On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

October 2nd, 2007

Is open source more secure?

Posted by Dana Blankenhorn @ 8:27 am

Categories: General, Hardware, Infrastructure, Security, marketing

Tags: Secure, Perception, Open Source, Security, Dana Blankenhorn

computer securityToday we have another study claiming that open source is more secure. (Picture from the state of Kentucky.)

This time it’s an IDC survey taken in Asia, whose “results indicate that organizations perceived open source technology as providing better security compared to proprietary products,” according to analyst Prianka Srinivasan.

It’s important to note some caveats. People believe open source is more secure. Perception is not always reality.

Recently I interviwed a security expert while he was working on a Linux disassembler. He said that 95% of his work is in Windows, but that’s just because everyone uses Windows. If everyone used Linux, he believed, it might be the other way.

Matt Asay has another survey today, thisĀ one taken by Barracuda Networks, an open source vendor in e-mail and security, indicating security is not what is driving open source adoption by its customers.

Instead, this survey says, it’s price. And when Barracuda reversed the question, asking for advantages in proprietary software, 23% answered security. When open source customers were asked the advantages in their choice, only 16% answered security.

What this tells me is that proprietary vendors are doing a better job pushing the buttons of buyers than open source vendors. Which is no surprise. Proprietary vendors have bigger marketing budgets.

But there’s a lot that open source vendors can learn from this. They can push the security message. It’s one buyers want to hear, and one many are responding to.

Question remains, of course, is it true? Is open source more secure, because bugs can be seen by everyone, and fixed by anyone? Or is security through obscurity still our best defense?

I know what I think.

Which type of software do you find, in practice, to be more secure?

View Results

Loading ... Loading ...

Dana BlankenhornDana Blankenhorn has been a business journalist for 30 years, a tech freelancer since 1983. You can follow Dana on Twitter. See his full profile and disclosure of his industry affiliations.

Email Dana Blankenhorn

Subscribe to Linux and Open Source via Email alerts or RSS.

  • Talkback
  • Most Recent of 51 Talkback(s)
Where do you think the apps come from?
Just FYI, the fact that more people have access to open source code does NOT mean more people are looking at it. If that were the case, there would be more drivers and applications for Linux.

... (Read the rest)
Posted by: santuccie Posted on: 10/08/07 You are currently: a Guest | | Terms of Use
Vote early, vote often  Yagotta B. Kidding | 10/02/07
Even neater trick  Tony Agudo | 10/02/07
While I have my opinion...  bjbrock | 10/02/07
Legal Issues for the Use of Free and Open Source Software in Government  D. T. Schmitz | 10/02/07
Most patches are for...  bjbrock | 10/02/07
Security Through Obscurity ...  MisterMiester | 10/02/07
Security through obscurity coding?  santuccie | 10/08/07
Neither is better than the other.  ye | 10/02/07
Chicken or egg?  MisterMiester | 10/02/07
Being able to inspect the code for securness...  ye | 10/02/07
Well ...  MisterMiester | 10/02/07
Inspecting the code has no bearing on how secure it is.  ye | 10/02/07
Au Contraire...  D. T. Schmitz | 10/02/07
They may been keeo on Open Source  ye | 10/02/07
You have a circular argument ...  MisterMiester | 10/02/07
There's nothing circular about my argument.  ye | 10/02/07
Is this George Ou?  D. T. Schmitz | 10/02/07
No. I think that would have been self evident since the post...  ye | 10/02/07
OK, are you related to George Ou?  D. T. Schmitz | 10/02/07
No. Are you obsessed with George Oui?  ye | 10/03/07
Actually  Hrothgar - PCLinuxOS User | 10/03/07
What ye is doing is correcting those who are in error.  ye | 10/03/07
ye, ye have a very narrow view  shis-ka-bob | 10/03/07
Ye is just repeating his fallacious argument over and over  bmerc | 10/03/07
You'll leave because you'll realize your FUD isn't...  ye | 10/03/07
The bean counters  Hrothgar - PCLinuxOS User | 10/03/07
Then how do you explain code audits of closed source...  ye | 10/04/07
I didn't say it doesn't get done.  Hrothgar - PCLinuxOS User | 10/04/07
That's exactly the implication. Otherwise you wouldn't...  ye | 10/04/07
If a bug is found that affects  Hrothgar - PCLinuxOS User | 10/04/07
Where do you think the apps come from?  santuccie | 10/08/07
Source code security  Larry the Security Guy | 10/03/07
Open source clearly is not...  BFD | 10/02/07
Lower TOC as well I suppose  odubtaig | 10/02/07
You mean spreading the FUD dont you...  mrOSX | 10/02/07
Jeff Jones from Microsoft  Ole Man | 10/02/07
Me, I'm a fan of George Ou  DanaBlankenhornZDNet Moderator | 10/03/07
George and I go way back.  D. T. Schmitz | 10/03/07
Security opinions  Update victim | 10/03/07
What ye is doing is correcting those who are in error.  Update victim | 10/03/07
Where do you think ye is in error?  ye | 10/03/07
ye have a narrow view  shis-ka-bob | 10/03/07
Nothing narrow about it. Code audits can be performed on...  ye | 10/03/07
Yes, let's put that fox in charge of protecting the chickens  bmerc | 10/03/07
I don't care what you've been saying because...  ye | 10/03/07
Doesn't sound right  notsofast | 10/03/07
You are overlooking a point.  normhaga@... | 10/04/07
I've explained your error in detail in a previous post  bmerc | 10/03/07
Too bad you were wrong.  ye | 10/03/07
All the world is a stage  Ole Man | 10/03/07
Where do the apps come from?  santuccie | 10/08/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline