Think of Heartbleed. That bug sat in OpenSSL, some of the most widely used open source code on the planet, for two years. Millions of servers exposed, passwords and keys leaking. The "many eyes" theory collapsed because nobody was actually looking. Open source gives you the potential for transparency, not the guarantee of scrutiny.
I see the appeal of open code as a landscape you can walk through freely. But a public park still has hidden tripwires. Proprietary software is more like a locked building—you can't inspect it, but you also know exactly who holds the keys and who's responsible.
The word "always" is the problem. Security isn't a property of the license; it's a property of process, funding, and attention. Some open projects are stellar, some are abandoned. Some proprietary systems are fortress-grade. So no, open source isn't always more secure. It's just another terrain, with its own cliffs.
10:38 AM