Nessus security tool closes its source

By Renai LeMay, ZDNet Australia
Friday, October 07, 2005 11:26 AM

The source code of one of the world's most popular free security tools will no longer be available to all, its creator has announced, saying the software's open-source license was fueling competition.

Renaud Deraison, the primary author of the Nessus vulnerability scanner, broke the news in a message to the software's e-mail list Wednesday. "Nessus 3 will be available free of charge...but will not be released under the GPL," or General Public License, Deraison wrote. Nessus, which Deraison says is used by 75,000 organizations worldwide, scans networks for vulnerabilities.

The developer, who has been working on the product since at least 1998, said commercial pressures facing Tenable Network Security, the company he started in 2002 around Nessus, was forcing him to stop making the software's source code available.

"A number of companies are using the source code against us, by selling or renting appliances, thus exploiting a loophole in the GPL," he wrote in a later e-mail, justifying his decision. "So in that regard, we have been fueling our competition, and we want to put an end to that. Nessus 3 contains an improved engine, and we don't want our competition to claim to have improved 'their' scanner."

The developer also expressed disappointment over the lack of community participation in developing the software, despite its open-source license.

"Virtually nobody has ever contributed anything to improve the scanning engine over the last six years," he wrote, noting that there had been minor exceptions.

Deraison said the existing version 2 of Nessus would continue to be available under the GPL license and receive bug fixes and regular updates. The large library of plug-ins to the software would also continue to distributed in a way that would allow parties to examine their source code.

Tenable will also cut down the number of system architectures that version 3 of Nessus will support, and one core part of Nessus--its graphical user interface will be split off into a separate, open-source project, Deraison added.

The developer's decision attracted immediate criticism, notably from the security expert known only as Fyodor. The programmer is the author of Nmap, a complementary network-scanning tool to Nessus, which is widely used among security professionals.

"Tenable argues that this move is necessary to further improve Nessus and/or make more money. Perhaps so, but the Nmap project has no plans to follow suit," Fyodor wrote in an e-mail, alerting his software's user base of the license change. "Nmap has been GPL since its creation more than eight years ago, and I am happy with that license," he continued.

Another critic posted concerns to the Nessus mailing list that Tenable would eventually get tired of supporting the open-source version 2 of the software and simply forget about it.

He raised the possibility that the community could "fork" version 2 of the software--that is, start developing a divergent version of Nessus from the one officially supported by Tenable.

New kid on the block
Deraison said version 3 of Nessus would contain several noteworthy improvements but be broadly backwards-compatible with version 2. The two will be able to share most of the plug-ins that are crucial to the software's operation.

"Nessus 3 is much faster than Nessus 2 and less resource-intensive," the developer wrote. "Your mileage may vary, but when scanning a local network, Nessus 3 is, on average, twice as fast as Nessus 2, with spikes going as high as five times faster when scanning desktop Windows systems."

"Nessus 3 also contains a lot of built-in features and checks to debug crashes and misbehaving plug-ins more easily, and to catch inconsistencies earlier," he wrote.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Migrating DHCP from Windows 2000 Server/Windows Server 2003 to Windows Server 2008

Windows Server

With a little bit of work, it's not hard to migrate DHCP services from Windows 2000 Server or Windows Server 2003 to Windows Server 2008. Here's how.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. antivirus
  2. apple ipod
  3. cnet networks inc.
  4. desktop
  5. e - mail
  6. hard drive
  7. intuit inc.
  8. mcafee inc.
  9. microsoft corp.
  10. microsoft windows
  11. microsoft windows vista
  12. microsoft windows xp
  13. norton co.
  14. pc
  15. performance
  16. security
  17. software
  18. tool
  19. web
  20. web site