On TV.com: Watch Jimmy Fallon's GLEE parody
BNET Business Network:
BNET
TechRepublic
ZDNet

April 4th, 2006

Open source gets results, while Microsoft blames malware on 'stupid users'

Posted by Ed Burnette @ 2:21 pm

Categories: Community, General, Microsoft

Tags:

Two very different news articles crossed my desk today. First, there was a report that open source developers on 32 projects fixed 900 bugs in two weeks that were reported by an automated scan program from Coverity, sponsored by a grant from U.S. Homeland Security. Second, a presentation was given by a Microsoft security official who said that rootkits, phishing, trojans, spyware, and other forms of malware had gotten so bad on Windows that IT departments needed to come up with a fast way to "nuke the systems from orbit", i.e., wipe out the hard drive and start over. He goes on to say that phishing is a problem because "there really is no patch for human stupidity".

Suppose for a moment that popular open source systems like Linux or Samba were suddenly under the same wide ranging attacks that the proprietary Microsoft systems are under now.  What do you think would happen?

I predict that lots of people, all over the world, would get fed up and start fervently scanning for holes, first by hand and then by ever more sophisticated automated scans over the source code and analysis at run time. Lists of bugs would be created, reputations put on the line, and those lists would be pounced upon by some of the same people that pounced on the Coverity list.

While the problem would not be solved in two weeks, there would certainly be a heck of a lot of progress in a hurry, compared to the years of fixes that have trickled out of Redmond. Users are plenty fed up now, but what can even knowledgeable users do to help without the source code? Nothing.

What do you think? Which is inherently more *securable*, open source or closed source?

Ed BurnetteEd Burnette is a professional developer and author of several articles and books about computing including Hello, Android: Introducing Google's Mobile Development Platform, 2nd Edition. For disclosure of Ed's industry affiliations, click here or to view his full profile click here.

Email Ed Burnette

Subscribe to Dev Connection via Email alerts or RSS.

  • Talkback
  • Most Recent of 42 Talkback(s)
they are
but the retards disregard or better yet; disable them. (Read the rest)
Posted by: JamesDoyle Posted on: 01/04/10 You are currently: a Guest | | Terms of Use
Give me a break, no one writes virii for Linux  No_Ax_to_Grind | 04/04/06
And this is why  Yagotta B. Kidding | 04/04/06
Here's a free break coupon  D-T-Schmitz | 04/04/06
As I have said before  Roger Ramjet | 04/05/06
Viruses on Linux  INGOTIAN | 04/05/06
I'd like to know - how would OSS put a patch in the *nix kernel for phising  zzz1234567890 | 04/12/06
the above post was posted at wrong thread  zzz1234567890 | 04/12/06
Not a system problem  MrKimm | 06/26/06
OPen source is secure???  No_Ax_to_Grind | 04/04/06
Not according to your source  Yagotta B. Kidding | 04/04/06
You're not talking about zone-h.org are you?  toadlife | 04/04/06
LOL, way to shoot yourself in the foot  mdsmedia | 04/04/06
Web servers are too easy to hack...  Ed BurnetteZDNet Moderator | 04/04/06
And if the server is  Hugh Jass | 04/04/06
The "virii" virus  jbroche18 | 04/05/06
Virus - or viruses or viri.  colcandi@... | 04/05/06
Credit card companies being hacked?  Roger Ramjet | 04/05/06
Shape shifting  handydan918 | 04/05/06
Open Source  oldfellow | 04/05/06
I'll call your strawman  hawkeyeaz1 | 04/05/06
Maby because there are no Windows servers to hack?  MrKimm | 06/26/06
Worst blog on ZDNet in a long time  toadlife | 04/04/06
Sorry you didn't like it  Ed BurnetteZDNet Moderator | 04/05/06
Why is it that . . .  sporkfighter | 09/23/09
they are  JamesDoyle | 01/04/10
Mixing apples and oranges  Mark Miller | 04/05/06
It's all fruit to the users  Ed BurnetteZDNet Moderator | 04/05/06
Okay, but you were comparing OSS to MS  Mark Miller | 04/05/06
Some of this is preventable  Mark Miller | 04/05/06
It takes a little knowledge, but if you set up...  Ed BurnetteZDNet Moderator | 04/05/06
Unfortunately  Mark Miller | 04/05/06
There's profit in those patches!  Mr. Roboto | 04/05/06
Its because of the community  MrKimm | 06/26/06
So I guess you prove MS point  martyt | 04/05/06
Scams can fool non-stupid people  Ed BurnetteZDNet Moderator | 04/05/06
The end of Microsoft  Dr_Zinj | 04/06/06
Money in errors  Altotus | 04/10/06
Want to know - how would OSS put a patch in the *nix kernel for phising  zzz1234567890 | 04/12/06
Stupid Users  Aaron A Baker | 04/12/06
Fixing:  Mad-n-Fla | 06/26/06
Windows users ARE dumber  Mad-n-Fla | 06/26/06
Re: Windows users ARE dumber  Jack Luminous | 06/27/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here