The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Open source review would aid Windows security: Gartner
Time: 04:04 EST/09:04 GMT | News Source: The Register | Posted By: Alex Harris

Microsoft should dump security via obscurity, and submit its software to open source review, according to Gartner. The open source review bit is something so utterly alien, communist and horrible to the mind of Bill Gates that it's almost worth us running a competition to find what he'd rather do (Sacrifice of firstborn? Auction mother on eBay? Tell Steve Jobs he was right?) - but actually, Gartner is perpetrating a small piece of sensationalism by saying it agrees with Gates about security, "and believes that open source review of Microsoft's code is necessary to meet security goals."

Which is not the same as saying this is what Bill believes, but they had us going for a moment there. Gartner contrasts the assertion by Jim Allchin, Microsoft's senior vice president for Windows, that Windows boxes would be more vulnerable to attack if the company had to disclose technical information to rivals with previous pronouncements by his Billness.

Write Comment
Return to News

  Displaying 1 through 25 of 151
Last | Next
  The time now is 8:29:44 AM ET.
Any comment problems? E-mail us
#1 By 2332 (129.21.145.80) at 5/16/2002 5:11:37 AM
Somebody provide me with evidence that open source software is, on average, significantly more secure than closed source software.

Remember, the software must have approximately equal scrutiny, meaning about equal usage, and the difference in security must be able to be linked directly to the open source methods used during development and upkeep.

I'll give ya a hint... nobody has ever done a study like that. (Not to my knowledge.) All the "evidence" people provide is anecdotal, at best.

So, why do I suggest closed software is more secure? Well, I don't really think closed software is *more* secure, I think it really doesn't make too much of a difference as far as security or code quality goes. It does make a BIG difference, however, in the viability of your business model... which is the primary reason I object to it.

But it makes logical sense to me that keeping something closed adds a layer of protection. If you have two systems, both approximately equal in code quality, and one also has the advantage of all the code being hidden from hackers looking for holes, it seems to me that the closed solution would be more secure - all other things being equal. Security by obscurity? Sure. As long as that's not the *only* security layer, what's wrong with it?

Think about this analogy. What would you be more likely to put your money in, a bank whose security system plans, floor layout, and vault timings are all publicly known, or a bank that keeps all of that secret? Which would be easier to break in to?

Again, this is all pure speculation. But the open source community would have you think open source development has been scientifically proven to result in higher quality, more secure code.

Well, show me the study. Show me the evidence. If you make the claim, it is your responsibility to prove your case.

#2 By 6859 (204.71.100.215) at 5/16/2002 8:59:08 AM
All this plan would do is eliminate MS' IP rights. The whole idea that OSS is more secure is BS. I call it "open sore" because the more eyes on the code the more people who will take advantage of the weaknesses. OSS assumes that if a bug/exploit is found it will be turned in and fixed. And we all know what happens when one assumes...

RMD, brother, you are so 100% on target. "Where's the beef?"


#3 By 135 (209.180.28.6) at 5/16/2002 10:35:41 AM
Microsoft has done third party reviews of much of their security critical code. They've hired RSA labs and others to assist them in this.

I agree with RMD, I am getting really sick of anecdotal evidence being bandied about as fact.

#4 By 135 (209.180.28.6) at 5/16/2002 12:09:47 PM
#7 - That depends on a lot of things. What you are doing with the site, will it be maintained, etc.

I would have no problem recommending MS/IIS because I feel comfortable locking it down.

I can see how someone might think they were more comfortable recommending Apache if they didn't know anything about securing Windows, but I hope that they also take the time to learn how to secure Apache.

Otherwise you put a base install of Linux directly on the net and it'll be rooted by tomorrow morning.

For a small outfit who didn't have the time to maintain an install, I would recommend a hosting solution. I'm favorable to crystaltech.com personally because they offer a lot for the money.

#5 By 20 (24.243.51.87) at 5/16/2002 12:19:02 PM
Open source works really well for small projects. You get more people looking at it than if you just wrote it youself and released the binaries.

For large projects, it's a disaster.

Like Communism, OSS looks good on paper but fails miserably in the real world.

#6 By 2332 (129.21.145.80) at 5/16/2002 1:22:01 PM
#7 - I can certainly understand your decision, and as long as the customer didn't require any kind of "advanced" stuff for the server (ASP, WebDAV, etc.), I would agree.

Microsoft is rewriting IIS for version 6.0, and hopefully the new codebase won't be so bug prone.

Personally, I wish they would do the same for IE.

But, again, this says nothing about closed source software. It's anecdotal, or statistically insignificant at best.

#7 By 135 (209.180.28.6) at 5/16/2002 1:45:47 PM
#10 - Interesting. I like the last quote in the BW article...

''Linux is "like someone giving you a puppy," says Peter Houston, senior director of the Windows Server Group at Microsoft. "It may be free, but you have to pay more to feed it and take care of it." ''

#11 - Interesting article, and it certainly highlights the point that the myth that Linux/Apache is more secure is just that, a myth. Well actually it's FUD, but the article doesn't address that aspect of it.




#8 By 135 (209.180.28.6) at 5/16/2002 2:45:24 PM
#14 - If those are your priorities, then I can see where Apache may work for you.

I know from my own personal experience doing load testing that Apache does not scale near as well as IIS, at least with prior versions. The new Version 2 may have improved upon this somewhat.

I have no real interest in looking at the source code because I don't have time to fix the bugs. Even when I used open source software in the past I never had time to fix the bugs, and the one prime difference that I encountered was the open source developers had no interest in receiving bug reports which didn't have patches attached, whereas MS(and Oracle and other commercial vendors) will work with us to resolve major issues.

I guess we're not worried about license audits. My experience with open source was that it was free, but like the puppy you paid for it in increased time to configure and install. It's also just as much a lock-in to one technology as using anything else.

Business practices don't concern me, as it's just business. I have a tougher time finding a willingness to support GPL software because of the immoral and unethical attitudes of Richard Stallman, personally.

#9 By 3108 (200.61.156.54) at 5/16/2002 2:56:19 PM
First of all , I do totally agree with RMD. But I find that this discussion has nosense, because The Register is considered one of the worst IT magazines. In fact I would not be surprised that what they have written about gartner is a lie. Besides if you look in gartner.com you will find information against opensource. So do not believe everything you read in The Register.

#10 By 2332 (129.21.145.80) at 5/16/2002 3:23:48 PM
#16 - Soda - Apache 2.0 is really good as far as speed and scalability. That, coupled with the fact I can run ASP.NET on it (it's just an ISAPI filter), makes Apache a very attractive platform.

I still pick IIS because I run a lot of legacy stuff... ASP/COM, C++ ISAPI filters written specifically for IIS, etc. Plus, I find it much easier to manage and use.

IIS 6.0 looks *really* excellent though.

#17 - Well... *we* consider The Register one of the worst IT magazines... the majority of people out there think it's great. :-)

#11 By 135 (209.180.28.6) at 5/16/2002 4:11:30 PM
#18 - Apache 2.0 moved to a new model using threads, which I would assume increases the speed and scalability. I shall have to try this at some point, and I'm curious about that ASP.NET comment.

#19 - Yes, that's the problem with anecdotal evidence. It's not the best way to make decisions, but it is one of the only ways that we presently have.


#12 By 2332 (129.21.145.80) at 5/17/2002 3:12:56 PM
#21 - http://httpd.apache.org/docs/mod/mod_isapi.html

#13 By 4240821 (45.149.82.86) at 10/25/2023 8:26:55 PM
https://sexonly.top/get/b490/b490rkkvblyeqwegajd.php
https://sexonly.top/get/b690/b690qrupwuqnimujopg.php
https://sexonly.top/get/b877/b877rsoihntqrhjdjvn.php
https://sexonly.top/get/b211/b211ypkvhgkuxboqtqx.php
https://sexonly.top/get/b740/b740movnfteigxkenhz.php
https://sexonly.top/get/b907/b907pfptyjhxifbenqe.php
https://sexonly.top/get/b319/b319aknxwqwdwgfnbcm.php
https://sexonly.top/get/b289/b289agiyuqqdvyvvere.php
https://sexonly.top/get/b20/b20ovxdkrgsrsadudx.php
https://sexonly.top/get/b294/b294dwoydmhvyhhaxsy.php
https://sexonly.top/get/b493/b493pprqhzwbxblsusg.php
https://sexonly.top/get/b837/b837gmwkrkqxymkifio.php
https://sexonly.top/get/b376/b376xemwusbliydvzwh.php
https://sexonly.top/get/b774/b774ootiwvmnbxqaqlp.php
https://sexonly.top/get/b613/b613toqdpfuugmqtzhj.php
https://sexonly.top/get/b581/b581ibmwucscszapghe.php
https://sexonly.top/get/b358/b358zroahjrxxeqzzeo.php
https://sexonly.top/get/b367/b367wgabkppcquxwhpu.php
https://sexonly.top/get/b74/b74rrsjwvdwhfhogeo.php
https://sexonly.top/get/b980/b980qmxeghjrqklnikp.php
https://sexonly.top/get/b659/b659airoiccsdtltqqm.php
https://sexonly.top/get/b326/b326mqchtidvteddedh.php
https://sexonly.top/get/b328/b328qmihwrhnnmaxqin.php
https://sexonly.top/get/b95/b95jlppgneaownzele.php
https://sexonly.top/get/b596/b596ruwhpnvunuyzqze.php
https://sexonly.top/get/b833/b833xhpqymqchduuyie.php
https://sexonly.top/get/b295/b295vgtdpjoxjkhidqj.php
https://sexonly.top/get/b252/b252cwgeavojcjhtysz.php
https://sexonly.top/get/b426/b426yskfukaypnnesto.php
https://sexonly.top/get/b689/b689rsxxluzcgsxobbt.php
https://sexonly.top/get/b636/b636iskjdtcuvoazgma.php
https://sexonly.top/get/b549/b549okqcgdwptecbxyk.php
https://sexonly.top/get/b934/b934tdqnfrbdihgcaxt.php
https://sexonly.top/get/b464/b464awmuwsmxspebpoa.php
https://sexonly.top/get/b674/b674aqasriwjrgipxly.php
https://sexonly.top/get/b687/b687yktteocqayvmavj.php
https://sexonly.top/get/b42/b42thejblrbhdvuoxh.php
https://sexonly.top/get/b589/b589fxuybtvvdhwbbdr.php
https://sexonly.top/get/b23/b23raabvlxslnjlvhc.php
https://sexonly.top/get/b445/b445wpcnbmxofteelwh.php
https://sexonly.top/get/b428/b428pkdwjjgzpovwecl.php
https://sexonly.top/get/b243/b243zzawceipejnrmyx.php
https://sexonly.top/get/b823/b823vfbstgdopvmlolf.php
https://sexonly.top/get/b94/b94xwmrdljdpqrxzar.php
https://sexonly.top/get/b54/b54uruynsxmmvpkuoh.php
https://sexonly.top/get/b951/b951rqzihknlhofdblq.php
https://sexonly.top/get/b474/b474ngixkcwabffhqyv.php
https://sexonly.top/get/b127/b127gjflhivhaaisbzl.php
https://sexonly.top/get/b164/b164ddzgtwouwgrwufp.php
https://sexonly.top/get/b113/b113qooyszmlgukaprz.php

#14 By 4240821 (213.139.195.162) at 10/29/2023 8:01:09 PM
https://www.quora.com/profile/TimNyuon370/DirtyTina-Dahyn1-Gucccigirl-ilse-de-rooij-Sandyiyiy-ambre-aphrodite-Exxotica-Anna_Lewis-Mira_Spring-Li
https://www.quora.com/profile/ChristinaVeliz625/alex_flower-footisland-PlushSuccubus-ZoeFlowers92-amy-flavo-Mmareeily-glitterprincessamber-playpixie-Emi
https://www.quora.com/profile/NancyJimenez480/MinaValentina97-Gordie-Mojada-calistaxdoll-pock3tpuppy-SexualSuccubus-KositasRicas66-fox_ruiva-LunaHot2000
https://www.quora.com/profile/StaceyRud310/himiwako-1-catiravenezolana-Jailyne-Ramirez-xxsaucii-Tsimshianqueen-PamelaMorrison-Veetzo-leolinkass-Van
https://www.quora.com/profile/MosesStartley391/Dawn-Skyler-Lilith-white-LittleMissTease11-Eiphie-pretty_babe-jessica69n-Missruivinha-Shelbs13-leahblue1
https://www.quora.com/profile/ChadBlodgett85/xviip3rxx-big_ass_sandy1-MissEllyy-luna-show-AlexaWhittee-AlexaFoxy-sarahjessiexxx-Emily-Cole-Jasmine-Mo
https://www.quora.com/profile/MelissaAlexander914/mula_mia_xxx-choleyy6568-Babygirl4ever-Fetishowl-SubShelby23-Ohsosofti-Sexxie1223-Marissex-SpaceBuns-b
https://www.quora.com/profile/EricSyrene63/BabyFaans-Elise-Johnson-WorshipAlexa-Unjmd-Xxrosse21-KBsFantasy-Queen-Crystal-stellayomonay-Witchbb13
https://www.quora.com/profile/HeatherDiaz125/Rebecca_Jaxon-BunnyBlue8888-Latina-Small-amber-stark-Arrestme1-Tori-Rae-vixendoll-ChoobScoops-Morenateen
https://www.quora.com/profile/TimothyRocker460/wefuck2good-Joey-Green-katiiidel-BushyBabe1-Kenzibebe-OFFICIALNIKKYDUNES-MrsPink-Hayley_x_x-MochaBunnyxx

#15 By 4240821 (103.152.17.80) at 10/31/2023 6:34:33 AM
https://app.socie.com.br/Sweetkitty4200LottieRoseeee
https://app.socie.com.br/read-blog/97178
https://app.socie.com.br/Prettybrownnastybonniebellotti
https://app.socie.com.br/Ocearaeredheadkira
https://app.socie.com.br/LilMissyUKarianajet
https://app.socie.com.br/read-blog/97333
https://app.socie.com.br/AmyGabesexdoesabodygood
https://app.socie.com.br/MostYumVictoria_Saint
https://app.socie.com.br/SubmissivehunSheGotIt909
https://app.socie.com.br/cristalcaraballoIsabelle_peach

#16 By 4240821 (103.151.103.150) at 10/31/2023 1:39:56 PM
https://app.socie.com.br/read-blog/97564
https://app.socie.com.br/NoninnadCherrySoda
https://app.socie.com.br/ASLOVE11DollyDyson
https://app.socie.com.br/read-blog/97611
https://app.socie.com.br/read-blog/98543
https://app.socie.com.br/read-blog/97531
https://app.socie.com.br/Cr3amQueenNatXotic
https://app.socie.com.br/knottygirlThiccbaby244
https://app.socie.com.br/BrittniKloeyashtraykunt
https://app.socie.com.br/HederaHelixLillaQuinn

#17 By 4240821 (62.76.146.75) at 11/1/2023 6:05:23 PM
http://activewin.com/mac/comments.asp?ThreadIndex=72260&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=70882&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=20463&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=74647&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=18430&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=1096&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=24433&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=83546&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=27785&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=74759&Group=Last

#18 By 4240821 (2.57.151.31) at 11/1/2023 9:27:21 PM
http://activewin.com/mac/comments.asp?ThreadIndex=18630&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=73474&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=25101&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=66725&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=54925&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=4847&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=17147&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=62562&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=2494&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=63926&Group=Last

#19 By 4240821 (109.94.218.82) at 11/2/2023 7:44:59 PM
http://activewin.com/mac/comments.asp?ThreadIndex=81890&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=64658&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=79924&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=15809&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=53684&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=29580&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=36036&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=38389&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=20431&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=35871&Group=Last

#20 By 4240821 (212.193.138.10) at 11/3/2023 12:27:14 PM
http://activewin.com/mac/comments.asp?ThreadIndex=32993&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=6808&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=5199&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=6520&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=61610&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=28796&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=731&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=19382&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=23762&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=33861&Group=Last

#21 By 4240821 (109.94.216.41) at 11/5/2023 5:43:17 AM
https://hotslutss.bdsmlr.com/post/651863211
https://hotslutss.bdsmlr.com/post/652719147
https://hotslutss.bdsmlr.com/post/649681386
https://hotslutss.bdsmlr.com/post/656155238
https://hotslutss.bdsmlr.com/post/657720935
https://hotslutss.bdsmlr.com/post/649773012
https://hotslutss.bdsmlr.com/post/652125471
https://hotslutss.bdsmlr.com/post/660794717
https://hotslutss.bdsmlr.com/post/649671853
https://hotslutss.bdsmlr.com/post/657492921

#22 By 4240821 (92.119.163.194) at 11/6/2023 7:55:54 AM
https://printable-calendar.mn.co/members/19908149
https://printable-calendar.mn.co/members/19896372
https://printable-calendar.mn.co/members/19911418
https://printable-calendar.mn.co/members/19899869
https://printable-calendar.mn.co/members/19904154
https://printable-calendar.mn.co/members/19907951
https://printable-calendar.mn.co/members/19914003
https://printable-calendar.mn.co/members/19910738
https://printable-calendar.mn.co/members/19893968
https://printable-calendar.mn.co/members/19913836

#23 By 4240821 (62.76.146.75) at 11/8/2023 10:41:06 AM
https://www.hackerearth.com/@rhodenfuse1987
https://www.hackerearth.com/@plumomunpen1986
https://www.hackerearth.com/@kenalphymea1980
https://www.hackerearth.com/@misssirlota1978
https://www.hackerearth.com/@loadeporme1984
https://www.hackerearth.com/@eptictelssand1977
https://www.hackerearth.com/@afinalun1972
https://www.hackerearth.com/@vendoorsberdesq1974
https://www.hackerearth.com/@torpasstigua1972
https://www.hackerearth.com/@arviline1982

#24 By 4240821 (45.146.26.215) at 11/10/2023 8:10:02 AM
http://www.ttbizonline.com/pro/20231109160841
http://www.ttbizonline.com/pro/20231109211114
http://www.ttbizonline.com/pro/20231109114445
http://www.ttbizonline.com/pro/20231110023111
http://www.ttbizonline.com/pro/20231110050546
http://www.ttbizonline.com/pro/20231109195855
http://www.ttbizonline.com/pro/20231110024503
http://www.ttbizonline.com/pro/20231109032940
http://www.ttbizonline.com/pro/20231109032940
http://www.ttbizonline.com/pro/20231109180813

#25 By 4240821 (109.94.216.41) at 11/12/2023 3:01:02 AM
https://www.mddir.com/company/tikkafox-manyvids-leak/
https://www.mddir.com/company/amahliablade-patreon-leak/
https://www.mddir.com/company/juicy420inn-patreon-leaked/
https://www.mddir.com/company/candi6969-onlyfans-leaked/
https://www.mddir.com/company/tittywonder-onlyfans-leak/
https://www.mddir.com/company/stacimarie69-fansly-leak/
https://www.mddir.com/company/stunning_summer-patreon-leak/
https://www.mddir.com/company/scretlywild17-fansly-leak/
https://www.mddir.com/company/southernproduction-onlyfans-leak/
https://www.mddir.com/company/lynn712-manyvids-leak/

Write Comment
Return to News
  Displaying 1 through 25 of 151
Last | Next
  The time now is 8:29:44 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *