i don’t understand how people see the xz incident and conclude that open source is insecure. That level of social engineering could easily have worked on a company as well, but it was detected *because* it was open source. All other mechanisms failed, and it was just some random guy poking around that discovered it. That kind of scrutiny doesn’t happen on closed source systems
@kellogh You only have to look at Microsoft at the moment. The company says the attacks are not wild and it was no big deal that their root keys were distributed. Apart from Microsoft's internal staff, no one currently has any information about Microsoft's security.