Bonum Certa Men Certa

Free Software More Secure, Say Experts

"The continuous and broad peer-review enabled by publicly available source code supports software reliability and security efforts through the identification and elimination of defects that might otherwise go unrecognized by a more limited core development team."

--CIO David Wennergren, Department of Defense (October 2009)



Summary: VeraCode argues that Free software is superior from the point of view of security

THE Register says that "Open source software has comparable security, faster bug fixing, and fewer potential backdoors than commercial software, according to a study on software application vulnerabilities by security firm VeraCode."



Here is another source speaking about the subject:

Around 58 percent of the applications tested by application security testing service provider Veracode in the past year-and-a-half failed to achieve a successful rating in their first round of testing. "The degree of failure to meet acceptable standards on first submission is astounding -- and this is coming from folks who care enough to submit their software to our [application security testing] services," says Roger Oberg, senior vice president of marketing for Veracode. "The implication here is that more than half of all applications are susceptible to the kinds of vulnerabilities we saw at Heartland, Google, DoD, and others -- these were all application-layer attacks."

[...]

Despite the relatively gloomy picture of developers still missing the mark initially on security, there were some bright spots in the report: Open-source software isn't as risky as you'd think, and financial services organizations and government agencies tend to have more secure applications from the get-go; more than half of their apps passed as acceptable in the first submission to testing, according to Veracode's report.


Someone mailed us a pointer to this article last night.

Start-up Israeli security company Trusteer claims to have hit on a different tactic when it comes to combating financial malware and making activities such as online banking more secure.

Rather than trying to eliminate every nasty from a user’s desktop, the four year-old company claims its Rapport software establishes a secure link between a customer’s desktop and the bank’s systems, excluding any malware in the process. The approach has been greeted with enthusiasm by analysts with a recent report from Frost and Sullivan neatly distilling the problem and Trusteer’s response to it.


"This is old news," says one of our readers who comments on "how to combat malware".

"Some time ago I suggested putting the VPN and IP stack on an embedded device. If they can't write to it, then they can't hack it. And seeing as Rapport is just another Windows process it's just as vulnerable as any other prog."

"Thanks to Mr. Gates, we now know that an open Internet with protocols anyone can implement is communism; it was set up by that famous communist agent, the US Department of Defense."

--Richard Stallman



Recent Techrights' Posts

Links 25/03/2025: Clownflare’s Slop and Bounties on Fake Patents
Links for the day
Let Them Eat 'Apps'
Go Appless
Linux Runs Almost Everything, But They Almost Never Tell You This (No Marketing Budget)
Only about 1% (or at most 2%) of the Linux Foundation's budget goes towards Linux; a lot is routed towards Bill Gates and Microsoft promotion
Free Software Community Folks Are Closer Together Than the Cliques and Opportunists Rallying Around "Open Source" (Openwashing, Marketing, Conniving)
Generally speaking, freedom-loving geeks learn to reject morbid elements and trolls, who end up expelled
Growing Poverty Rates in the United States of America (or Elsewhere) Beneficial to GNU/Linux Adoption
Toxic politics around the world, including the US, may mean weaker economies
European Patent Office (EPO) Illegally Turning to Slop Behind Closed Doors, Staff Objects to This Hidden Catastrophe
Who stands to gain from all this and at whose expense?
After US Government Funding Cuts the Centralisation of the Web (Especially Certificate Authority Let's Encrypt) is at Risk
They try to pull the plug on open protocols with decent encryption available (unless it is outsourced to third parties)
When Microsoft Folks Who Literally Strangle Women Try to Strangle Microsoft Critics
Speaking to Court staff yesterday, they too are shocked about those SLAPPs
Martinique: Windows Down to All-Time Low
we cannot expect Windows to ever recover
 
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, March 25, 2025
IRC logs for Tuesday, March 25, 2025
Links 25/03/2025: Terrace Workbench and Spellcheck in LibreOffice on FreeBSD
Links for the day
The Open Source Initiative (OSI) Might Get 'Forked' Soon
Someone who read our series has already taken a leading role
IBM Layoffs in the United Kingdom (UK) in 2025
Should Free software people trust such a secretive company?
Roku Will 'Lead' Attempts to Abolish the Illegal and Unconstitutional Unified Patent Court (UPC), Which Represents EPO Corruption and Lobbyism Spreading Upwards Inside the EU
When bribery buys policies and courts, even illegal policies and courts
Gemini Links 25/03/2025: Relaxation, Literary "Movements", and Gemini Mentions
Links for the day
Links 25/03/2025: Putin Sends Children to Battle, 23andMe Drowns as People's Highly Personal DNA Data Floats
Links for the day
Anticipated in 2018: Lilie James & Location tracking, Googlists complained
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 24, 2025
IRC logs for Monday, March 24, 2025
IBM (and Red Hat) on a Fast Train to Nowhere
What is the future of Fedora when IBM keeps removing its leadership?
Press Reports Say Almost 10,000 Western IBMers Laid Off
We've been trying to verify/corroborate this somehow
Gemini Links 24/03/2025: "Live Off the Land" and Life Without YouTube
Links for the day
Planet Ubuntu (or Ubuntu Planet) is LLM Slop
Reading chatbots' output is bad use of time
Days Ago yewtu.be Found a Workaround That Made Invidious Work Again. Then Google Broke All the Instances (Again).
"Youtube changed something again, so if a video does not play, it's because of that."
The European Patent Office (EPO) is Slowly Killing Its Own Staff; All It Cares About Is Money
The Office hasn't been run by a scientist for about 18 years already
Links 24/03/2025: US Detaining Innocent People, F-35 Contracts Suspended Due to Hostilities
Links for the day
Cellphones (Mobile Phones) in Classrooms
A recent study confirmed that people's intelligence has dropped in recent years/decades
Is the FSF Being 'Trolled' by Microsofters Pushing C# (Microsoft)?
Who stands to benefit from training people to use and spread Microsoft?
Matthew J. Garrett is "Former Microsoft Researcher", According to Microsoft's Serial Strangler
Their argument is something along the lines of, "what Roy published damaged my career prospects, so I want Roy to pay me...
Links 24/03/2025: Political Catchup and Environmental Concerns
Links for the day
Windows Has Now Fallen to Rather Ridiculous 3% "Market Share" in Iraq (Windows Was Measured at 100% Back in 2010)
Iraq is not a place where Windows can make a comeback
Gemini Links 24/03/2025: Working With Music and Unconscious Influence
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 23, 2025
IRC logs for Sunday, March 23, 2025