FierceCIOFierceCIOTechWatchFierceMobileITFierceContentManagement   FierceVoIPFierceHealthITFierceFinanceIT
About | Sample | Privacy

Study claims that open source software is a security risk

Tools
Tags
Vulnerability
Tomcat
Open-Source
Open Source Projects
Larry Suto
Jacob West
Fortify Software

A study released earlier this week was critical of open source software after evaluating 11 such projects over the course of three months. "Open Source Study--How Are Open Source Development Communities Embracing Security Best Practices?" was put together by Fortify Software, together with consultant Larry Suto to gauge whether open source projects adhere to security best practices.

Various active projects were evaluated to determine their responsiveness to security questions, as well as vulnerability findings, among other metrics.  Application server Tomcat came up tops, though all the other projects gave a dismal showing. Jacob West, manager of Fortify's security research group, summed up what he thinks of the problem: "In two-thirds of these cases, you didn't get a response at all."

To read up more on the security risks of open source software:
- check out this Network World article

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.

More information about formatting options

What is 1 + 37?
To combat spam, please solve the math question above.