UK Conservatives Slammed Over Open Source Stance
Golygydd Max writes "The UK government has been criticised by the opposition Conservative (Tory) party for its lack of support for open-source software. Now, according to Techworld, a security company that has examined the Tory plans has come out against the use of open source software, citing the number of security problems inherent in the software. This is a sensitive issue for the UK government, still smarting from the loss of 7m family records from HM Revenue and Customs in 2007. What makes this criticism interesting is that this is an attack on the policies of what will certainly be the next British government — it's unusual for a party to be criticised like this before it comes to office. It's an indication of how IT is going to be a battleground in the future general election."
> it's unusual for a party to be criticised like this before it comes to office
Clearly timothy is unfamiliar with UK politics.
A link to the company's study: http://www.fortify.com/servlet/download/user/OpenSource_Security_WP_V5.pdf
While they raise a couple interesting points, my first impression is that they broadly generalize from a small sample set. Specifically, they only look at about 10 Java projects (including Tomcat, Hibernate, and JBoss), and proceed to conclude that the open source community is unresponsive to security threats. Conspicuously absent are any Linux distributions (let alone any *BSD... they have obviously never heard of OpenBSD), OpenOffice, or any tools likely to make it into desktop use for the UK government.
Oh, and the solution to all this apparently is to rely on their company's security auditing services to make sure that your company doesn't have "hidden security holes".... Riiiight....
'Every story, if continued long enough, ends in death.' --Ernest Hemingway
Fortify Software is not exactly a neutral party for conducting studies of the fitness of FOSS for enterprise software use. Half its Board of Directors have ties to enterprise software and service corporations like PeopleSoft, Sybase, Oracle, and Microsoft. I think I might get a second opinion.
err... less of the FUD please.
First of all, why on earth are you assuming a multi million dollar project is going to be using software supported by some guy called bob?
Rewrite that as using open source software supported by Canonical, Novell, Red Hat or Sun, and all of a sudden Open Source is competing on much more equal footing, and your first argument goes out of the window. After all, you could just have easily bought some closed source software off 'Bob' for your multi-million pound project.
What that, you don't trust Bob's software, and would rather buy from a big company? Funny that.
And do you *really* think Microsoft's EULA disclaimers don't apply to large organizations? Bill Gates didn't get Microsoft to where they are today by the company being dumb. I've seen their volume license terms, and if anything they're *more* restrictive, not less. By all means, quote me a paragraph or two from one of these 'favourible' EULA's that show me I'm wrong, but somehow I don't think that's going to happen.