Comment by suifbwish
5 years ago
Believe it or not, open sourcing the security code is actually not a great idea. Most of the worlds bot nets run on Wordpress which is open source. Most of the time legitimate actors are not going to read through an entire code base because they have better things to do. Illegitimate actors however have a very high incentive to read through a widely used public code base and do so.
OpenBSD [0] is OSS, practices full disclosure, and is considered highly secure by... everyone.
Wordpress is a mess, but being OSS does not inherently make something less secure.
[0] https://www.openbsd.org/security.html