People 'verify' source code far less than people actually believe. The audience of people who actually can are less than people think too. The entropy code was likely read by many people, many times. It means most did not actually understand what was written. Larger projects pay for AppSec teams to do assurance testing / 'audits' because just having visible source code isn't equal to an audit. Suspected and known malware get a more documented, deep analysis by security firms compared to most open source projects.

Replies (1)

The obscurity of this issue specifically is almost the level of Jia Tan inserting a dot to break the sandboxing enable defined in CMakeLists.txt in xz.