Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Maybe. Quantifying your counter argument would help. If one developer writes 90% of the code there is signal in the statistics.


Counting CVEs is a trivially easy argument to debunk. It’s a topic well written about by many open source contributors and security researchers. It’s a topic discussed on here frequently too. And it’s a topic that common sense alone should be able to debunk, should one spend a few minutes thinking about it rationally.

However I have written a more in-depth reply about why counting CVEs is meaningless here:

https://news.ycombinator.com/item?id=27969587




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: