Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Falling Apart at the Seams
Kathleen Ellis and Jon Lasser, SecurityFocus 2000-09-04

Last month's Brown Orifice program opened a backdoor to an insecure future. Can open source save the day?

Comments Mode:
User: friend or enemy? 2000-09-05
Pavel Roskin (1 replies)
User: friend or enemy? 2000-09-08
foo
Open Source Solution 2000-09-05
Pete Kofod (2 replies)
Re: Open Source Solution 2000-09-08
angel'o'sphere (1 replies)
I comletely agree with the previous poster.

Further more it is a myst that OS software is more secure.

In fact if I I as a hypotetical cracker want to break into a system

I would of course try to use an unknown exploit.

So if I can get hands on the sources for a system I would

analyse them in the first line to to break into it and not to

post the exploit.

Also is Raymond simply wrong if he claims Brooks Law would

not hold for OS development.

In OS development the situation is even worse! Make the test:

watch how many check out from an CVS archive, and how many

check in.

Watch the changes and contributions they make.

You see that most OS development projects have a ridiculess

low performance in terms of LOC per programmer or LOC per

month.

If you go to sourceforge.net and pick randomly OS developed

projects you find rediculous high bug rates.

Please do not conclude that I'm against OS :-) But most

which is written about it, even from coryphaes like ESR, is

simply wrong or at least unprooved and there are no investigations

or numbers which proove any claim made.

Regards,

angel'o'sphere

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/80/3318#3318
Re: Open Source Solution 2000-09-08
Richard
Open Source Solution 2000-09-08
Mike Crist
Open source is not a silver bullet 2000-09-06
Your friendly neighborhood software developer
"All bugs are shallow" is a delusion of Open Source Arguments 2000-09-08
peter (at) smalltalk (dot) org [email concealed]
Open source WORKS! 2000-09-08
Another friendly software developer
Mozilla and JavaScript 2000-09-08
Markus Fleck
How many ways can one article be wrong? 2000-09-08
Charles Miller







 

Privacy Statement
Copyright 2009, SecurityFocus