DEV Community

Discussion on: LINUX KERNEL: Researchers from University of Minnesota had no bad intentions- lift ban

Collapse
 
ssimontis profile image
Scott Simontis

I am all for exposing security flaws, but ethics are key when you do security research. There should have been some forward notification of the maintainers that an information security project was going to contribute potentially lethal code.

This also makes a key point that open-sourcing software does not make secure software. Very few people are qualified to do security reviews on a codebase, and without their expertise, one cannot say code is secure because it has passed public scrutiny.