ie8 fix
madison

Reply to Message

RE Busting "Eyes on the code" "myth".
enduser_z 3rd Feb 2009
I don't see where the Linux kernel having a greater volume of vulnerabilities identified/reported busts the "Eyes on the code" "myth" as you suggest. At the worst, this suggests that security analysts and others are more interested in identifying vulnerabilities in released Linux kernel code vs code under testing. I suspect this is just the nature of how they are motivated, and not specific to any OS.

The problem is no one can prove the ratio of undisclosed to disclosed vulnerabilities for any OS or application. If anything more vulnerabilities disclosed would seem to prove "eyes on the code" is working as advertised. Your real criticism should seem to be with the kernel development/release process itself, not with how well eyes on the code works.
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

ie8 fix