Earlier quoted context omitted.
I think it's more of a point that if you are using something for free, you should think more in terms of "What did I do wrong to cause this? Who did I not support that put us in this situation?". People pointed out that OpenSSL had a miniscule budget and provided tons of value to the world. Once again, all you can say is mea culpa. Either that or they should be creating alternatives and moving away from poorly writte…
Isn't that then an argument against using free software? If the best way to have secure software without being a security expert is to use proprietary software, then that is what we should encourage. FOSS advocates make the opposite argument that FOSS is more secure because there are more eyes on the code.
The point is, when FOSS software has a bug, there's no small set of developers who are responsible. It's, in some small way, collectively all our faults. Like in the case of Bash - apparently for 20 years, we never actually checked if environment variables were executable.