by Readers

Letters to the editor: “Open source companies to watch”

Opinion
Oct 2, 20064 mins

Open source companies to watch; Neglecting identity management; Embracing the free culture movement; A stroll across campus without leaving home; Vista, not improving security?

Another company to watch

Regarding “Open source companies to watch”: You missed the No. 1 open source company to watch: N3P. N3P offers a brand new, contrasting and intrepid two-year college level training in how to become a successful project entrepreneur in open source. The students will learn not only the technical possibilities, but also how to exploit new business opportunities, manage profitable ideas and create flourishing businesses. The training will focus on how to generate business using open source.

Claes Magnusson

Co-founder and C.K.O.

N3P

Malmo, Sweden

Begin at the beginning

Regarding “Neglecting identity management”: I believe smaller companies should not start with a full-blown identity management solution, but rather start to get their privileges model intact so their growth is more organized, even if provisioning is still done with pen and paper.

The best-known approach is to correlate the way in which privileges are granted to business roles. Companies with less than 5,000 employees can usually do this in a three-month project with the aid of analytical tools. The same project can also serve to demonstrate compliance with the basic segregation of duties and other policies required by their auditors.

Ron Rymon

Founder

Eurekify

Raanana, Israel

More than ‘Net neutrality

Your editorial, “Embracing the free culture movement” highlights an important piece of the proposed legislation in the debate over Net neutrality but fails to mention that the legislation is really about increasing video service options and saving consumers money.

The Advanced Telecommunications and Opportunity Reform Act of 2006 (S. 2686) is about more than Net neutrality. This bill would fix today’s outdated laws that go all the way back to the 1960s by breaking up one of the last monopolies left in this country – cable television – and bring benefits to consumers, businesses and local communities.

How it would work is really very simple. Consumers win when businesses compete. Increased competition means consumers will see almost immediate cost savings and improved customer service. And with the introduction of new competitors comes increased options and control over cable programming, high-speed Internet and costs.

The video choice bill comes down to increased cost savings, competition, choice and control. This legislation is a clear win for consumers; on that point I refuse to be neutral.

Kelley Gannon

Spokesperson

TV4US

Arlington, Va.

Welcome recognition

Regarding, “A stroll across campus without leaving home”: I am pleased to see the name and work of my teacher, Margarita Ruiz, being recognized in such an interesting article. Instituto D’Amicis is very proud of Appalachian State University’s efforts to innovate with such a caring environment.

Technology-empowered, humane professionals are what the world needs, especially in the field of education.

Lucila Sotomayor de Gil

Academic principal

Instituto D’Amicis, A.C.

Puebla, Mexico

Vista and security

Regarding Mark Gibbs’ BackSpin column, “Vista, not improving security?”: I agree with Gibbs’ thesis (Vista is not improving security), but the trouble is not that Vista is over-engineered. The lack of security compliance in sensitive applications (the banking industry is rife with them) is not and should not be a reason to continue with disabled security, else we find ourselves in a situation where we collectively are held hostage to poorly written applications.

The real security issues with Vista continue to be cosmetic security. I was at the recent Vista/Exchange 2007 preview in Redmond; the show was long on polish and short on substance. The presenter was quite annoyed when I pointed out that the “Are you sure you want to do this?” message that pops up whenever performing a security-sensitive function is insufficient to ensure security. Such boxes use the standard interface API set and it’s trivial to code automatic acceptance into a potential bit of malware.

The worst part is that the fix is likewise trivial – instead of a simple checkbox dismissed with a real or programmed mouse click, re-authentication could be used like virtually every other operating system. Such a change might take a half hour at most and resolve a major security flaw. Although closer, Microsoft still doesn’t get security. I look forward to the day they do.

Randy Grein

Bellevue, Wash.

Regarding Mark Gibbs’ column about Microsoft security, I can see the corner they’ve backed themselves into. Why support legacy applications forever? I would recommend a clean break from the past. I would say after, for example, 2010, we are moving to a hybrid open-source/closed-source model and hybrid local/Web-based software — based on the cutting edge in computer science, the code is fast, small, secure and if your application does not work, it’s your problem and not the operating system’s fault. Speed and security should be first and foremost in every OS design principle, period.

Tom Maioli

Rochester, N.Y.