i don’t understand how people see the xz incident and conclude that open source is insecure. That level of social engineering could easily have worked on a company as well, but it was detected *because* it was open source. All other mechanisms failed, and it was just some random guy poking around that discovered it. That kind of scrutiny doesn’t happen on closed source systems
@kellogh It's the same reason people see a car beached on that hump in the middle of a roundabout and think that makes roundabouts dangerous... they don't understand that what they're seeing is the safety measures working. That beached car is one that would have hit other humans. That found exploit is one that would have gone unfound.