Open source: does transparency lead to security?

被引:2
|
作者
机构
来源
Comput. Fraud Secur. | 2008年 / 9卷 / 11-13期
关键词
Best practices - Closed source - Community involvement - Open source developers - Open source projects - Proprietary software - Quality of softwares - Security vulnerabilities;
D O I
10.1016/S1361-3723(08)70137-4
中图分类号
学科分类号
摘要
A recent report criticising the security of open source software, and a flame war among Linux developers, have cast some doubts on whether open source software can achieve a sufficiently high level of security. Yet others believe that the principles of transparency and community involvement actually contribute to higher levels of software quality, including security, than can be achieved in the closed world of proprietary software. It's an important issue as open source projects continue their inroads into mainstream, enterprise solutions. Steve Mansfield-Devine examines the arguments and touches on the efforts being made to develop best practices, methodologies and tools to ensure security in open source software. Debates about open source software quickly develop a religious dimension. And nothing is more likely to set off an argument of inquisitional proportions than accusations of shortcomings in an area as important as security. Two recent events highlighted the issue of the security of open source software (OSS): one was a report claiming that open source developers are failing to achieve the necessary standards. The other was a suggestion that Linux kernel developers may have tried to cover up security vulnerabilities. However, when it comes to ensuring the quality of software from a security standpoint, is there really any difference between open source and closed source? © 2008 Elsevier Ltd. All rights reserved.
引用
收藏
相关论文
共 50 条
  • [41] Security in Open Source Web Content Management Systems
    Meike, Michael
    Sametinger, Johannes
    Wiesauer, Andreas
    IEEE SECURITY & PRIVACY, 2009, 7 (04) : 44 - 51
  • [42] Security Assessment of Virtual Machines in Open Source Clouds
    Donevski, Aleksandar
    Ristov, Sasko
    Gusev, Marjan
    2013 36TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2013, : 1094 - 1099
  • [43] Performance and Security Issue on Open Source Private Cloud
    Boonchieng, Ekkarat
    2014 INTERNATIONAL ELECTRICAL ENGINEERING CONGRESS (IEECON), 2014,
  • [44] The Use of Security Tactics in Open Source Software Projects
    Ryoo, Jungwoo
    Malone, Bryan
    Laplante, Phillip A.
    Anand, Priya
    IEEE TRANSACTIONS ON RELIABILITY, 2016, 65 (03) : 1195 - 1204
  • [45] Recent and noteworthy open source transportation security developments
    Andrew R. Thomas
    Journal of Transportation Security, 2008, 1 (1) : 67 - 70
  • [46] Security Vulnerabilities in Open Source Projects: An India Perspective
    Achuthan, Krishnashree
    SudhaRavi, Sreekutty
    Kumar, Renuka
    Raman, Raghu
    2014 2ND INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (ICOICT), 2014,
  • [47] Offshoring and open source will lead to new business models
    Anon
    Manufacturing Business Technology, 2005, 23 (02):
  • [48] Fiscal transparency and tax ethics: does better information lead to greater compliance?
    Capasso, Salvatore
    Cicatiello, Lorenzo
    De Simone, Elina
    Gaeta, Giuseppe Lucio
    Mourao, Paulo Reis
    JOURNAL OF POLICY MODELING, 2021, 43 (05) : 1031 - 1050
  • [49] Does disclosure on corporate governance lead to openness and transparency in how companies are managed?
    Parum, E
    CORPORATE GOVERNANCE-AN INTERNATIONAL REVIEW, 2005, 13 (05) : 702 - 709
  • [50] Transparency versus Security
    Weller, Bernhard
    Weimar, Thorsten
    CHALLENGING GLASS, 2008, : 491 - 500