Advertisement
  • Networking
  • Storage
  • Security
  • Mobility and Wireless
  • Applications
  • OS and Servers
  • Mid-sized Business
  • Green IT
  • IBM Infoclipz

Home | News | Insight | How-tos | Case studies | Interviews | Briefings | Reviews | Blog

Computer & Internet Security News

22 July 2008

Open source could learn from Microsoft

By Maxwell Cooter, Techworld

Companies who opt for an open source software within their organisations could be leaving themselves open to security breaches.

Advertisement

That's according to software company Fortify which has researched the implementation of several open source projects and found them lacking, with one executive suggesting that they could learn from Microsoft in how to improve security.

The research completed by security consultant Larry Suto, examined 11 of the most common Java open source packages. Fortify worked with open source maintainers and examined documented open source security practices to evaluate the level of security. The results were disappointing: the Fortify study found that many Open Source Software (OSS) development communities have not yet adopted a secure development process and often leave dangerous vulnerabilities unaddressed.

Rob Rachwald, Fortify's director of product marketing said that open source developers should be prepared to learn from companies like Mozilla, which has recently hired Rich Mogull as its security chief.

Even Microsoft could be help up as an example of good security practice. Rachwald said that had improved its security policies no end, “It's a company that used to be severely slammed for its security procedures but, following the 2002 Trustworthy Computing memofrom Bill Gates, that's all changed. Gates simply said 'if it's a choice between functionality and security, always choose security' and the company has changed its mindset, said Rachwald.

He added that proprietary software developers tended to think far more about security issues than open source developers did – although he conceded that this wasn't always the case.

Rachwald said that a lot of the developers' problems started with their initial training. “The problem starts with the developers themselves and in particular with their education. “They've normally majored in computer science and just haven't had the grounding in security issues.”

Advertisement

He said that it was true that the openness of open source projects would help secure vulnerabilities. But, he said, companies should ask themselves what would they rather be “great at fixing security problems or preventing those problems from happening in the first place.”

According to Fortify, there are three key ways to improve the security of open source projects: first, appoint a security expert, someone with a thorough understanding of security issues. ”The difference between you and me and a security expert,”said Rachwald, “is that you and I enter a shop and think about what we could buy, the security expert enters and thinks about what he could steal.”

Second, build security processes within the software development lifecycle and third, use the correct tools to test the security procedures.

<<newer article | back to index | older article>>

close

Email this article to a friend or colleague:




PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

close
  • This article is now being printed.
close

What are your views on this subject? Use the form below to post a comment on this article up to 1000 characters.


Characters remaining:

close

Click below to add 'Open source could learn from Microsoft' to your blog.



If you do not have a ComputerworldUK Account and would like to use this feature, please Register.

If you are a registered, logged-in user, this will post the title and first paragraph of this story to your blog to share with your readers.

What is this?

Comments received


bad spell said on Tuesday, 22 July 2008

Ever heard of spell check? "open source softwar ", "Even Microsof could"

The Pedant said on Tuesday, 22 July 2008

No, but I've heard of a spelling check... Have you ever heard of a grammar check? LOL!

Advertisement
Advertisement

WHITE PAPERS

  • BPM, SOA and Web 2.0: Business transformation or train wreck?
    Organisations must not only promote change from within, but they must also be agile enough to quickly adapt to evolving markets, policies, regulations, and business models. Fortunately, the convergence of a trio of technologies and business practices—business process management (BPM), service-oriented architecture (SOA), and Web 2.0—is providing a solution.
  • The Social Enterprise: Using Social Enterprise Applications to Enable the Next Wave of Knowledge Worker Productivity
    On the face of it, social software seems an unlikely example of enterprise collaboration. Aren’t social networks a fad? What does sharing photos or connecting with college buddies have to do with getting work done?
  • Unified Threat Management
    This white paper looks at the emergence and inadequacies of unified threat management (UTM) products, and introduces a new solution from Check Point.
  • Delivering an Effective Backup and Recovery Service
    Rapid data growth and the need for greater data availability place a demand on organisations to provide an effective backup and recovery service. Yet businesses have often been satisfied with just minimal provision. It is only when a disaster arrives that it becomes clear how inadequate this approach is. This white paper helps organisations make the right decisions about how best to prevent data loss and potentially catastrophic IT failure.
  • Oracle Universal Content Management
    The key features and benefits to an enterprise of Oracle's Universal Content Management solution. Easily manage content through the whole lifecycle, streamline business processes and improve customer service and relationships.

Techworld topic pages