Does Open Source Need a Red Team?
"The Team could also provide a set of recommended processes and tools for O.S. projects to follow prior to submission to the Red Team test queue. This by itself would be a valuable tool.
Such teams are sometimes used by companies to test the security of their networks and software. The O.S. community have done an excellent job so far, but as open source is used more and more by the mainstream computer users, vetting by a 3rd party would help make many organizations more likely to accept a piece of O.S. software.
The Team would, like any open source project, be comprised of both experts and newbies. The newbies would have the opportunity of doing real testing under the guidance of folks who know more, thereby becoming more expert themselves. The experts would provide a centralized open-source-oriented set of recommendations and specialized review as needed.
Either the Red Team or its members could also provide paid services for commercial software, and could participate with university CS departments in training students, providing the opportunity for valuable cross-training between schools. It might even be possible to arrange course credit for work on the Team.
Many Open Source projects could benefit from such a 3rd party group to recommend development procedures, code styles, and actual testing to teach and motivate better security practices in code design. The plain fact is that many (most?) of us developers are not completely 'up' on the issue of security - it's a very dynamic area of specialization. This initiative could be another resource that will be useful in establishing OS in the mainstream."
I'd rather have an OSI Red Team that was more like Delta Force.
They could wear MIT wearables, have an internet uplink, and code-fu your ass into submission.
-- I'd say your post was about 3 monkeys, 18 minutes.
Folks... it's called "bugtraq" and it's been around for decades.
;)
Anyone else amused by the irony that someone is advocating open source software should start practising the things closed source development is now getting buzzword compliant with, which is made popular in that arena because its already such a success with open source software?
Matt
... Sure, so long as they don't join Starfleet.
Captain Kirk, Mr. Spock, and the Red Team beam down to an alien planet -
Kirk - "Rodriguez, check to see what's causing that buzzing sound coming from the rock nearby."
Rodriguez (Red Team) - "Bleep you! Go check it out yourself! We've lost three Red Team members this past week that beamed down to strange worlds with you!"
"We are all in the gutter, but some of us are looking at the stars." - Oscar Wilde