Cover image Science in Perspective

Do we trust it too much? On the hidden fragility of open-source software

How trustworthy is open-source software really? Science in Perspective Talk #13 on 25 November 2025 questions blind confidence and highlights how social and technical factors contribute to security vulnerabilities.

In early 2024, a hidden backdoor in a small piece of open-source software called xz-utils nearly compromised countless computers worldwide. Its source code had been publicly available for years, maintained by a handful of volunteers, and trusted by millions of users. No one noticed the attacker's careful manipulation until it was almost too late.

This incident highlights a deeper problem: we place enormous trust in open-source software simply because it is open. As part of the thirteenth Science in Perspective Talk, Professor Sascha Fahl from the CISPA Helmholtz Centre for Information Security examines why this trust often exceeds what open-source software can guarantee. In his presentation, he highlights how social dynamics, limited resources, and false assumptions make even our most ‘open’ software surprisingly vulnerable and how we can hopefully increase its trustworthiness.

SiP Talk #13 on 25 November 2025

As part of the Science-In-Perspective (SiP) Talks, researchers from the Department of Humanities, Social and Political Sciences invite their colleagues from other departments to discuss current social issues from an interdisciplinary perspective.

SiP Talk #13 is organised by the “Security, Privacy & Society” research group led by Professor Verena Zimmermann and will open with a lecture by Sascha Fahl. Following the lecture titled “Do we trust it too much? On the hidden fragility of open-source software”, human-computer interaction expert April Wang (professor in the Department of Computer Science), head of the Secure and Trustworthy Systems group Shweta Shinde (also a professor in the Department of Computer Science) and Sascha Fahl will discuss trust in open-source software.

The SiP Talk will take place on Tuesday, 25 November at 4.15 p.m. in the RZ building, room F 21 at Clausiusstrasse 59, followed by an aperitif. ETH members and external guests are cordially invited. Admission is free. The event will be held in English.

Note on the translation

This text has been translated for your convenience using a machine translation tool. Although reasonable efforts have been made to provide an accurate translation, it may not be perfect. If in doubt, please refer to the German version.

Should you come upon significant translation mistakes, please send a short message to so that we can correct them. Thank you very much.

Always up to date

Would you like to always receive the most important internal information and news from ETH Zurich? Then subscribe to the "internal news" newsletter and visit Staffnet, the information portal for ETH employees.

JavaScript has been disabled in your browser