Linux.com

How can they validate non-open source?

Posted by: Anonymous Coward on February 09, 2007 08:20 PM

This whole article baffles me. How can anyone certify software for which they do not see the source? Exhaustive testing of a package this size is not possible. You can't be sure you know everything it is designed to do unless you see source code.

#

Return to OpenSSL gets hard-fought revalidation