Access and Feeds

Open Source: A Ticket to Security Problems?

By Dick Weisinger

Most Open Source software lacks basic security protections. That’s the conclusion of a report issued by security company Fortify Software. While the report is no doubt somewhat self-serving since Fortify is in the business of selling security add-ons, there is likely at least a kernel of truth in their results.

The report studied 11 different software applications. Interestingly the report focused on the community response when security vulnerabilities or other security issues related to the software were uncovered. The report selected the follwing Open Source applications and tools: Tomcat, Derby Geronimo, Hibernate, Hipergate, JBoss, Jonas, OFBiz, OpenCMS, Resin and Struts.

Tomcat was considered the best of the lot. But others, like JBoss, had a closed policy related to security issues: reported security issues were not reported publicly to the rest of the community. The reason is that the companies don’t want security flaw information public until a fix is created so that attackers can’t take advantage of the exploit.

Fortify’s conclusion was that commercial apps in general had better security practices. Using Fortify software, the report identified
22,826 cross-site scripting and 15,612 SQL injection problems across all 11 Open Source applications. There was concern that once security problems are found that there was no good way to contact the software developers. No phone numbers. Only email addresses, and most of the time the email questions were not answered. The report questions the life-time support of Open Source software.

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*