Others have mentioned this, but to make sure all context is clear:
- FOSS software is not inherently more secure.
- New FOSS software is probably as secure as any closed source software, because it likely doesn't have many eyes on it and hasn't been audited.
- Mature FOSS software will likely have more CVEs reported against it than a closed source alternative, because there are more eyes on it.
- Because of bullet 3, mature FOSS software is typically more secure than closed source, as security holes are found and patched publicly.
- This does not mean a particular closed source tool is insecure, it means the community can't prove it is secure.
- I like proof, so I choose FOSS.
- Most people agree, which is why most major server software is FOSS (or source available)
- However that's also because of the permissive licensing.
This is only half of the meme.