred because testing revealed the presence of a problem. Shutting the stable door after the horse has bolted is no vindication of open source.
How would you have found the bug without it being open source? You think companies pay for these open public audits on proprietary software?
The vulnerability was first found by a fuzzer, which would have worked equally well on closed-source software. And I believe the fuzz tester (part of Codenomicon's "Defensics") is also closed-source.
You misunderstand - how would the public have found out about the results of that audit? There is no incentive to release this information for a closed product; very much the opposite.
This point is important. Testing came first and then auditing. In other words, black box testing and then white box testing. Why pretend you are better off just because you have millions of lines of inscrutable source?