The biggest problem I see with security in the open source community is the desire to tinker with the code. When we can find a way to do trusted distribution via signed (by multiple signors) source code packages AND convince people to spend more time on bug fixing than feature adding, then I'll think we'll get somewhere.
Hey, I resemble that remark! The C2 system I worked on 3 years ago brought rsh, rlogin AND NFS through formal evaluation.
The biggest problem I see with security in the open source community is the desire to tinker with the code. When we can find a way to do trusted distribution via signed (by multiple signors) source code packages AND convince people to spend more time on bug fixing than feature adding, then I'll think we'll get somewhere.