Study: Open source poses security risks

A conservative US think tank suggests in an upcoming report that open-source software is inherently less secure than proprietary software.

The white paper, Opening the Open Source Debate, from the Alexis de Tocqueville Institution (ADTI) will suggest that open source opens the gates to hackers and terrorists.

"Terrorists trying to hack or disrupt US computer networks might find it easier if the federal government attempts to switch to 'open source' as some groups propose," ADTI said in a statement released ahead of the report.

Open-source software is freely available for distribution and modification, as long as the modified software is itself available under open-source terms. The Linux operating system is the best-known example of open source, having become popular in the Web server market because of its stability and low cost.

Many researchers have also suggested that since a large community contributes to and scrutinises open-source code, security holes are less likely to occur than in proprietary software, and can be caught and fixed more quickly.

The ADTI white paper, to be released next week, will take the opposite line, outlining "how open source might facilitate efforts to disrupt or sabotage electronic commerce, air traffic control or even sensitive surveillance systems," the institute said.

"Computer systems are the backbone to U.S. national security," said ADTI Chairman Gregory Fossedal. "Before the Pentagon and other federal agencies make uninformed decisions to alter the very foundation of computer security, they should study the potential consequences carefully."

Advertisement

Talkback 2 comments

    The Alexis de Tocqueville Inst ...Anonymous -- 04/06/02

    The Alexis de Tocqueville Institution has a reputation for their knowledge of computer security issues? Well, no, they actually appear to be a shill for large corporates and for Microsoft in particular - witness a whole page of PR about MCSE training.

    Frankly, I don't see why ZDnet bothers reporting this kind of junk.

    They're absolutely right Anonymous -- 28/08/08

    At the BlackHat 2008 conference, a presenter
    showed how a perusal of Xen's source demonstrated a simple buffer overflow in, of all places, the security code. A user in a non-privileged domain was shown to have the power to corrupt Xen's heap and gain control over the system. If the developer had not been able to see the source code, the problem would not have been obvious or apparent.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured