A friend sent me a link with the subject line, "Why All security should be open source."
The email was short. It did not explain the article or copy its text into the message. The link carried the detail, and I had not replied in the thread.
The subject line made a much larger claim than the note below it. Open source meant the design and code could be inspected, changed, and tested. It did not mean that every open-source system was secure. It meant secrecy was not the only thing protecting the system.
Linux and open-source software were already part of my work. I ran Linux systems at Beatport and dealt with storage, networks, servers, and the software around them. Security questions came with all of it: who could reach a machine, what they could change, and what happened when an assumption was wrong.
The email connected that argument to cars. It did not contain enough of the linked article for me to repeat the technical claim, the number of affected remotes, or the method involved. All I had in the message was the subject and the link.
Cars were already elsewhere in my inbox. I was trying to trade the black RS4-style front panels from my Audi for stock S4 parts. No trade had closed yet. That was a separate hardware problem with body panels instead of code.
I had not answered the open-source email. The subject was still direct enough to stand on its own.
Why should all security be open source?
The link was supposed to make the case.