Earlier quoted context omitted.
> Debian SSL bug lasted 2 years. Open source means little for security. How many examples can you come up with? Was this specific bug being actively exploited when it was discovered?
> How many examples can you come up with? A bug caused by prettying the code, which was secure from upstream, which is in an important, widely used, supposedly secure bit of code isn't a good enough example? > Was this specific bug being actively exploited when it was discovered? Many Linuxes used to ship with lots of services running. That lead to many rooted boxes being used to deliver spam. Open Source fixed the p…
It's a good example. Can you come up with more? Because, you know, it's just one instance of a problem. It says nothing on how pervasive it is.
> For years anyone putting an MS server onto the Internet ran the risk of very quick exploitation.
IIRC, there was a time when the average time between install and first invasion was in the 40 seconds range.