The 'Many Eyes' Fallacy of Open Source Security
Description
This meme uses the 'Shut Up Seagull' format, where a large yellow emoji-style hand pinches a seagull's beak closed, silencing it. The background is dark and indistinct. Text at the top reads, 'Open Source Software is more secure because absolutely anybody could audit the'. At the bottom, aligned with the silencing action, is the single word 'shut'. The image includes a small watermark 'imgflip.com' in the bottom-left corner. The meme humorously cuts short a common but naive argument in favor of open-source security. The technical context, especially given the post date of December 2021, points directly to the Log4j (Log4Shell) vulnerability crisis. It satirizes the 'many eyes' theory, where the theoretical possibility of anyone auditing the code is supposed to guarantee its security. Experienced engineers know that 'could' doesn't mean 'does,' and critical, widely-used libraries can go unaudited for years, leading to massive security vulnerabilities. The joke resonates with senior developers who understand that the security of the software supply chain often rests on underfunded and under-maintained open-source projects
Comments
57Comment deleted
The 'many eyes' on that critical OSS dependency turned out to be one unpaid maintainer who burned out in 2017 and a CVE that just says 'good luck'
Sure, the repo is public - right next to the 1,237 other tabs every "potential auditor" swears they'll read after the sprint retro
After 20 years in tech, I've learned that 'many eyes make all bugs shallow' actually translates to 'everyone assumes the other guy already looked at it' - just like how we all assumed someone was auditing OpenSSL before Heartbleed, or Log4j before... well, you know
'Given enough eyeballs, all bugs are shallow' - turns out the eyeballs were all on the README, while the JNDI lookup sat unreviewed for eight years
Ah yes, the classic 'many eyes make all bugs shallow' argument - conveniently ignoring that those eyes are usually skimming Stack Overflow at 2 AM, not performing rigorous security audits of your dependency tree's dependency tree. Turns out 'anybody could audit it' and 'anybody actually does audit it' are separated by approximately 10,000 unpaid volunteer hours and a critical CVE that's been sitting there since 2015
Linus’s Law works - until you realize those “many eyes” are GitHub stars, not reviewers, and the xz backdoor still ships
Open‑source security model: infinite reviewers in the spec, a bus‑factor‑1 maintainer in production
Many eyes make bugs shallow - until those eyes are glued to Jira tickets instead of the codebase
And what's actually wrong here? Comment deleted
I think its refering to log4shell. Comment deleted
people claim that open source is better because anyone can audit, but no one guartantees that the code will be checked Comment deleted
So you should check it by yourself Comment deleted
Memes don’t need to be fun. They also may teach us something. It’s DevMeme, not fun meme, you know🤔 Comment deleted
Well if it were to be a real Backdoor, not a bug, it could be found far more easy. Comment deleted
Original please Comment deleted
let it be the original Comment deleted
I use arch btw Comment deleted
thanks to arch linux my netbook can handle 10 fps on low graphics minecraft (compared to 2 fps on winxp) Comment deleted
Win xp supports minecraft? Comment deleted
winxp supports java 8, thats enough for 1.12.2, which was tested Comment deleted
How old is 1.12.2? Comment deleted
4.5 years (summer 2017) Comment deleted
Well Minecraft is Java. Comment deleted
thanks to arch linux and optifine, I get 60fps on my pentium shitshow Comment deleted
Is OF faster than vanilla? Comment deleted
sometimes Comment deleted
if you turn all the settings down, yes, massively. Comment deleted
u woman, u do not Comment deleted
D: Comment deleted
Lol Comment deleted
Well, this vulnerability was found because the open source code was audited, so the problem was patched... Comment deleted
That's the idea behind the phrase. Free software is not magically better with less bugs, community just has a way to actually discover and fix them. Comment deleted
i dont see how that is a bad thing? Comment deleted
Maybe because it's not. Comment deleted
Ah i see. Necromancy Comment deleted
i don't think so, at least because 1.16 crashed under java 8 Comment deleted
I thought OF is just bringing better Graphics... Comment deleted
you need extra shaders for the real meat Comment deleted
optifine eats 2x ram... (allocate 4GB for minecraft, optifined minecraft uses 7GB) Comment deleted
I have 4GB RAM, stop shitting me Comment deleted
I that Comment deleted
only 32x resource packs, BUT same settings with and without OF Comment deleted
pics will be soon Comment deleted
Optifined minecraft 1.17.1 Private bytes for java: 3.1GiB Allocates: 2.1GiB -Xmx 4g from where 1GiB? Comment deleted
> why xp > how big is the render distance > openjdk or oracle java? Comment deleted
openjdk 16 Comment deleted
31 render Comment deleted
31 render distance? holy shit no wonder lmao Comment deleted
I got like 2 or 4 chunks render distance btw, not ideal, but I have to take what I can get with my 1.9GHz Pentium Comment deleted
how can i set render distance below 2 chunks Comment deleted
impossible afaik Comment deleted
maybe with mods Comment deleted
NOT xp, but xp-styled win7 Comment deleted
still bad Comment deleted
No optifine 1.17.1 allocated 2.4GiB private bytes 3.4GiB maybe it is not reproducible now, because I updated versions? Comment deleted
firefox uses 28GiB virtual memory, but i meant not virtual Comment deleted
Hahahahahaa Comment deleted