The secure open source fallacy
Most open source advocates, and many security professionals, often say things like “open source software is secure because you can just read the code”. This argument assumes that the ability to read source code directly translates into the ability to understand, verify, and trust it, because you can see the files this software opens or the network sockets it listens on. You can see the kind of network data it sends, and the cryptography it uses.