General Discussion
In reply to the discussion: Iowa doesn't smell right [View all]TheBlackAdder
(29,981 posts).
There's a fallacy that open-source software is more secure because it is reviewed by others.
In reality, no one really reviews it besides academia, nation states and hackers. They do not have to disassemble the code because the source is given to them to exploit. On top of that, many of the open-source groups are infiltrated with hackers and nation state developers to inject rogue code or malware.
As an example: Many companies are moving to this Spring Open Development platform, because it's free. It's also rife with hundreds of vulnerabilities.
While an app might be custom built, it is often done using widgets, plug-ins, or code development tools that are laced with vulnerabilities that open the application up to remote access, injection, takeover, or updating of data.
=======
Read the following article and then travel to Sonatype, register and get the free download of the report.
https://www.theregister.co.uk/2018/09/25/open_source_security/
Just search: SONATYPE OPEN SOURCE SECURITY
.