Pacnet CEO departs; acquisition rumors gain #steam http://t.co/QSCFfCcy
15 minutes ago by SuperGamePower on twitterZDNet is available in the following editions:
A new study finds lax or non-existent security processes in open source development, serving as a warning to businesses.
The security practices of open source IT developers should lead enterprises to think twice before using open source software, according to a new study sponsored by security tools vendor Fortify.
The study, carried out by application security consultant Larry Suto, found that a lack of security processes led to a constant or increasing number of security issues in successive open source releases.
As a result, government and commercial organizations should approach open source applications with "great caution", carrying out risk analysis and code review before it is used, Fortify said.
The company argued that open source development simply does not live up to enterprise security standards. Fortify quoted Jennifer Bayuk, an independent security consultant, as saying that open source implies a "hidden cost" due to the necessity of testing for security bugs.
The study is likely to reopen the debate around the relative security of proprietary and open source software.
Independent software vendors (ISVs) selling proprietary software have claimed that the open source development process exposes open source software to greater security risks, while open source developers argue that the openness of the process allows for more security flaws to be caught.
The study examined software for developing and serving Java applications, including Geronimo, JBoss, Struts and Tomcat. It found that all or nearly all of the projects examined failed to provide access to an internal security expert, reduce the number of security flaws in successive releases or make use of bug-catching tools such as FindBugs or Fortify's own Java Open Review (JOR).
As a result, bugs such as SQL injection and cross-site scripting (XSS) continue to proliferate, Fortify said.
"Open source packages often claim enterprise-class capabilities but are not adopting--or even considering--industry best-security practices," the study said. "Serious security threats stemming from numerous application vulnerabilities are a direct result of poor or non-existent security processes."
One exception is Mozilla, which in July announced a security initiative and hired security consultant Rich Mogul as an adviser. But more projects need to follow Mozilla's lead or, better yet, follow the lead of proprietary ISVs in improving security practices, Fortify said.
"Open source development can benefit from private industry practices--notably those created by financial services organizations and larger independent software vendors," the report said.
Not everyone agrees that security should be the priority Fortify takes it to be. Last week Linux creator Linus Torvalds criticized the makers of the OpenBSD operating system as part of a critique of what he said was self-centered behavior in the IT security industry.
The row erupted in the Gmane mailing list after a developer for the PaX Team, which patches the Linux kernel, accused Torvalds and other top Linux kernel developers of "covering up [the] security impact of bugs" by not clearly labeling them as security flaws. Torvalds wrote that disclosing the bug itself was enough, without having to label each individual security flaw. He added that taking the bugs to the "security circus" level only glorified the wrong kind of behavior.
A May study funded by the U.S. Department of Homeland Security praised improvements in open source security. A recent survey found that unsupported open source software was one of the top causes of security breaches.
Pacnet CEO departs; acquisition rumors gain #steam http://t.co/QSCFfCcy
15 minutes ago by SuperGamePower on twitter5 SaaS adoption speed bumps to avoid http://t.co/AJQYAkOh via @zdnetasia
15 minutes ago by pmarini on twitterRT @SecMash: #InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity
15 minutes ago by suhnylla on twitterExperience trumps content in apps monetization http://t.co/MVPlf9gR
15 minutes ago by saffronistah on twitterBetter biz models needed for sustainability. http://t.co/tXuq7174
15 minutes ago by zdnetasia on twitterSudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG
30 minutes ago by NGTsummit_ASIA on twitter@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech
30 minutes ago by mcjimmm on twitterMalaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP
45 minutes ago by zdnetasia on twitterRT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr
45 minutes ago by nickstersss on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news
45 minutes ago by Nathiet on twitter#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity
1 hour ago by SecMash on twitterhttp://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security
1 hour ago by CYSEC_COM on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN
1 hour ago by Cloud_Fail on twitterPacnet CEO departs; acquisition rumors gain steam. http://t.co/Nu2Mdcj0
1 hour ago by zdnetasia on twitterMalaysia organizations don't realize severity of cyberattacks http://t.co/zeaxHbYa http://t.co/erFSwAUB #arcavir
1 hour ago by V_RaV on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoidI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
4 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
5 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.
Well, It is getting better all the time
The tides are changing in this aspect. Enterprise security and open source have not been good bedfellows in the past but developers are starting to make it a priority. I came across this site a while back http://www.accesstream.com/ and they are working on a cross platform application for specifically for enterprise security. Did I mention that it is open source :) I can't wait to see open source go toe to toe with the big boys in this market. Remeber Jboss? Is there any doubt it is enterprise now?