<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rich Sharples&#039; Blog &#187; coverity</title>
	<atom:link href="http://blog.softwhere.org/tag/coverity/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.softwhere.org</link>
	<description>Musings on the world of software from the sharp end of the long tail</description>
	<lastBuildDate>Sat, 27 Aug 2011 01:03:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Security and Open Source</title>
		<link>http://blog.softwhere.org/archives/260</link>
		<comments>http://blog.softwhere.org/archives/260#comments</comments>
		<pubDate>Wed, 06 Aug 2008 15:19:53 +0000</pubDate>
		<dc:creator>sharps</dc:creator>
				<category><![CDATA[open source]]></category>
		<category><![CDATA[Red Hat]]></category>
		<category><![CDATA[coverity]]></category>
		<category><![CDATA[fortify]]></category>
		<category><![CDATA[JBoss]]></category>
		<category><![CDATA[OSS]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.softwhere.org/?p=260</guid>
		<description><![CDATA[I&#8217;ve been meaning to find some time to respond to a recent report by Fortify that cast some pretty negative aspersions on the security of Open Source software. Their conclusions are fairly sweeping generalizations that could be applied to just about anything : Government and commercial organisations… should use open source applications with great caution&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been meaning to find some time to respond to a <a href="http://www.linuxworld.com.au/index.php?id=239169459&amp;eid=-50">recent report by Fortify</a> that cast some pretty negative aspersions on the security of Open Source software. Their conclusions are fairly sweeping generalizations that could be applied to just about anything :</p>
<blockquote><p>Government and commercial organisations… should use open source applications with great caution&#8221;</p></blockquote>
<p>absolutely true &#8211; but also true for software developed under any model with any license.</p>
<blockquote><p>Open source projects should adopt robust security practices from their commercial counterparts.&#8221;</p></blockquote>
<p>for some reason Fortify believes that commercial software is the benchmark for software security &#8211; though doesn&#8217;t provide any evidence of that, nor does it provide any detail what those practices are. Many commercial software companies are proprietary and closed and lack transparency &#8211; so we really don&#8217;t know if they&#8217;re better or worse. I&#8217;d also suggest that commercial / proprietary software companies can learn a lot from open source &#8211; and indeed many have.</p>
<p>But here&#8217;s the real issue and the irony &#8211; Fortify could not write this report for closed, proprietary products &#8211; they would not be able to include proprietary products in this report. it&#8217;s just not possible. That should be a real concern.</p>
<p>IMO &#8211; the recent <a href="http://scan.coverity.com/report/Coverity_White_Paper-Scan_Open_Source_Report_2008.pdf">report from Coverity</a> offers a much more balanced view of security defects in open source</p>
<p>On the whole &#8211; the report was pretty positive on JBoss. Firstly, Red Hat sponsored projects did pretty well in their static analysis. As you can see from the chart &#8211; the vulnerability density for JBoss AS and Hibernate were the lowest of the projects analysed.</p>
<p><a href="http://blog.softwhere.org/wp-content/uploads/2008/08/vuln-density.gif"><img class="alignnone size-medium wp-image-261" title="vuln-density" src="http://blog.softwhere.org/wp-content/uploads/2008/08/vuln-density-300x248.gif" alt="" width="300" height="248" /></a></p>
<p>Secondly &#8211; our sponsored projects benefit from <a href="http://www.redhat.com/security/team/">Red Hat&#8217;s security response team</a> and their best practices, in addition JBoss has it&#8217;s own security expert &#8211; <a href="http://anil-identity.blogspot.com/">Anil Saldhana.<br />
</a></p>
<p>Since the report was published we&#8217;ve also taken action to ensure Red Hat&#8217;s secalert mail alias is more prominent in more places.</p>
<p>Finally &#8211; I should add &#8211; we take security pretty seriously and invest pretty heavily &#8211; we have to do this because our customers demand it. One example is that JBoss <a href="https://www.redhat.com/solutions/government/commoncriteria/jboss.html">EAP 4.3 is currently undergoing</a> Common Criteria Evaluation at EAL 2+ &#8211; that a pretty serious and long term commitment.</p>
<p>Update &#8211; I noticed that Fortify has a <a href="http://extra.fortifysoftware.com/blog/2008/07/the_empty_debate_over_open_sou.html">blog</a> &#8220;&#8230; a place for  place for discussion and feedback, both positive and negative&#8221; unfortunately they&#8217;ve blocked comments &#8211; so maybe not.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.softwhere.org%2Farchives%2F260&amp;title=Security%20and%20Open%20Source" id="wpa2a_2"><img src="http://blog.softwhere.org/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.softwhere.org/archives/260/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

