On The Insider: Gerard Butler Joins Aniston in Mexico
BNET Business Network:
BNET
TechRepublic
ZDNet

July 20th, 2008

Do open source applications take security seriously?

Posted by Dana Blankenhorn @ 1:42 am

Categories: Applications, Development, General, Implementations, Security, marketing, support

Tags: Security Best Practice, Open Source, Security, Dana Blankenhorn

Fortify technical advisory board, 01-2007, by Gary McGraw of Cigital.comNot according to the folks at Fortify, who today are issuing a blistering report claiming open source projects and companies don’t take security seriously at all.

Security best practices are missing in the open source space, Fortify says. (Gary McGraw interviewed Fortify’s technical advisory board in January, 2007. Here are some of those heroes.)

“If there’s an application hack at Microsoft you would know who to go to. But what about open source? The answer isn’t always clear,” director of product marketing Rob Rachwald told ZDNet.

It should be noted before going forward that Fortify specializes in this sort of security life cycle work. One can argue they are arguing from the position of a vendor who stands to benefit if its demands for the industry are met.

But this should not invalidate the point, which is that security is a process that must be followed consistently, and many open source projects do this only haphazardly.

Here is the way way CEO John Jack CTO Roger Thornton put it when he got on the call:

There were 215 million data breaches from 2004-2006. Something is going on.

The bad guys have figured out how to exploit software, and one of the key elements is something firewalls can’t deal with and anti-virals don’t deal with – the applications layer.

Most hacks today are at the application layer, anywhere from 75-92%.

Open source projects that leave vulnerabilities open threaten the integrity of entire installations.

computer securityI thought at first this might be a crack at non-professional open source projects, as opposed to the work of professional open source companies.

Fortify’s research indicates both sides are equally at fault here.

“Some commercial companies maintain open source packages and I wish they were doing a better job on this than non-commercial projects,” admitted Jack. “There’s no swing one way or another in terms of security practices.”

Secure development, real-time monitoring, and the hiring of full-time security directors are all steps which need to be taken, Rachwald concluded. Open source needs to take security as seriously as Microsoft does.

“One thing I don’t think developers understand is the difference between security and quality. Security is gray. Quality is black and white. That’s why a security process is essential, because it’s not black and white.”

This should be the chief open source challenge for the next year, because if application security is not addressed, it’s hard to see much more progress coming in the enterprise market.

Dana BlankenhornDana Blankenhorn has been a business journalist for 30 years, a tech freelancer since 1983. You can follow Dana on Twitter. See his full profile and disclosure of his industry affiliations.

Email Dana Blankenhorn

Subscribe to Linux and Open Source via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 43 Talkback(s)
Unfairly focuses on open source
I've worked on many projects for many commercial software companies and the problem with secure software isn't limited to just the open source products. There are very few software engineers who are ... (Read the rest)
Posted by: kkernes Posted on: 08/25/08 You are currently: a Guest | | Terms of Use
Good Point, Good Post  bcarpent1228@... | 07/20/08
RE: Do open source applications take security seriously?  ShaunConnolly | 07/20/08
Don't forget the corollary  rpmyers1 | 07/20/08
I think you are on to something ...  n0neXn0ne | 07/20/08
Inflating title with little sustance  wackoae | 07/20/08
instead of ...  n0neXn0ne | 07/20/08
That was one example  DanaBlankenhornZDNet Moderator | 07/21/08
Ok, give us another one  Hemlock Stones | 07/21/08
Here's a list  FatherJ | 07/21/08
OUCH!...  ItsTheBottomLine | 07/21/08
You just hit the nail on the head....  dunn@... | 07/22/08
What a crock: "So much for "open source patching quicker".  bmerc | 07/22/08
PHP?  grail@... | 07/22/08
Actually, No.  FatherJ | 07/21/08
Actually, Yes.  Hemlock Stones | 07/21/08
Do some homework.  FatherJ | 07/21/08
The links you provided do not support your claim  bmerc | 07/22/08
I think YOU need to do a bit more homework...  bmerc | 07/22/08
Get over yourself  FatherJ | 07/22/08
YAWN...not another one...nt  ItsTheBottomLine | 07/21/08
How do you patch what you don't know about?  ItsTheBottomLine | 07/21/08
That's exactly his point, genius.  bmerc | 07/22/08
most Unix/Linux administrators would  deowll | 07/21/08
"...fix it themselves of (or I think) purchase a solution..."  ItsTheBottomLine | 07/21/08
"I'm not buying the source so I have the ability to fix it..."  bmerc | 07/22/08
Taking security seriously.  sysop-dr | 07/21/08
RE: Do open source applications take security seriously?  adminlong6458@... | 07/21/08
It's not a run for closed source  DanaBlankenhornZDNet Moderator | 07/21/08
RE: Do open source applications take security seriously?  gsuser | 07/21/08
Anyone who says what you're saying they do is a few bricks short of a load  TtfnJohn | 07/21/08
Stop lying  bmerc | 07/22/08
Fortify looking for consulting work, really  TtfnJohn | 07/21/08
2 words for you as an example...  MrGrave | 07/21/08
MrGrave offers wisdom  DanaBlankenhornZDNet Moderator | 07/21/08
Open source needs to take security as seriously as Microsoft does.  The Mad Hatter | 07/21/08
RE: Have to use a convention to report security issues  uthaiyashankar@... | 07/21/08
RE: Do open source applications take security seriously?  Mitch 74 | 07/22/08
You assume the vulnerability is public....  dunn@... | 07/22/08
Do I know how many...  Mitch 74 | 07/22/08
youre nuts!  billw1234 | 07/23/08
And MicroShaft Windoze is EVER So Secure, Right?  drprodny | 07/23/08
RE: Do open source applications take security seriously?  Greenknight_z | 07/23/08
Unfairly focuses on open source  kkernes | 08/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here