[citation][nom]A Bad Day[/nom]For example, Citi Bank had a major URL flaw where hackers could simply replace some numbers in the URL and log into random accounts. Then then built an automated number generator/enterer to break into hundreds of thousands of accounts.The website designer stated that security and features are incompatible.But no one in the public knew about the flaw, because the bank never revealed it for obvious reasons.[/citation]
That's still highly irresponsible. With all of the website hacking going on, a flaw like that could expose millions of people to theft and fraud. Something Citi would eventually be found negligent for. OTH, if Citi had used OSS, a hole of that magnitude would likely have been found and fixed before the code ever went live. OSS will always be more secure, and fixed faster than close source.