Security Projects In his seminal work The Cathedral and the Bazaar, Eric Raymond put forward the claim that “given enough eyeballs, all bugs are shallow.” He dubbed this Linus’ Law, in honor of Linux creator Linus Torvalds. It sounds like a fairly self-evident statement, but as the Wikipedia page points out the notion has its detractors. Michael Howard and David LeBlanc claim in their 2003 book Writing Secure Code “most people just don’t know what to look for.”

A new report from the Coverity Scan project today indicates that a great many people do know what to look for, and open source software is at least on par — if not better than! — proprietary software with respect to software defects. The Coverity Scan project evaluated selected open source projects and a number of anonymous proprietary codebases to identify “hard-to-spot, yet potentially crash-causing defects.” The results reinforce Linus’ Law.

