Commentary

Mitch Wagner
Executive Editor, Community  

Don't Put That In Your Mouth, You Don't Know Where It's Been

One of the major objections to open source is that nobody's responsible for the code. Enterprise users need to be sure that the software they're deploying is secure. The way they do that for proprietary code is to bind the authors with contracts, requiring the authors to guarantee that the code has been reviewed for security. But you can't do that with open source because anyone can contribute to open source, and, ultimately, there's no single party that can be held responsible for the software's security. You don't know where it's been.

One of the major objections to open source is that nobody's responsible for the code. Enterprise users need to be sure that the software they're deploying is secure. The way they do that for proprietary code is to bind the authors with contracts, requiring the authors to guarantee that the code has been reviewed for security. But you can't do that with open source because anyone can contribute to open source, and, ultimately, there's no single party that can be held responsible for the software's security. You don't know where it's been.That issue came up at a Birds of a Feather Session (BOFS) at the InformationWeek Spring Conference. The BOFS was one of several informal discussion groups of IT managers with like-minded concerns, facilitated by InformationWeek editors. At the Open Source BOFS, Stephen B. Rycroft, a director at a multibillion-dollar financial services company, raised concerns about accountability and security.

"What I'm concerned about is, if I bring the code in, will it start writing out my database to a server somewhere?" said Rycroft, who asked that his corporate affiliation be withheld.


More Windows Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

His company's own developers are thoroughly investigated and required to undergo security training prior to writing company code. Likewise, vendors of proprietary software are required to sign contracts swearing that they've been through the same thing.

He mentioned terrorists in particular as a concern--what if his company adopted an open-source package, and a terrorist slipped a Trojan horse into it?

Now I think the concern about terrorists is far-fetched. Terrorists are more concerned with blowing things up and releasing poison gas than writing open-source software. But worry about thieves is not far-fetched; indeed, phishing scams and other forms of identity theft demonstrate every week that professional computer criminals are targeting financial institutions and their customers.

Moreover, it's easy for me to say fears over terrorism are far-fetched; I'm not responsible for billions of dollars of other people's money. As a matter of fact, the company Rycroft works for is a company I do business with. So I'm pleased to find that this company is devoting resources to figuring out how malefactors might break into its systems, and how to stop those malefactors.

If I found out that the company had a team of people researching the threat posed by mind-control aliens from Neptune, I would likely react by asking if they'd ever considered the threat of bloodsucking mind-control aliens from Neptune. Because it's better to think these things through than to get a nasty surprise.

Several attendees at the BOFS attempted to counter Rycroft's concerns.

Martin Doettling, VP of worldwide marketing for CollabNet, pointed out that the U.S. Department of Defense uses open-source software, apparently having satisfied itself over security concerns. He also noted that there are several companies that evaluate, certify, and support open-source packages. CollabNet, a vendor of collaboration software, uses open-source software in its products.

Rycroft said he's not so much concerned about major packages like Linux, but rather smaller projects like the Tapestry and Rails development tools.

James McGovern, chief security architect for the Property and Casualty Division at The Hartford, said those applications are so small that they can easily be reviewed by in-house developers to assure their security.

What do you think? Are open-source users risking allowing Trojan horses into their enterprise?


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links