- Microsoft Windows chief decries standards grandstanding
- The 5 best, and 5 worst, features of Google Chrome OS
- Federal government using PS3 to crack pedophile passwords
- 10G Ethernet cheat sheet
- Top 10 free Windows tools for IT pros, at a glance
Open source software is a significant security risk for corporations that use it because in many cases, the open source community fails to adhere to minimal security best practices, according a study released Monday.
The study, carried out by Fortify Software with help from consultant Larry Suto, evaluated 11 open source software packages and each community's response to security issues over the course of about three months. The goal was to find out if the community for each open source software package was responsive to security questions or vulnerability findings, published security guidelines and maintained a secure development process, for example.
Open source application server Tomcat scored the best in the study, titled "Open Source Study -- How Are Open Source Development Communities Embracing Security Best Practices?"
The remaining 10 open source application, tool and database packages -- Derby, Geronimo, Hibernate, Hipergate, JBoss, Jonas, OFBiz, OpenCMS, Resin and Struts -- had a dismal showing. Among these 10 packages, application server JBoss scored higher by providing a prominent link to security information on its Web site and easy access to security experts, but came up short for not having a specific e-mail alias for submission of security vulnerabilities.
"You don't want to report bugs to a general mailing list because it would go to the general public," says Jacob West, manager of Fortify's security research group. There needs to be a measure of confidentiality in reporting bugs so that the fix for them can be provided when the public is notified, so attackers don't get early information they can exploit.
But too often the open source communities that offer their software for free don't appear to be as mindful about security practices as their commercial counterparts, which charge for software and support, West says.
Fortify identified a total of 22,826 cross-site scripting and 15,612 SQL injection issues associated with multiple versions of the 11 open source software packages examined.
But when Fortify tried to reach out to the open-source software communities, with the primary point of contact a Web site and a general e-mail address, the security firm found that "in two-thirds of these cases, you didn't get a response at all," West says. "There are no phone numbers. Who do you go to ask for information? It's kind of hard to tell who these people are."
The report itself notes, "Open source packages often claim enterprise-class capabilities but are not adopting -- or even considering -- industry best practices. Only a few open source development teams are moving in the right direction."
West says Fortify did not conduct this study in order to condemn open source software, but rather to point out that the security practices need to improve because open source adoption by enterprises and governments is growing.
Howard Schmidt, former White House cybersecurity czar who's now a consultant, and also a board member at Fortify, says the study shows that when it comes to business adoption of open source software, "You've got to go into this with your eyes wide open."
Comments (48)
pay themBy Anonymous on July 21, 2008, 4:37 pmThere are no phone numbers. Who do you go to ask for information? It's kind of hard to tell who these people are." > Pay them for support and get...
Reply | Read entire comment
Open source softwareBy Anonymous on July 21, 2008, 12:42 pmWell, I have fix about 15 Window machines this weekend and 0 machines with open source. That is why I love windows, it gives me work to do.
Reply | Read entire comment
best security practices...By Anonymous on July 21, 2008, 12:44 pmNow it all depends how Fortify defines "best security practices" Each and every open source software carries a file often the name of the file is "LEAGAL" states...
Reply | Read entire comment
FUD, StupidityBy Anonymous on July 21, 2008, 12:58 pmWell, certainly Fortify (whatever) has all interest in disseminating FUD, so they can make some money. Now, there is also the possibility that the "study" has been...
Reply | Read entire comment
Open source, open soreBy Anonymous on July 21, 2008, 1:00 pmNothing is free. The idea of free software being worth something was cultivated by geeks. Geek knowledge is like currency. They trade on it to garner more power...
Reply | Read entire comment
Bad ConclusionsBy Anonymous on July 21, 2008, 1:06 pmI sense a hidden agenda here. First of all, you can't evaluate such a narrow range of software (clearly the study focused on a small number of prominent open-source...
Reply | Read entire comment
View all comments