Open Source Security
Open source software is often misunderstood as being more vulnerable to attacks due to its accessible source code, but having the source code is not essential for exploitation. The belief that many eyes will catch bugs in open source is also challenged, as it doesn’t guarantee better security. Additionally, writing about vulnerabilities tends to attract more attention than discussing secure practices, reflecting a broader human fascination with failure, akin to the NASCAR effect.In this clip
From this podcast

Software Engineering Radio - the podcast for professional software developers
Episode 66: Gary McGraw on Security
Related Questions