{"id":2420,"date":"2026-08-05T06:34:44","date_gmt":"2026-08-05T06:34:44","guid":{"rendered":"https:\/\/abilit.eu\/?page_id=2420"},"modified":"2026-08-05T14:39:41","modified_gmt":"2026-08-05T14:39:41","slug":"faq-doesnt-being-opensource-imply-a-security-threat","status":"publish","type":"page","link":"https:\/\/abilit.eu\/index.php\/faq-doesnt-being-opensource-imply-a-security-threat\/","title":{"rendered":"FAQ: \u00ab Doesn\u2019t being Opensource imply a security threat ? \u00bb"},"content":{"rendered":"\n<hr class=\"wp-block-separator has-text-color has-base-color has-alpha-channel-opacity has-base-background-color has-background is-style-default\" style=\"margin-top:var(--wp--preset--spacing--small)\"\/>\n\n\n\n<h1 class=\"wp-block-heading has-text-align-center alignwide\">FAQ: \u00ab Doesn\u2019t being Opensource imply a security threat ? \u00bb<\/h1>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-base-color has-alpha-channel-opacity has-base-background-color has-background\" style=\"margin-top:var(--wp--preset--spacing--small)\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">The term<a href=\"https:\/\/abilit.eu\/index.php\/free-software-freeware-freesoftware-public-domain-and-shareware\/\" data-type=\"page\" data-id=\"380\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em> \u201copen source\u201d or \u201cfree software\u201d <\/em><\/strong><\/a>simply means that you have access to the source code, which allows you to check it for any security vulnerabilities, backdoors, hidden features, etc. By choosing software with published source code, you can double-check that no such issues might arise.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What if I don&#8217;t have time\/ressources to check it ?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You do not need to check it yourself. As free software (for example, released under <a href=\"https:\/\/abilit.eu\/index.php\/gpl-or-not-gpl\/\" data-type=\"page\" data-id=\"399\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>the GPL licence<\/em><\/strong><\/a>), its source code is available to the Community and is therefore checked by numerous users, developers and would-be users. For example, the source code for the Linux kernel is accessible worldwide; it is therefore checked on a daily basis, even by the most demanding customers, such as <a href=\"https:\/\/www.fsf.org\/blogs\/community\/gnu-linux-chosen-as-operating-system-of-the-international-space-station\" data-type=\"link\" data-id=\"https:\/\/www.fsf.org\/blogs\/community\/gnu-linux-chosen-as-operating-system-of-the-international-space-station\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>NASA<\/em><\/strong><\/a>, <a href=\"https:\/\/antigo.ufam.edu.br\/attachments\/article\/15\/Linux_on_the_International_Space_Station.pdf\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>ESA<\/em><\/strong><\/a>, NSA, <a href=\"https:\/\/www.linuxfoundation.org\/press\/press-release\/google-funds-linux-kernel-developers-to-focus-exclusively-on-security\" data-type=\"link\" data-id=\"https:\/\/www.linuxfoundation.org\/press\/press-release\/google-funds-linux-kernel-developers-to-focus-exclusively-on-security\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>Google<\/em><\/strong><\/a>, <a href=\"https:\/\/www.ibm.com\/solutions\/linux\" data-type=\"link\" data-id=\"https:\/\/www.ibm.com\/solutions\/linux\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>IBM<\/em><\/strong><\/a>, <a href=\"https:\/\/linuxsoft.cern.ch\/\" data-type=\"link\" data-id=\"https:\/\/linuxsoft.cern.ch\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>CERN<\/em><\/strong><\/a>, \u2026 not only for its security, but also for issues relating to stability, performance, reliability, and so on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The source code for the Linux kernel (the <a href=\"https:\/\/bfrere.world\/WITMUOSITW.pdf\" data-type=\"link\" data-id=\"https:\/\/bfrere.world\/WITMUOSITW.pdf\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>world\u2019s most widely used operating system<\/em><\/strong><\/a>) is extremely trustworthy, very stable and free from any backdoors, despite certain satirical publications, such as<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full has-custom-border\"><img loading=\"lazy\" decoding=\"async\" width=\"526\" height=\"674\" src=\"https:\/\/abilit.eu\/wp-content\/uploads\/2026\/08\/Warning-Linux-kernel-source-code-leaked.jpeg\" alt=\"The source code for the Linux kernel (the world\u2019s most widely used operating system)\" class=\"wp-image-2421\" style=\"border-width:1px\" srcset=\"https:\/\/abilit.eu\/wp-content\/uploads\/2026\/08\/Warning-Linux-kernel-source-code-leaked.jpeg 526w, https:\/\/abilit.eu\/wp-content\/uploads\/2026\/08\/Warning-Linux-kernel-source-code-leaked-234x300.jpeg 234w\" sizes=\"auto, (max-width: 526px) 100vw, 526px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Software whose source code cannot be verified (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Proprietary_software\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/Proprietary_software\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>proprietary software<\/em><\/strong><\/a>) offers <a href=\"https:\/\/www.the20.com\/blog\/the-danger-of-proprietary-software\" data-type=\"link\" data-id=\"https:\/\/www.the20.com\/blog\/the-danger-of-proprietary-software\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>no guarantee of stability or security<\/em><\/strong><\/a>, other than the level of confidence you grant to its publisher\u2026 <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is a decision that must be taken with great caution, especially as it has been common knowledge for years, if not decades, that the major proprietary software publishers (mainly US) have <a href=\"https:\/\/en.wikipedia.org\/wiki\/PRISM\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/PRISM\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>collaborated with espionage or intelligence agencies<\/em><\/strong><\/a>, thereby undermining any trust that might be placed in such organizations and\/or countries.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full has-custom-border\"><img loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"525\" src=\"https:\/\/abilit.eu\/wp-content\/uploads\/2026\/08\/image.png\" alt=\"Major proprietary software publishers (mainly US) have collaborated with espionage or intelligence agencies.\" class=\"wp-image-2422\" style=\"border-width:1px\" srcset=\"https:\/\/abilit.eu\/wp-content\/uploads\/2026\/08\/image.png 700w, https:\/\/abilit.eu\/wp-content\/uploads\/2026\/08\/image-300x225.png 300w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Even security-focused software, such as the <a href=\"https:\/\/en.wikipedia.org\/wiki\/OpenSSL\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/OpenSSL\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>OpenSSL library<\/em><\/strong><\/a>, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Secure_Shell\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/Secure_Shell\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>SSH<\/em><\/strong><\/a>, <a href=\"https:\/\/en.wikipedia.org\/wiki\/OpenVPN\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/OpenVPN\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>OpenVPN<\/em><\/strong><\/a>, <a href=\"https:\/\/en.wikipedia.org\/wiki\/RSA_cryptosystem\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/RSA_cryptosystem\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>RSA implementations<\/em><\/strong><\/a>, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Time-based_one-time_password\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/Time-based_one-time_password\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>TOTP<\/em><\/strong><\/a>, \u2026 is open source software: security through obfuscation is not a requirement; publishing the source code is a better way to ensure its robustness, as it allows external experts to verify that it contains no potential vulnerabilities.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion: <\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">The use of a software that is delivered to you, also in source-code format is the best way to ensure its stability, reliability, security, aside of its <a href=\"https:\/\/abilit.eu\/index.php\/why-lts\/\" data-type=\"page\" data-id=\"615\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>Long-Term maintainability<\/em><\/strong><\/a>.<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On the same subject, read here about \u00ab <a href=\"https:\/\/abilit.eu\/index.php\/faq-does-using-your-scada-system-involve-you-having-remote-access-to-our-data-or-our-facilities\/\" data-type=\"page\" data-id=\"2425\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>Does using Scada-LTS implies you to have remote access to it ?<\/em><\/strong><\/a> \u00bb<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Don&#8217;t miss neither our related page, about <a href=\"https:\/\/abilit.eu\/index.php\/faq-why-dont-you-recommend-windows-as-operating-system-as-everybody-else-does\/\" data-type=\"page\" data-id=\"2442\" target=\"_blank\" rel=\"noreferrer noopener\">&#8220;<strong><em>Why Linux and not Windows ?<\/em><\/strong>&#8220;<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-base-color has-alpha-channel-opacity has-base-background-color has-background\" style=\"margin-top:var(--wp--preset--spacing--x-small)\"\/>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large has-custom-border\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"97\" src=\"https:\/\/abilit.eu\/wp-content\/uploads\/2025\/10\/image-89-1024x97.png\" alt=\"\" class=\"wp-image-336\" style=\"border-width:1px;object-fit:cover\" srcset=\"https:\/\/abilit.eu\/wp-content\/uploads\/2025\/10\/image-89-1024x97.png 1024w, https:\/\/abilit.eu\/wp-content\/uploads\/2025\/10\/image-89-300x28.png 300w, https:\/\/abilit.eu\/wp-content\/uploads\/2025\/10\/image-89-768x73.png 768w, https:\/\/abilit.eu\/wp-content\/uploads\/2025\/10\/image-89-1536x145.png 1536w, https:\/\/abilit.eu\/wp-content\/uploads\/2025\/10\/image-89-2048x194.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>FAQ: \u00ab Doesn\u2019t being Opensource imply a security threat ? \u00bb The term \u201copen source\u201d or \u201cfree software\u201d simply means that you have access to the source code, which allows you to check it for any security vulnerabilities, backdoors, hidden features, etc. By choosing software with published source code, you can double-check that no such [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-2420","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/abilit.eu\/index.php\/wp-json\/wp\/v2\/pages\/2420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/abilit.eu\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/abilit.eu\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/abilit.eu\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/abilit.eu\/index.php\/wp-json\/wp\/v2\/comments?post=2420"}],"version-history":[{"count":7,"href":"https:\/\/abilit.eu\/index.php\/wp-json\/wp\/v2\/pages\/2420\/revisions"}],"predecessor-version":[{"id":2462,"href":"https:\/\/abilit.eu\/index.php\/wp-json\/wp\/v2\/pages\/2420\/revisions\/2462"}],"wp:attachment":[{"href":"https:\/\/abilit.eu\/index.php\/wp-json\/wp\/v2\/media?parent=2420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}