Earlier quoted context omitted.
> At least with Linux we have thousands of open source developers keeping an eye on things A bit of pithy sarcasm for your morning: Those thousands of eyes worked so well with OpenSSL, didn’t it? Those eyes are less vigilant than you might think, especially when the eyes aren’t being paid to monitor a particular chunk of code.
Yes, they worked pretty well for OpenSSL. The issue was found eventually. In a proprietary system, it may have been there forever.
And not to mention that Windows - the explicitly called out alternative from this article - makes their source available for security companies (as well as general developers who sign up for their MSDN program).