Most Popular Stories
Events
Sponsored Links
Latest News
Popular Topics
Whitepapers
- IM and Presence: Achieving Mission Critical Status in the Enterprise
- The Definitive IP Address Management (IPAM) Intelligence Whitepaper
- Web Services Addressing 1.0 - Metadata
- How Social Computing, Team Collaboration, and Enterprise Content Management Drive Competitive Advantage
- Collaboration and Social Media: Taking Stock of Today's Experiences and Tomorrow's Opportunities
- Service Oriented Architecture
Study claims that open source software is a security risk
A study released earlier this week was critical of open source software after evaluating 11 such projects over the course of three months. "Open Source Study--How Are Open Source Development Communities Embracing Security Best Practices?" was put together by Fortify Software, together with consultant Larry Suto to gauge whether open source projects adhere to security best practices.
Various active projects were evaluated to determine their responsiveness to security questions, as well as vulnerability findings, among other metrics. Application server Tomcat came up tops, though all the other projects gave a dismal showing. Jacob West, manager of Fortify's security research group, summed up what he thinks of the problem: "In two-thirds of these cases, you didn't get a response at all."
To read up more on the security risks of open source software:
- check out this Network World article
Related Stories
- Fundamental flaw in DNS protocol discovered
- Red Hat 's new CEO eyes the cloud
- 22 traits that make you a geek
- Critical vulnerability opens electrical grids to attack
- DNS flaws opens the door to an array of attacks
- Apple fix more than 20 security flaws in October update
- Microsoft: We are a 'mixed source' company
- Tips to cut IT costs
- OpenSolaris OS for mainframe released
- ALSO NOTED: 3rd-party patch for IE vulnerability; Getting harder to staff the data center; and much more...
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceSarbox | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceBiotech | FierceBioResearcher | FiercePharma | FierceVaccines | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2008 FierceMarkets, Inc. All rights reserved. |
![]() |





