Study: Open source poses security risks

A conservative US think tank suggests in an upcoming report that open-source software is inherently less secure than proprietary software.

The white paper, Opening the Open Source Debate, from the Alexis de Tocqueville Institution (ADTI) will suggest that open source opens the gates to hackers and terrorists.

"Terrorists trying to hack or disrupt US computer networks might find it easier if the federal government attempts to switch to 'open source' as some groups propose," ADTI said in a statement released ahead of the report.

Open-source software is freely available for distribution and modification, as long as the modified software is itself available under open-source terms. The Linux operating system is the best-known example of open source, having become popular in the Web server market because of its stability and low cost.

Many researchers have also suggested that since a large community contributes to and scrutinises open-source code, security holes are less likely to occur than in proprietary software, and can be caught and fixed more quickly.

The ADTI white paper, to be released next week, will take the opposite line, outlining "how open source might facilitate efforts to disrupt or sabotage electronic commerce, air traffic control or even sensitive surveillance systems," the institute said.

"Computer systems are the backbone to U.S. national security," said ADTI Chairman Gregory Fossedal. "Before the Pentagon and other federal agencies make uninformed decisions to alter the very foundation of computer security, they should study the potential consequences carefully."

Advertisement

Talkback 2 comments

    The Alexis de Tocqueville Inst ...Anonymous -- 04/06/02

    The Alexis de Tocqueville Institution has a reputation for their knowledge of computer security issues? Well, no, they actually appear to be a shill for large corporates and for Microsoft in particular - witness a whole page of PR about MCSE training.

    Frankly, I don't see why ZDnet bothers reporting this kind of junk.

    They're absolutely right Anonymous -- 28/08/08

    At the BlackHat 2008 conference, a presenter
    showed how a perusal of Xen's source demonstrated a simple buffer overflow in, of all places, the security code. A user in a non-privileged domain was shown to have the power to corrupt Xen's heap and gain control over the system. If the developer had not been able to see the source code, the problem would not have been obvious or apparent.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • Array Can the Telco Reform Act be win-win?
    In the second of our two programs looking at the Senate Inquiry into the Telecommunications Legislation Amendment Bill, we hear from shareholders, bureaucrats and industry groups.
  • Array Has New Zealand's smiling assassin delivered?
    One year into its tenure, how has the new New Zealand Government performed on issues of technology and telecommunications?
  • More blogs »

Tags

Back to top

Featured