The most popular and comprehensive Open Source ECM platform
Open Source Security: Does Open Source Really Have the Edge?
In the wake of the exposure of the HeartBleed OpenSSL security flaw, the security and safety of Open Source software has been under fire. The theory has been that because open source software is freely downloadable, it is exposed to many more ‘eyes’ than proprietary software, and that sheer exposure provides a more thorough vetting of its contents. Bruce Schneier, security technologist, explained it saying that “public security is always more secure than proprietary security…For us, open source isn’t just a business model; it’s smart engineering practice.”
But how many eyes are many and how focused are those eyes? The ‘many eyes’ open source security theory makes sense if everyone (or many) who download open source also scan and analyze the software internals of the software which they use. But it’s likely that only a small number of open source downloads actually result in detailed inspection of any part of the code. Although a small fraction of hundreds of thousands of downloads may still be a large number.
Dr Ian Levy, technical director with the CESG, a department of the UK’s GCHQ intelligence agency, told Nick Heath of ZDNet said that “many eyes give you many eyelashes, and not a lot else.”
Levy doesn’t think that Open Source has an edge over proprietary software, but then proprietary doesn’t hold the edge either. “”I’ve done a lot of work on this, there’s no objective evidence either way. On average, good open source is about as good as good proprietary, and [bad] about as bad as bad proprietary.”
A report by Coverity compared the results of security scans of open source software with that of proprietary software. The results are close but show a slight edge for open source over proprietary. The report used the source code from 750 million lines from 700 open source projects and found that open source code had a slightly lower incidence of bugs compared to proprietary software: .59 bugs per 1000 lines of open source code versus .72 for proprietary.
In a Wall Street Journal blog posting, Gary McGraw, CTO of security firm Cigital Inc. and a former member of the IEEE Computer Society board of governors, was critical of Open Source software, saying that “nobody is in charge when it comes to open source, and the same applies with patching.” Open source projects with few core contributors often can’t consistently keep the project current by creating new updates and security patches. Especially, in the case of small and less well organized projects, McGraw says that “the only way to describe it is chaos… The fact of the matter is that open source is very pervasive, but it’s not equally secure or reliable everywhere.”













