Open source 'lacks enterprise-grade security'

 

Summary

A new study finds lax or non-existent security processes in open source development, serving as a warning to businesses.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

The security practices of open source IT developers should lead enterprises to think twice before using open source software, according to a new study sponsored by security tools vendor Fortify.

The study, carried out by application security consultant Larry Suto, found that a lack of security processes led to a constant or increasing number of security issues in successive open source releases.

As a result, government and commercial organizations should approach open source applications with "great caution", carrying out risk analysis and code review before it is used, Fortify said.

The company argued that open source development simply does not live up to enterprise security standards. Fortify quoted Jennifer Bayuk, an independent security consultant, as saying that open source implies a "hidden cost" due to the necessity of testing for security bugs.

The study is likely to reopen the debate around the relative security of proprietary and open source software.

Independent software vendors (ISVs) selling proprietary software have claimed that the open source development process exposes open source software to greater security risks, while open source developers argue that the openness of the process allows for more security flaws to be caught.

The study examined software for developing and serving Java applications, including Geronimo, JBoss, Struts and Tomcat. It found that all or nearly all of the projects examined failed to provide access to an internal security expert, reduce the number of security flaws in successive releases or make use of bug-catching tools such as FindBugs or Fortify's own Java Open Review (JOR).

As a result, bugs such as SQL injection and cross-site scripting (XSS) continue to proliferate, Fortify said.

"Open source packages often claim enterprise-class capabilities but are not adopting--or even considering--industry best-security practices," the study said. "Serious security threats stemming from numerous application vulnerabilities are a direct result of poor or non-existent security processes."

One exception is Mozilla, which in July announced a security initiative and hired security consultant Rich Mogul as an adviser. But more projects need to follow Mozilla's lead or, better yet, follow the lead of proprietary ISVs in improving security practices, Fortify said.

"Open source development can benefit from private industry practices--notably those created by financial services organizations and larger independent software vendors," the report said.

Not everyone agrees that security should be the priority Fortify takes it to be. Last week Linux creator Linus Torvalds criticized the makers of the OpenBSD operating system as part of a critique of what he said was self-centered behavior in the IT security industry.

The row erupted in the Gmane mailing list after a developer for the PaX Team, which patches the Linux kernel, accused Torvalds and other top Linux kernel developers of "covering up [the] security impact of bugs" by not clearly labeling them as security flaws. Torvalds wrote that disclosing the bug itself was enough, without having to label each individual security flaw. He added that taking the bugs to the "security circus" level only glorified the wrong kind of behavior.

A May study funded by the U.S. Department of Homeland Security praised improvements in open source security. A recent survey found that unsupported open source software was one of the top causes of security breaches.

Talkback

Well, It is getting better all the time

The tides are changing in this aspect. Enterprise security and open source have not been good bedfellows in the past but developers are starting to make it a priority. I came across this site a while back http://www.accesstream.com/ and they are working on a cross platform application for specifically for enterprise security. Did I mention that it is open source :) I can't wait to see open source go toe to toe with the big boys in this market. Remeber Jboss? Is there any doubt it is enterprise now?

Sam Adams August 12, 2008
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Pacnet CEO departs; acquisition rumors gain #steam http://t.co/QSCFfCcy

5 SaaS adoption speed bumps to avoid http://t.co/AJQYAkOh via @zdnetasia

RT @SecMash: #InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity

Experience trumps content in apps monetization http://t.co/MVPlf9gR

Better biz models needed for sustainability. http://t.co/tXuq7174

Sudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG

@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech

Malaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP

RT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news

#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity

http://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN

Pacnet CEO departs; acquisition rumors gain steam. http://t.co/Nu2Mdcj0

Malaysia organizations don't realize severity of cyberattacks http://t.co/zeaxHbYa http://t.co/erFSwAUB #arcavir

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

4 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

4 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate