> Ars seems to be calling all open source software insecure
> The article starts as a gotcha piece
Haha, that’s the problem. You, Netapp, value saving face so very much that you are incapable of constructive response to well-meaning, fair, and honest criticism.
Not netapp and I don’t use or endorse their products. I just don’t like angry mobs or journalism that uses angry mobs as a business model. Too much anger and retribution in the world, not enough forgiveness or compassion. If this code was up for review for months and nobody noticed the printf debugging code in the crypto then I’m sorry but blaming this one bad person seems gratuitous to me, and shortsighted. Are concludes the article by saying this is a bsd/open source problem. How does that help anyone?