On TechRepublic: Who lies the most on resumes?
BNET Business Network:
BNET
TechRepublic
ZDNet

July 20th, 2008

Do open source applications take security seriously?

Posted by Dana Blankenhorn @ 1:42 am

Categories: General, Applications, Development, Implementations, Security, support, marketing

Tags: Security Best Practice, Open Source, Security, Dana Blankenhorn

Fortify technical advisory board, 01-2007, by Gary McGraw of Cigital.comNot according to the folks at Fortify, who today are issuing a blistering report claiming open source projects and companies don’t take security seriously at all.

Security best practices are missing in the open source space, Fortify says. (Gary McGraw interviewed Fortify’s technical advisory board in January, 2007. Here are some of those heroes.)

“If there’s an application hack at Microsoft you would know who to go to. But what about open source? The answer isn’t always clear,” director of product marketing Rob Rachwald told ZDNet.

It should be noted before going forward that Fortify specializes in this sort of security life cycle work. One can argue they are arguing from the position of a vendor who stands to benefit if its demands for the industry are met.

But this should not invalidate the point, which is that security is a process that must be followed consistently, and many open source projects do this only haphazardly.

Here is the way way CEO John Jack CTO Roger Thornton put it when he got on the call:

There were 215 million data breaches from 2004-2006. Something is going on.

The bad guys have figured out how to exploit software, and one of the key elements is something firewalls can’t deal with and anti-virals don’t deal with – the applications layer.

Most hacks today are at the application layer, anywhere from 75-92%.

Open source projects that leave vulnerabilities open threaten the integrity of entire installations.

computer securityI thought at first this might be a crack at non-professional open source projects, as opposed to the work of professional open source companies.

Fortify’s research indicates both sides are equally at fault here.

“Some commercial companies maintain open source packages and I wish they were doing a better job on this than non-commercial projects,” admitted Jack. “There’s no swing one way or another in terms of security practices.”

Secure development, real-time monitoring, and the hiring of full-time security directors are all steps which need to be taken, Rachwald concluded. Open source needs to take security as seriously as Microsoft does.

“One thing I don’t think developers understand is the difference between security and quality. Security is gray. Quality is black and white. That’s why a security process is essential, because it’s not black and white.”

This should be the chief open source challenge for the next year, because if application security is not addressed, it’s hard to see much more progress coming in the enterprise market.

Dana Blankenhorn has been a business journalist for 30 years, a tech freelancer since 1983. See his full profile and disclosure of his industry affiliations.

Email Dana Blankenhorn

  • Talkback
  • Most Recent of 43 Talkback(s)
Unfairly focuses on open source
I've worked on many projects for many commercial software companies and the problem with secure software isn't limited to just the open source products. There are very few software engineers who are ... (Read the rest)
Posted by: kkernes Posted on: 08/25/08 You are currently: Logged In | Log out
Good Point, Good Post bcarpent1228@...   | 07/20/08
RE: Do open source applications take security seriously? ShaunConnolly   | 07/20/08
Don't forget the corollary rpmyers1   | 07/20/08
I think you are on to something ... n0neXn0ne   | 07/20/08
Inflating title with little sustance wackoae   | 07/20/08
instead of ... n0neXn0ne   | 07/20/08
That was one example DanaBlankenhorn  ZDNet | 07/21/08
Ok, give us another one Hemlock Stones   | 07/21/08
Here's a list FatherJ   | 07/21/08
OUCH!... socialism=nowhere   | 07/21/08
You just hit the nail on the head.... dunn@...   | 07/22/08
What a crock: "So much for "open source patching quicker". bmerc   | 07/22/08
PHP? grail@...   | 07/22/08
Actually, No. FatherJ   | 07/21/08
Actually, Yes. Hemlock Stones   | 07/21/08
Do some homework. FatherJ   | 07/21/08
The links you provided do not support your claim bmerc   | 07/22/08
I think YOU need to do a bit more homework... bmerc   | 07/22/08
Get over yourself FatherJ   | 07/22/08
YAWN...not another one...nt socialism=nowhere   | 07/21/08
How do you patch what you don't know about? socialism=nowhere   | 07/21/08
That's exactly his point, genius. bmerc   | 07/22/08
most Unix/Linux administrators would deowll   | 07/21/08
"...fix it themselves of (or I think) purchase a solution..." socialism=nowhere   | 07/21/08
"I'm not buying the source so I have the ability to fix it..." bmerc   | 07/22/08
Taking security seriously. sysop-dr   | 07/21/08
RE: Do open source applications take security seriously? adminlong6458@...   | 07/21/08
It's not a run for closed source DanaBlankenhorn  ZDNet | 07/21/08
RE: Do open source applications take security seriously? gsuser   | 07/21/08
Anyone who says what you're saying they do is a few bricks short of a load TtfnJohn   | 07/21/08
Stop lying bmerc   | 07/22/08
Fortify looking for consulting work, really TtfnJohn   | 07/21/08
2 words for you as an example... MrGrave   | 07/21/08
MrGrave offers wisdom DanaBlankenhorn  ZDNet | 07/21/08
Open source needs to take security as seriously as Microsoft does. The Mad Hatter   | 07/21/08
RE: Have to use a convention to report security issues uthaiyashankar@...   | 07/21/08
RE: Do open source applications take security seriously? Mitch 74   | 07/22/08
You assume the vulnerability is public.... dunn@...   | 07/22/08
Do I know how many... Mitch 74   | 07/22/08
youre nuts! billw1234   | 07/23/08
And MicroShaft Windoze is EVER So Secure, Right? drprod@...   | 07/23/08
RE: Do open source applications take security seriously? Greenknight_z   | 07/23/08
Unfairly focuses on open source kkernes   | 08/25/08

What do you think?

No Trackbacks Yet

The URI to TrackBack this entry is:
http://blogs.zdnet.com/open-source/wp-trackback.php?p=2675

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs