Open-source software is often assumed to be more secure because the code is public, but I'm not convinced that visibility alone makes it safer than proprietary alternatives. Heartbleed sat in OpenSSL for two years before being found, and Log4Shell in 2021 showed how a widely used open-source library could be exploited globally. Meanwhile, proprietary vendors can afford full-time security teams and pay bounties, whereas many critical open-source projects run on volunteer time. Should we really trust open source with our most sensitive systems just because the code is auditable?