Trend Micro Has A Bad Case Of Open Source Foot In The Mouth

Analysis
Jan 13, 20114 mins

Saying open source is less secure results in deserved backlash against security vendor

The chairman of security vendor Trend Micro is having a tough time extracting his foot from his mouth after saying that open source software is not as secure as other software. He claims because “the hacker can also understand the underlying architecture and source code”, open source is therefore less secure. Steve Chang was talking about the Android OS versus Apple’s iOS. Putting aside for a second the issue of whether Android is indeed truly open, Chang’s remarks ignited a firestorm of rebuttals and vitriol from the open source community.  

Of course the fact that Chang was making these remarks while marking the release of Trend’s new Android anti-malware products gave the whole thing the smell of a cheap suit and a bottle of snake oil. But FUD (fear, uncertainty and doubt) and snake oil are not strangers to the security market. Take it from me, I have been there for 10 years now.  FUD is the security salesperson’s best friend.  But there is FUD and there is FUD. Spreading FUD that open source is not as secure as closed source will always get a knee jerk reaction out of the FOSS community.

In this case the outrage was so great that Trend tried to issue some press releases and follow ups trying to explain away what Chang meant. But it was too little too late and the damage was already done. Adding salt to the wound was that Chang was trying to say that Android had security issues compared to Apple’s iOS.  Fact is there are many in the security field and smartphone market who think that that Apple OS has many if not more issues than Android. 

In any event, Trend which over the last few years has seemed to lost its spot as the clear cut #3 AV product has stuck a stick in a bee’s nest and is now getting stung.  The whole issue of which is more secure, open source or closed source though is a waste of time. The fact is that all software can have vulnerabilities. It doesn’t seem to make a difference. One may have more than another, but there are holes it seems in all software. On top of that is that the biggest hole is the human using the software. Social engineering will trump secure software design every time, regardless of whether it is open source or not.

But I guess this also explains their neglect of OSSEC. OSSEC is an open source host based intrusion detection project that Trend acquired when they bought Third Brigade, a HIDS (host based IDS) vendor. The front page for the project says the most recent entry was back in October!  It seems that Trend just has no respect for open source. What a shame.

In fact some are saying that the whole idea of using paid for desktop AV might not be worthwhile. I wrote a blog on that on my own personal ashimmy.com blog today. While the mobile market may represent a new attack vector for the malware makers, there are bound to be other solutions both free and not that you may want to look at. Also the OS makers themselves will probably have something to add to this as well. But the fact there are some who say that most of the AV and anti-malware out there today does not really work in stopping the kind of attacks we are seeing.

But the threat landscape is too great and the level of security awareness too low for most of you reading this to go naked. If you are an open source fan you may even not want to use a product from a company that thinks open source is less secure.