Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Security – Open Source vs. Closed: It’s a matter of eyes

Posted on April 14, 2014 By Michael Kavka 1 Comment on Security – Open Source vs. Closed: It’s a matter of eyes

For years there has been the whole what is more secure, Open or Closed source? Microsoft has and still takes a beating over this. Truth, though, is a different thing.

We all have heard of Heartbleed by now. The 2 year old security gap in OpenSSL has been all over the news. During all of this, a hole in the much loved Chrome browser that will allow websites to turn on your microphone and record what you are saying was announced. Another bug that had been around for a while (August 2013). Meanwhile, the hated entity known as Microsoft has been pretty much unaffected by these issues. Maybe it is time to remove our preconceived and ancient thought over security in the Open vs. Closed Source world.

The argument has been, from what I have heard and can tell, that Open Source is more secure because you have more eyes looking at it. The code is open and out there so people can find the issues faster and with the collaborative nature of Open Source, will be patched faster. Truth of the matter, as has been shown over the past week, is that it is not the case, and security holes can get past this set of checks and balances just as they can in any Closed Source system. The surprising thing is how long it has taken to find Heartbleed. One would think, with all those eyes looking at the code, that it would have been found much sooner. Of course this has led to the theories of the bug being an NSA backdoor. True or not, the code was still out there for everyone to see.

Chrome is a slightly different issue. Here is a bug that was found over 6 months ago, that still hasn’t been patched. It was brought to Google’s attention and they sat on it. Could this be another NSA (or insert your favorite Government agency here) backdoor? A way to spy on you without warrants? We will never know for sure, but it does show one major hole. Our thinking of Open Source and security is not completely correct. It is not the be all end all.

What has been lost in this is that Microsoft, and its Closed Source implementations of SSL have been free and clear of the Heartbleed problem. Microsoft at one time was awful with security. In this day and age though, it has gotten a lot better. It is responsive to holes, and the amount of out-of-band patches and workarounds for Zero Days is quite speedy. In fact the biggest security holes in Microsoft systems, is usually Java and/or Flash. Flash is still Closed Source, but Java was at one point more open. Java also is embedded in the web very deep. Try using NoScript at it’s tightest levels and see how much of websites get blocked, and how many websites complain about Java not being turned on. Yet through all of this, Microsoft is the one that still takes the blame, especially in the public’s eye. That is because we, the ones in the know, have done little to reeducate the public, and ourselves.

Do not get me wrong. I have nothing but love for the Open Source community. Collaborative efforts are awesome, and the community puts out some fantastic software, and alternatives to Closed Source (and overpriced) programs. It just has to be realized that it is no more secure than Closed Source. In the end it is all about the eyes on the code and the people looking for the holes. Remember Security is a process, not a destination.

Rants, Security, Software Tags:Chrome, Google, Hearbleed, Microsoft, Open Source, Security

Post navigation

Previous Post: Why new PCs? These are good enough!
Next Post: Meanwhile, away from Las Vegas

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Comment (1) on “Security – Open Source vs. Closed: It’s a matter of eyes”

  1. Suspect says:
    May 11, 2016 at 12:11

    The main issue I have with your article is the assumption that Microsoft’s SSL implementation is free of security vulnerabilities. The fact is that Microsoft 0days can remain 0days for years, and can spread across multiple Windows operating systems before they are “discovered” and labeled as a “CVE”. Just because there isn’t a public MS SSL exploit right now doesn’t mean there haven’t been working Microsoft SSL exploits for years.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Ransomware forces Lancaster, Ohio, to take city computers offline September 9, 2026 Joseph Topping
  • Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms September 9, 2026 Zack Whittaker
  • FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching September 9, 2026 Tim Starks
  • WeChat worm could pwn a friend before they even answered the call September 9, 2026
  • Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs September 9, 2026 Serhii Melnyk and Timmy Lister
  • Ukraine prosecutor general steps down amid scam call center bribery probe September 9, 2026
  • Claude Fable Solves a Historical Cipher September 9, 2026 Bruce Schneier
  • Fort Scott restores systems after ransomware attack September 9, 2026 Joseph Topping
  • A “proof” of Fermat’s Last Theorem that fits the margin September 9, 2026
  • Over 36,000 exposed Plex servers vulnerable to recent flaws September 9, 2026 Sergiu Gatlan
  • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure September 9, 2026 Rem Dudas
  • Man gets 15 years for extorting women with AI-generated porn videos September 9, 2026 Sergiu Gatlan

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Ransomware forces Lancaster, Ohio, to take city computers offline September 9, 2026 Joseph Topping
  • Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms September 9, 2026 Zack Whittaker
  • FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching September 9, 2026 Tim Starks
  • WeChat worm could pwn a friend before they even answered the call September 9, 2026
  • Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs September 9, 2026 Serhii Melnyk and Timmy Lister
  • Ukraine prosecutor general steps down amid scam call center bribery probe September 9, 2026
  • Claude Fable Solves a Historical Cipher September 9, 2026 Bruce Schneier
  • Fort Scott restores systems after ransomware attack September 9, 2026 Joseph Topping
  • A “proof” of Fermat’s Last Theorem that fits the margin September 9, 2026
  • Over 36,000 exposed Plex servers vulnerable to recent flaws September 9, 2026 Sergiu Gatlan
  • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure September 9, 2026 Rem Dudas
  • Man gets 15 years for extorting women with AI-generated porn videos September 9, 2026 Sergiu Gatlan
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.