The Fortify "Get the Facts" campaign (against Free software) was only mentioned very briefly here. It came in the form of a warning (it was also included in some link digests).
Microsoft and Fortify Software are enabling software developers and testers to build and deliver more secure applications. Visual Studio 2005 Team Edition for Software Testers offers an easy-to-use yet powerful framework for testing. Fortify leverages this infrastructure and adds Web application security testing capabilities. The combination of the two effectively brings basic security testing out of the realm of specialized experts and into the hands of software testers. In addition, Fortify provides its award-winning source code analysis capabilities to Visual Studio Team Edition for Developers so security flaws discovered in development and testing can be diagnosed and fixed quickly. Working closely with the Visual Studio team has enabled Fortify Software to incorporate its innovative software security capabilities within the powerful Visual Studio
Her main points:
1. There are other security toolkits other than Fortify. Just because you don’t use their system doesn’t mean you don’t care. 2. When reading vendor-sponsored studies consider the source. Always a wise move. 3. Open source projects in Fortify’s Open Review report fewer defects per thousand lines of code than proprietary products in the same review. I didn’t know that.
Fortify SCA helps security, testing and development teams pinpoint and eliminate security vulnerabilities in software applications. Fortify's patent-pending technology delivers the most accurate and reliable results with low false positives..
“There should really be an index somewhere to tell who's with who.”Watch who Fortify built an alliance with: Wipro, another Microsoft partner that's joint to it by the hip and lobbies for OOXML -- all against India's interests [1, 2, 3, 4, 5].
Fortify lives in a not-so-healthy neighbourhood of proprietary software companies that combat Free software and encourage software patents.
The apple doesn't fall so far from the tree.
With money on the table, there is no trust. Will you also believe OpenLogic and Black Duck, for example, despite being headed by former Microsoft employees? They sell open source fear. There should really be an index somewhere to tell who's with who. It would help tremendously. ⬆
Comments
aeshna23
2008-07-31 23:06:37
http://www.discoverthenetworks.org/
(Pointing out this website as good model is neither an endorsement of the site nor is it to say that all information there is accurate. Most websites on the left and the right get carried away and honesty suffers.)