I was not aware of the Shellshock bug when I posted that comment (in fact, I only learned about it a few hours after posting my reply). That bug couldn't illustrate my point any better that at least you can examine the damn code yourself to a) verify the bug exists, b) see that it does what the sec experts say it does on the tin, and c) to crowd-source as many possible answers to it as possible. Seriously? Pushing the merits of our arguments aside for a moment, you're being a bit myopic.
Power management, mobile and firmware developer on Linux. Security developer at nvidia. Ex-biologist. Content here should not be interpreted as the opinion of my employer. Also on Mastodon and Bluesky.
Re: Open source is not a panacea
Date: 2014-09-30 02:30 am (UTC)