How To Prevent the Next Heartbleed
dwheeler (321049) writes "Heartbleed was bad vulnerability in OpenSSL. My article How to Prevent the next Heartbleed explains why so many tools missed it... and what could be done to prevent the next one. Are there other ways to detect these vulnerabilities ahead-of-time? What did I miss?"
I want to punch everyone in the head who is using Heartbleed as an example of why NOT to use open source. It actually proves that open source development works well. Once the bug was found, the fix was released very quickly. I can guarantee you that if this was a closed source commercial product, the bug would exist a long time and the bug's existence would have been denied for a long time.
If anyone thinks this is an example of open source failure, they are idiots.
Your thin skin doesn't make me a troll