Open Source Security

The cluster debates whether open source software is more secure and trustworthy than closed source due to its auditable code, with proponents emphasizing community review and skeptics citing vulnerabilities like those in OpenSSL.

📉 Falling 0.4x Security
6,133
Comments
20
Years Active
5
Top Authors
#7134
Topic ID

Activity Over Time

2007
2
2008
21
2009
48
2010
68
2011
66
2012
122
2013
441
2014
408
2015
384
2016
506
2017
437
2018
468
2019
361
2020
476
2021
551
2022
454
2023
490
2024
440
2025
353
2026
39

Keywords

e.g jessfraz.com US EFF OP schneier.com OpenSourceand OSS ISO9001 OpenSourceandSecurity open source source open audit code source code secure security software closed

Sample Comments

t0mas88 Jul 18, 2020 View on HN

If it's open source and people can check that it doesn't anything hidden, yes

pritambaral Oct 4, 2017 View on HN

Does closed source not have security issues?

ipaddr Aug 11, 2024 View on HN

You can't hide something in open source code for those who audit what they use. You can for those who just install without reviewing.

unnouinceput Nov 14, 2020 View on HN

open source means you can review the code. pretty sure, since this comes from them, is intensely scrutinized. So again, not worried.

sak5sk Jul 10, 2025 View on HN

It's open source, others can audit it if you can't.

nwh Oct 22, 2013 View on HN

Open source does not mean secure. Half the time nobody even reads the source, let alone compares the binaries to the repository.

trimtab Jun 30, 2015 View on HN

You can't trust what you cannot audit. Open Source is auditable software. You can hire non-vested 3rd parties to validate it.

morjom Nov 9, 2021 View on HN

Wouldn't open-source and/or auditing alleviate this?

oakwhiz Jan 20, 2026 View on HN

This is open source. You're thinking of trusted execution, audits, licenses with disclosure requirements, or signed affidavits which is a totally different thing than open source. Otherwise you could claim that just about anything isn't open source just because you're not sure what is happening on someone else's computer.

spion Jan 14, 2019 View on HN

Nothing is 100% guaranteed, but with an open source project, given enough users, its far less likely for someone to be able to bury nefarious stuff without many eyes looking at it and at least one person sounding an alert.