Open source: does transparency lead to security?

被引:2
|
作者
机构
来源
Comput. Fraud Secur. | 2008年 / 9卷 / 11-13期
关键词
Best practices - Closed source - Community involvement - Open source developers - Open source projects - Proprietary software - Quality of softwares - Security vulnerabilities;
D O I
10.1016/S1361-3723(08)70137-4
中图分类号
学科分类号
摘要
A recent report criticising the security of open source software, and a flame war among Linux developers, have cast some doubts on whether open source software can achieve a sufficiently high level of security. Yet others believe that the principles of transparency and community involvement actually contribute to higher levels of software quality, including security, than can be achieved in the closed world of proprietary software. It's an important issue as open source projects continue their inroads into mainstream, enterprise solutions. Steve Mansfield-Devine examines the arguments and touches on the efforts being made to develop best practices, methodologies and tools to ensure security in open source software. Debates about open source software quickly develop a religious dimension. And nothing is more likely to set off an argument of inquisitional proportions than accusations of shortcomings in an area as important as security. Two recent events highlighted the issue of the security of open source software (OSS): one was a report claiming that open source developers are failing to achieve the necessary standards. The other was a suggestion that Linux kernel developers may have tried to cover up security vulnerabilities. However, when it comes to ensuring the quality of software from a security standpoint, is there really any difference between open source and closed source? © 2008 Elsevier Ltd. All rights reserved.
引用
收藏
相关论文
共 50 条
  • [1] Open source and security: why transparency now equals strength
    Murray, Dale
    Network Security, 2020, 2020 (07): : 17 - 19
  • [2] Does open source improve system security?
    Witten, B
    Landwehr, C
    Caloyannides, M
    IEEE SOFTWARE, 2001, 18 (05) : 57 - +
  • [3] Does Transparency Lead to Pay Compression?
    Mas, Alexandre
    JOURNAL OF POLITICAL ECONOMY, 2017, 125 (05) : 1683 - 1721
  • [4] On the security of open source software
    Payne, C
    INFORMATION SYSTEMS JOURNAL, 2002, 12 (01) : 61 - 78
  • [5] Is Open Source Security a Myth?
    Schryen, Guido
    COMMUNICATIONS OF THE ACM, 2011, 54 (05) : 130 - +
  • [6] Security and trust in open source security tokens
    Schink M.
    Wagner A.
    Unterstein F.
    Heyszl J.
    1600, Ruhr-University of Bochum (2021): : 176 - 201
  • [7] Open Source Software (OSS) Transparency Tutorial
    Woody, Carol
    Hissam, Scott
    2024 IEEE SECURE DEVELOPMENT CONFERENCE, SECDEV 2024, 2024, : 186 - 187
  • [8] Open Source Transparency The Making of an Altered Identity
    Campbell, Daryl
    DIGITAL NEXUS: IDENTITY, AGENCY, AND POLITICAL ENGAGEMENT, 2016, : 89 - 106
  • [9] WHICH TRANSPARENCY DOES THE OPEN GOVERNMENT REQUIRE?
    Marinez Navarro, Freddy
    REVISTA DE GESTION PUBLICA, 2013, 2 (02): : 303 - 333
  • [10] Blocklist Babel: On the Transparency and Dynamics of Open Source Blocklisting
    Feal, Alvaro
    Vallina, Pelayo
    Gamba, Julien
    Pastrana, Sergio
    Nappa, Antonio
    Hohlfeld, Oliver
    Vallina-Rodriguez, Narseo
    Tapiador, Juan
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (02): : 1334 - 1349