Slashdot Mirror


UK Conservatives Slammed Over Open Source Stance

Golygydd Max writes "The UK government has been criticised by the opposition Conservative (Tory) party for its lack of support for open-source software. Now, according to Techworld, a security company that has examined the Tory plans has come out against the use of open source software, citing the number of security problems inherent in the software. This is a sensitive issue for the UK government, still smarting from the loss of 7m family records from HM Revenue and Customs in 2007. What makes this criticism interesting is that this is an attack on the policies of what will certainly be the next British government — it's unusual for a party to be criticised like this before it comes to office. It's an indication of how IT is going to be a battleground in the future general election."

75 of 281 comments (clear)

  1. Hmmmm.... by Anonymous Coward · · Score: 5, Interesting

    > it's unusual for a party to be criticised like this before it comes to office

    Clearly timothy is unfamiliar with UK politics.

    1. Re:Hmmmm.... by Xest · · Score: 5, Interesting

      > It's an indication of how IT is going to be a battleground in the future general election.

      Indeed Mr AC, you're right.

      The UK doesn't have battleground issues in politics like the US, the UK is plagued with football team style voting, most of Yorkshire will vote Labour, most of London will vote Conservatives, the rest of the country will vote one or the other depending with a few Lib Dem pockets (Sheffield, Cambridge) littered in between.

      It doesn't matter what their policies are, people don't care about that, the people in Yorkshire (disclaimer: that's where I live) will as always go on about how Thatcher ate their babies in the 70s/80s and so vote Labour, the people in rich areas will go on about how Labour caused a big recession in the 70s and vote Conservatives and the few parts of the country capable of intelligent, dynamic thought will actually vote for the party that actually fits their political hopes best.

      People here rarely seem to vote on the merit of a party's politics or agenda but instead based on whatever x party did 20 to 40 years ago and those that weren't around then still vote on what party x did 20 to 40 years ago because their parents have whined to them all their lives about how hard party x made life for them all that time ago.

      I think part the problem is that in the UK we get no political education whatsoever, kids grow up without a clue as to what left wing and right wing are, what the different flavours of conservatism for example are, what liberalism and libertarian are and where our parties sit in these areas. We're never taught the importance of voting, or how our vote can effect the outcome of an election, hell most people don't even know what the house of Lords is, they think parliament is one big single chamber of sheer boredom. I find this quite shocking, because whilst I can see the merit in music class, religious education, art and so on I really do think politics is perhaps more important, yet oddly entirely neglected. I could quite happy have lived without the hour a week spent in music class, or the 2 to 3 hours spent on English literature (although language is of course important), I understand some people do want to know this, but it should've been optional whereas I'm not convinced politics should be. We already have history lessons to teach us about our and the world's past so I simply cannot see what is more important about analyzing Wordsworth's Daffodil poem, searching for things that Wordsworth probably never really actually intended us to decide was there as a hidden meaning in the first place to merit a complete national ignorance of how our country is run and how our elected powers work.

      I wonder if part the reason there's no will to change this is because both Labour and the Conservatives know that whilst no one has a clue about politics then one or the other is guaranteed to get in via the current football team voting mentality and as such there will be no threat to power being taken away from either of them- when one has had a few years, the other is bound to get in, rinse and repeat.

      I think this is the fundamental difference between British and American politics at least, whilst you do get Republicans who always vote Republican and Democrats that always vote Democrat at least you had the likes of Colin Powell endorsing the Democrats because he realised despite them being the opposition, they had the better policies at the end of the day.

    2. Re:Hmmmm.... by jabithew · · Score: 3, Informative

      most of London will vote Conservatives

      Er, is this a different London to this one? Or this one?

      The South East and South tend to vote Tory. London is pretty mixed.

      --
      All intents and purposes. Not intensive purposes.
    3. Re:Hmmmm.... by sqldr · · Score: 5, Funny

      Clearly timothy is unfamiliar with UK politics.

      Could be worse.. half of america thinks Obama is the antichrist.

      --
      I wrote my first program at the age of six, and I still can't work out how this website works.
    4. Re:Hmmmm.... by Xest · · Score: 2, Insightful

      I'd like to think so, I just hope the media most people have been consuming isn't the Daily Mail! ;)

    5. Re:Hmmmm.... by Anonymous+Brave+Guy · · Score: 4, Insightful

      The problem we have in the UK isn't just football team mentality, it's the bizarre way our "representatives" are elected. Well, the way some of them are elected, anyway. It is disturbing that the so-called "upper house" was, until recently, a group of people who hold office only because a distant ancestor was rich or because they hold a high office in a particular religion (yes, really). These days, they are almost all appointed, though I think the 92 hereditary peers who survived Labour's initial reforms are still there, and the Lords conveniently overturned a strong vote in the Commons for a 100% appointed upper house, arguing for 100% appointed (and therefore their own jobs) instead. In any case, members of the upper house still retain office regardless of trivia like criminal convictions and accepting bribes to "do the right thing" with certain laws. Perhaps we should just go back to the fifteenth century and let the church run the show? At least 5% of the population are practising Christians, which gives them more moral authority than our upper house today!

      Meanwhile, the first-past-the-post voting system ensures that the Commons alternates between the two dominant parties with a huge majority each, even though that is in no way representative of the strength of support the party in power actually carries among the population at the time. Don't even get me started on European government, which is a fantastic excuse for political parties to push through legislation their electorate don't want because "Europe told me to, mummy!", while conveniently overlooking the way that Europe only considered the issue because the unelected representatives of the country asked them to.

      In any case, none of this helps me: I have fairly moderate, well-considered, and (I think) consistent political views, yet none of the parties with even a chance of getting a seat in Parliament represents my views. Labour are a complete waste of space, even if you're one of the "hard-working families" they were formed to look out for, and the current administration has no democratic mandate anyway. The Tories don't know what their policies are, though they keep trying to sound really convinced about what they believe this week, and they're certainly still on the draconian side when it comes to state power and even worse when it comes to allowing businesses to become the most powerful players in the game. (They're in favour of copyright term extension too, BTW, despite an overwhelming majority — for once the over-used term is justified — of respondents to the government's Gowers Review criticising such a move.) Cameron all but washed his hands of one of the few guys he had with the guts to stand up for what he believed in. The Lib Dems seem to think an arbitrarily high level of tax on people who earn more than average is "fair", probably because very few such people will ever vote for them anyway, and their policies on things like the environment and transport are the kind of thing you can only say if you're never going to achieve office because they conveniently overlook trivia like keeping the lights on and getting people to work. The one guy they had with any sort of clue was leader only briefly, and then stepped aside for another guy with all the depth of a two-dimensional object. Then, in England at least, you're into minor parties like the Greens (whose one issue got stolen by everyone else), the BNP (who do a disturbingly good job of sounding reasonable on some topics, until you realise what they really mean), the UKIP (who also might sound plausible on those sorts of issues, but have no credibility after pulling stunts like letting Kilroy-Silk's ego run the show for a while), and so on.

      So who does that leave for me, and a heavy majority of friends I've talked to on political subjects, who believe in things like individual rights and freedoms, in exchange for individual responsibility; strong laws, but due process to enforce them; small, weak government; low taxes; healthy European relationships for tr

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    6. Re:Hmmmm.... by Xest · · Score: 3, Insightful

      I know exactly where your coming from and I think it's another reason that politics should be taught in school, I think if it was then we would have a much better variety of political parties to represent our views.

      Also I think the Lords problem would be solved if we could solve the commons problem, the commons has the power to eventually remove control from the Lords and so I think the Lords issue would be resolved as a side effect of fixing the commons.

      Personally, I'll probably vote Lib dems next election because I think although they don't fully represent my views, they come the closest. David Davis is about the only guy in the Conservatives I trust and as you mention, he's not even part of the core team anymore.

      Regarding the Lib Dems though, I think some of the things they say that sound impossible are actually quite reasonable, one strikes me in particular as I can confirm it's validity. The Lib Dems have mentioned that they would make savings in public sector of around £20bn if I recall, I've encountered many people say that's a joke, there's nothing to save but having worked in public sector for a few years I can confirm that it is quite a valid claim to make and in fact, I think they're underestimating the amount that could be saved. I worked in local government and saw potential for millions to be saved in a single local government department alone, extrapolated across all public sector departments, across the whole country I think their claim is quite valid. My real concern is that Labour and to a lesser extent, the Conservatives seem quite ignorant about how much really could be saved.

    7. Re:Hmmmm.... by commodore64_love · · Score: 3, Insightful

      This is why ye should pull thy kids out of government schools (whose sole purpose is to keep the voters ignorant & easily malleable), and send them to a private school or homeschool.

      BACK to topic:

      Speaking as an outsider, I don't understand how Open source software can be secure. If the virus makers have access to the source, doesn't that make it easier to examine and locate flaws in the program?

      --
      "I disapprove of what you say, but I will defend to the death your right to say it." - historian Evelyn Beatrice Hall
    8. Re:Hmmmm.... by Xest · · Score: 4, Insightful

      Yes, but it also makes it easier for those who use the software to locate and fix the flaws first ;)

      To give a better explanation of why OSS is more secure though, think about this scenario. You have a web server on the wide open internet serving an important web page for your business or institution and any downtime will lose you thousands, maybe millions of pounds of profit (think how much Amazon would lose if it's site goes down for example). If you run an open source web server and an exploit is uncovered by security researchers that allows an attacker to take over your web server then you can edit the source code to fix it immediately, or at least put a quick fix in place to block the attack and have very little, perhaps even no downtime.

      If however you rely on a propriatary vendor, say Microsoft, to fix it and it takes them 2 weeks to release a patch, what do you do in the meantime? Do you keep your web server up and risk having your web server hijacked or do you take it down and lose millions in business?

      This is just an example, you can mitigate the problem by having a firewall block attacks but this only works to a degree. I wasn't too sure about why OSS myself was more secure for a while, but it's one of those things that when you look into the reasoning behind such comments you'll see realise that yes, they're right, OSS really is fundamentally a more secure concept.

      Of course, the other thing to realise is that binaries are themselves fairly trivial to interpret for people who have a strong computer science background such that it's not even particularly a massively difficult task to spot exploits in closed source software. It is however often much harder to fix faults in closed source software in the same way.

    9. Re:Hmmmm.... by mdwh2 · · Score: 2, Interesting

      I agree that FPTP is a bad system, but:

      Don't even get me started on European government, which is a fantastic excuse for political parties to push through legislation their electorate don't want because "Europe told me to, mummy!", while conveniently overlooking the way that Europe only considered the issue because the unelected representatives of the country asked them to.

      Do you have examples? I'd argue that the UK Government has no trouble pushing through legislation (it has a majority, and it can even force legislation through the Lords with the Parliament Act), without resorting to an excuse. And on the contrary, it's European laws which are the only thing preventing some of the authoritarian laws that the Government has been forcing through (e.g., the recent ruling based on European law that taking DNA and fingerprints of anyone arrested, even if not charged, or found not guilty, is unlawful). It's the European Convention on Human Rights that gives us our only chance of "individual rights and freedoms" that you mention later on.

      The Lib Dems seem to think an arbitrarily high level of tax on people who earn more than average is "fair"

      Do you have a reference for this policy? Whilst traditionally they said they would increase income tax, now they say they will reduce it ( http://news.bbc.co.uk/2/hi/uk_news/politics/7615630.stm ) (incidentally, this change came with the "guy with all the depth of a two-dimensional object"). Given that Labour now plan an even higher rate of tax for high earners ( http://news.bbc.co.uk/2/hi/uk_news/politics/7745070.stm ), I'm not sure off-hand that Lib Dem policies are worse here?

      So who does that leave for me, and a heavy majority of friends I've talked to on political subjects, who believe in things like individual rights and freedoms, in exchange for individual responsibility; strong laws, but due process to enforce them; small, weak government; low taxes; healthy European relationships for trade, but not all the other stuff that doesn't work at the current time because the nations are too unequal to start with; basically liberal economics, but with controls imposed to prevent companies that have grown large from becoming too powerful either in a certain market or compared to their employees; a basic social safety net, but otherwise letting people earn their own rewards; and other similar policies?

      Remember that no one can be expected to match your views 100% - unless you stand yourself. But Lib Dems fit a lot of those I would say, especially with their changed position on tax.

    10. Re:Hmmmm.... by He+who+knows · · Score: 3, Interesting

      We do now get political education called "Citizen ship". we have to spend an hour a day on it and it is useless. It is basically propaganda for labor saying how good they are with new laws. Nobody pays any attention to it. The people who can understand what it is about realise how awful it is while the people it is aimed at don't care about it. I feel sorry for people who now have to do it for GCSE. It is worse than media studies or music tech.

    11. Re:Hmmmm.... by nyvalbanat · · Score: 2, Insightful

      ... and they voted for the candidate who was demonstrating leadership skills by building up resentment between different parts of the country

      --
      Ubuntu on primary work desktop since Dapper Drake (2006).
    12. Re:Hmmmm.... by TheRaven64 · · Score: 2, Insightful

      Or they are appointed and they will vote for whoever appointed them or who has the most money

      This isn't what happens at the moment because the appointed individuals are still there for life. It doesn't matter to them if they vote against the person who appointed them because they can't be removed. This is quite a good system in general. If you pick people who have already achieved most of what they wanted to in life then sitting in the Lords is a nice retirement job for them. They'll only show up for issues they care (and, hopefully, know about) and can vote based on their experience and conscience rather than any party or constituency obligations.

      When I watched the Commons and Lords debate, back around '99, it was right in the middle of the removal of the hereditary principle. I spent around an hour watching the debates in both houses and came away with the distinct impression that, if I had to choose between them, I'd vote to abolish the House of Commons.

      --
      I am TheRaven on Soylent News
    13. Re:Hmmmm.... by jonbryce · · Score: 2, Insightful

      Yes it does. That's why it is more secure. If there is anything wrong with the program, it is picked up much more quickly, and something is done about it.

  2. The British like Americans seem to be incompetent by bogaboga · · Score: 5, Insightful

    ...Now, according to Techworld, a security company that has examined the Tory plans has come out against the use of open source software, citing the number of security problems inherent in the software...

    I think we need to be objective here. Software both closed source and open source is created by human beings.

    By nature, these human beings make mistakes.

    The question then becomes: Which model of software development fixes security issues faster? We should collect statistics here and convince these Britons that OSS is still the best model around.

    We should also remind the skeptics about OSS, that more than 80% of internet traffic is handled by OSS systems, so if OSS were that insecure, it would show...fast.

  3. What a credible argument against OSS by Walkingshark · · Score: 5, Insightful

    "Our own research, however, has concluded that open source software exposes users to significant and unnecessary business risk, as the security is often overlooked, making users more vulnerable to security breaches," said Fortify vice president, Richard Kirk.

    US outfit Fortify Software has come up with research to prove it.

    Uh, wow, a US company that sells software doesn't want the British government to switch to open source software? What a radical position to take! Of course, it couldn't have anything to do with the fact that its hard to price gouge a rich government for security software if they're not running propriatary crap. I'm sure if they had their way the Brits would all be running Vista and MS Office.

    --
    The world you experience is only a close approximation of reality.
    1. Re:What a credible argument against OSS by SanityInAnarchy · · Score: 3, Insightful

      Completely shoddy, backwards arguments, too:

      any flaws on commercial applications tend to get patched a lot faster than on open source, as the vendors producing the software have a lot more to lose than an open source programmer

      This ignores the "many eyes" factor, and the additional effect that anyone who finds a security vulnerability can also patch it, and can inform people of the patch at the same time as the vulnerability. Contrast this to proprietary software, where anyone who does find a breach will also find that the best they can do is report it to the vendor and hope for the best -- and when some of them take many months to be patched, it may be worthwhile for them to start exploiting it, if for no other reason than to get Microsoft to take them seriously.

      All of those have been argued to death... Let's assume I'm completely wrong. There's still the fact that there are many corporations which support open source. If an IBM, or a RedHat, or a Canonical ships an insecure product, they have every bit as much to lose as a proprietary vendor -- often moreso, as they tend to have quite a lot more competition.

      All of which has very little to do with the supposed counterargument:

      We need to move in the direction of what are known as 'open standards' - in effect, creating a common language for government IT. This technical change is crucial because it allows different types of software and systems to work side by side in government.

      Microsoft aside, there is plenty of proprietary software that not only supports open standards, but actually revels in them. Unless the argument about security implied that there's an inherent insecurity in ODF itself, I don't see what the relevance is.

      However, this article unfortunately presents it as an argument of security against hot new stuff. I don't think anyone is urging the government to become less secure.

      --
      Don't thank God, thank a doctor!
  4. Doesn't make sense by Psychotria · · Score: 3, Insightful

    ...it's unusual for a party to be criticised like this before it comes to office.

    How is it unusual? It happens all the time. And anyway, the whole summary doesn't make sense.

    The UK government has been criticised by the opposition Conservative (Tory) party for its lack of support for open-source software.

    And, then:

    a security company that has examined the Tory plans has come out against the use of open source software

    So, the security company agrees with the current government? How is this news?

    1. Re:Doesn't make sense by Walkingshark · · Score: 4, Informative

      Not to mention its an American company with a product to sell, and that product's utility is strongly diminished by using open source software.

      --
      The world you experience is only a close approximation of reality.
  5. An indication? by JPortal · · Score: 5, Insightful

    "It's an indication of how IT is going to be a battleground in the future general election."

    Not really. Politicians will grasp at anything to make sensational claims about their opponents. Doesn't matter if it involves IT, their sex lives or what they eat for breakfast.

    American here, maybe politics are better in the UK. (but I doubt it)

    1. Re:An indication? by Hal_Porter · · Score: 5, Funny

      Doesn't matter if it involves IT, their sex lives or what they eat for breakfast.

      Unfortunately with some MPs it may involve all three.

      --
      echo -e 'global _start\n _start:\n mov eax, 2\n int 80h\n jmp _start' > a.asm; nasm a.asm -f elf; ld a.o -o a;
    2. Re:An indication? by SpringRevolt · · Score: 4, Funny

      An orange, a CAT5 cable and a pair of stockings..?

  6. Re:The British like Americans seem to be incompete by Anonymous Coward · · Score: 5, Informative

    We should collect statistics here and convince these Britons that OSS is still the best model around.

    Yeah, maybe we look here https://opensource.fortify.com/ They scanned 103 projects with a total of 24668646 loc and found a total of 403 error which makes for 1 error in 61212 loc or 4 errors per projects. Not too bad I'd say. Oh, btw of those 403 errors found 383 are already fixed.

  7. Missing step ???? by Galactic+Dominator · · Score: 4, Insightful

    1. Identify greatest long term threat to my industry

    2. Conduct "Research" on threat and publish to increase FUD.

    3. Sell products to "fix" FUD issues.

    4. Profit!

    Subject: No ?????????
    Filter error: Your subject looks too much like ascii art.

    You saw him repressing me, didn't you?

    --
    brandelf -t FreeBSD /brain
    1. Re:Missing step ???? by LazySlacker · · Score: 2, Insightful

      I disagree, OSS is an opportunity to Fortify. The implication is that the Tories didn't include ensuring the security of OSS in their plans. What Fortify should want is

      Gov use OSS
      Gov need security assurance
      Gov purchase Fortify s/w.
      Gov Fortify against the source code - something they can only do with OSS.
      Given that you can't outsource accountability, any org that wants to ensure security of OSS must buy the Fortify product.

  8. Just another way to fight... by D-Cypell · · Score: 5, Insightful

    Politics is about, "We would do things better than you do!", open source software is just an unfortunate, innocent bystander in this process. If Labour were open source advocates, the Tories would be saying exactly what the, presumably Labour funded, security company are saying right now.

    Personally, I think the time has come for another interesting political scandal so they will leave the software industry alone.

    For those of you not familiar with UK politics, it works a bit like this...

    There are 2 main parties, plus a 3rd with a small but meaningful number of seats. Each of the two main parties elect a leader who becomes candidate for PM. Labour are historically the party for the working man, formed out of the unions, however, in recent years they have figured out that the working man is significantly less likely to invite you for a spin on their yacht, so have shifted their position a little.

    The current opposition party, the conservatives (or 'Torys'), usually have MPs that come from the rich and privately educated set, such as the hilarious London mayor Boris Johnson (seriously, look this guy up, he is a laugh a minute). They stand for strong family values, but are actually quite likely to be found having a three-way homosexual romp in a public toilet while their wife is at home taking care of the kids.

    Neither party gives the slightest toss about open source software (at least, not even close to the level that we do here), but they *do* care about scoring some points. If FOSS is the battlegroud-dujour so be it... tomorrow it will be the colour of the sky!

    Incidentally, you have have detected a slight hint of British cynicism in my post, it is pretty common. When Obama got elected I was thinking, "Does this guy have a brother that can come and help us out?", then I found out he has a brother that has recently been charged with drug offenses in Kenya... but to be honest, I am still thinking... 'He'll do!'.

    1. Re:Just another way to fight... by williamhb · · Score: 4, Informative

      Ok, a slightly less blinded-by-the-cynicism round-up.

      Labour used to be dominated by the unions, but then realised this was making them almost unelectable as anybody who isn't in a union really doesn't like other people's unions very much. They've tried to become centrist.

      Conservatives used to be very much for "small government", turning everything free market and cutting taxes as far as possible. They've been realising that times have changed since the 80s and a social conscience is generally seen as a good thing. So, both the main parties have been chasing "the middle ground", or at least marketing themselves that way.

      The Liberal Democrats formed from an amalgam of a breakaway party from Labour (the SDP) and one of the old British political parties (the Liberals). They tend to have a socially progressive set of policies, often highlighting just one or two policies that sound populist or radical (eg, local income taxes) because they struggle to keep their profile up in the media.

      Things are complicated further because while the Lib Dems have far too few seats ever to form a government, they have much more evenly spread support than the two main parties -- so northern seats are often Labour vs Lib Dem battles, while southern seats are often Conservative vs Lib Dem battles, making British politics a very odd fight: it's not a straight fight between Labour and Conservatives, but also a question of which of them can fight the Lib Dems at a local level more convincingly.

      Also, although the Conservatives have a lead in the polls, the original headline is wrong to say that the Conservatives are "certainly going to be the next government", because of the way constituency borders are at the moment. The large lead in the vote could very easily turn into a small loss in numbers of seats, or a "hung parliament" (which in practice would probably mean a Labour minority government, as on economic issues the Lib Dems vote with Labour more often than with the Conservatives)

    2. Re:Just another way to fight... by Carfiend · · Score: 2, Insightful

      I vote Raving Monster Loony since they are the only Party with policies that make any sense.

      --
      Uh, perhaps you can help me? I'm looking for a love-potion aerosol, that I can spray on a certain Penthouse Pet, to obta
    3. Re:Just another way to fight... by bloobloo · · Score: 2, Informative

      What homophobia? He's claiming the tories are hypocrites - there is no value judgement on homosexuality in the post.

    4. Re:Just another way to fight... by Anonymous Coward · · Score: 2, Interesting

      I would beg to differ. I do this because I am one of the people advising, well indeed pushing OS within the Conservative Party, hence the AC moniker.

      While it may used as a political football there is a good reason also for getting FOSS into Govt. It saves money, which is always good, and if we get Govt to use it, we can get schools to use it and hopefully start to reverse the abysmal decline in coding and computer science in our schools. That's my agenda for pushing it anyway - it's something that the country needs in the short term to save money and that will have real and tangible benefits in the long term in developing and furthering a knowledge based economy

  9. Anyone for TenDRA? by Antony+T+Curtis · · Score: 4, Insightful

    The British Government, or at least, branches of it, used to be very open source friendly. Developing software and publishing it with a very permissive license attached to the source code.

    Alas, since the Blair Regime started, that all seemed to come to an end... and the British people had to learn to put up with huge IT spending to private firms, usually affiliated with Fujitsu or Microsoft ... and those public IT projects would famously fall flat on their faces and be quietly shelved.

    Just look at the recent hiccups with the UK Biometrics scheme... 'nuff said.

    --
    No sig. Move along - nothing to see here.
    1. Re:Anyone for TenDRA? by williamhb · · Score: 3, Interesting

      Some branches of the UK Government still do develop software and publish it with very permissive licenses. For example, JISC (the Joint Information Systems Committee) has sponsored a number of projects to produce open source software in higher education. And various other arms of the British Government always have spent huge amounts of money through private firms, often falling flat on their faces. Government projects failing isn't a new invention.

  10. "Sells software"? Microsoft Partner! by rtfa-troll · · Score: 4, Informative

    A simple Google Search shows rather more than just being a vendor of some random proprietary software. Fortify is a Microsoft partner which has indulged in joint product launches with them and this isn't even mentioned in the original article.

    This is yet another example of a Microsoft inspired campaign of lies. This group never changes and they and their software should be automatically excluded from all state contracts for ethical violations.

    --
    =~ s,(.*),<sarcasm>$1</sarcasm>,g if any_point_you_wish();
  11. See to believe.... by qw0ntum · · Score: 4, Interesting

    A link to the company's study: http://www.fortify.com/servlet/download/user/OpenSource_Security_WP_V5.pdf

    While they raise a couple interesting points, my first impression is that they broadly generalize from a small sample set. Specifically, they only look at about 10 Java projects (including Tomcat, Hibernate, and JBoss), and proceed to conclude that the open source community is unresponsive to security threats. Conspicuously absent are any Linux distributions (let alone any *BSD... they have obviously never heard of OpenBSD), OpenOffice, or any tools likely to make it into desktop use for the UK government.

    Oh, and the solution to all this apparently is to rely on their company's security auditing services to make sure that your company doesn't have "hidden security holes".... Riiiight....

    --
    'Every story, if continued long enough, ends in death.' --Ernest Hemingway
    1. Re:See to believe.... by eof · · Score: 4, Interesting

      Yes. Not only was the study out of context with the conclusions TFA reached (It's a study specific to FOSS Java-based projects and deployments, not FOSS in general), but the study itself isn't clear on what its objectives were. It fails to elaborate on methodologies used to conduct the examinations of projects or process, fails to elaborate on any of the security issues found, and fails to offer any comparative analysis with a successful application of the study to other projects, open source or otherwise. It reeks of FUD.

    2. Re:See to believe.... by betterunixthanunix · · Score: 2, Informative

      Perhaps you would be interested in looking up the EAL certifications for RHEL, SLES, and Windows Server 2k3 (hint: all three products are certified at EAL 4). NIST/NSA certifications are the closest thing you can get to a nonpartisan, non-politically driven evaluation of security...

      --
      Palm trees and 8
  12. City of London and the BBC by hughbar · · Score: 2, Insightful

    Actually both the city of London (which would tend to contain Tories, they're often investment bankers) and the BBC (which contains champagne socialists) both use a lot of open source, mainly scripting languages, databases and web servers.

    However, in both cases, anybody 'political' wouldn't actually dirty their hands with 'software' AND software engineers wouldn't dirty their hands with 'politics'.

    As for the 'report' it's basically self-promotion by the company in order to peddle its wares.

    --
    On y va, qui mal y pense!
  13. Re:The British like Americans seem to be incompete by williamhb · · Score: 5, Insightful

    I think we need to be objective here. ... We should collect statistics here and convince these Britons that OSS is still the best model around.

    Because there's nothing more objective than deciding what conclusion you want to convince people of before collecting the statistics! (You don't happen to work for Gartner, do you?)

  14. " will certainly be the next British government " by jools33 · · Score: 4, Insightful

    In case I missed something there are multiple parties in the UK who will contest the next election - there are no certainties. Whilst the Tories may have a strong lead now in the polls anything could happen between now and the election.

  15. Conflict of interest? by eof · · Score: 4, Interesting

    Fortify Software is not exactly a neutral party for conducting studies of the fitness of FOSS for enterprise software use. Half its Board of Directors have ties to enterprise software and service corporations like PeopleSoft, Sybase, Oracle, and Microsoft. I think I might get a second opinion.

    1. Re:Conflict of interest? by Kjella · · Score: 3, Insightful

      I don't think you need a big anti-OSS conspiracy for this one. If you asked them "So if we went with closed source, we wouldn't need your products?" you can damn well bet they'd say you need their product to "enhance" your security then as well. It's just another piece of "If you do this, you need us. If you do that, you really need us. And if you do THAT, you REALLY need us." product placement to sell their own products and make a buck. That the board of a software company is full of people from other software companies is hardly surprising.

      --
      Live today, because you never know what tomorrow brings
    2. Re:Conflict of interest? by eof · · Score: 2, Informative

      Oh, I wouldn't go so far to label it a conspiracy, just an obvious conflict of interest.

      The fact that they themselves sell software that benefits from the results of a study that they themselves conduct just degenerates the whole thing into the realm of the ludicrous.

  16. Re:"Sells software"? Microsoft Partner! by tokabola · · Score: 5, Informative

    The "press release" by Fortify for this claims that Larry Suto performed the test. He has a reputation for faulty, perhaps even fraudulent, testing methods. He also only tested 11 specific Java apps (and Fortify sells "audited" versions of those apps). The tests were performed using Fortify's software, no other testing software was used. So the accuracy of this test relies on the accuracy of Fortify's software, which hasn't been independently tested as far as I can tell. The press release also mentions findings by the Forrester Group, who are well known for a history of spreading inaccurate FUD about non-MS software.

    --
    Open Source for Open Minds
  17. Re:"Sells software"? Microsoft Partner! by romanval · · Score: 4, Informative

    OSS lacks QA - show me a OSS project that government is likely to use that has any quality assurances. the big font stating "use at own risk" is a massive turn off for government and rightly so.

    Um.. Microsoft's EULA basically says the same thing.

  18. Enterprise-level change control by Lord+Bitman · · Score: 3, Interesting

    I've yet to be in an enterprise which uses enterprise-level change control.

    Working for one of the world's largest commercial companies: Closest thing to "source control" was a rigorous automated backup process across network shares.

    Working for a small commercial company which sold commercial data processing tools for some of the world's largest commercial companies, and the U.S. Military, and various parts of the U.S. Government: Closest thing to "source control" was laws requiring our code be held in escrow for every release. We routinely released completely untested versions and claimed that it was a re-build of the same sources. Eventually management was convinced to start using source control after asking if anyone had an old copy of a file lying around and I quickly produced it from my local repository. Just before I left, I brought up the issue of segmentation faults and memory corruption, and was told "we can't avoid signalling if we're given bad inputs".

    Working for possibly the largest I.T. Company in the world, processing data for the U.S. Government: One person in charge of source control. No branching allowed. Occasionally heard complaints from the guru that people were overwriting each-other's changes. Never heard the word "security" mentioned at any point. Found out I could get a root shell and modify anyone else's source code by passing bad parameters to the reporting system.

    --
    -- 'The' Lord and Master Bitman On High, Master Of All
  19. Re:"Sells software"? Microsoft Partner! by Kjella · · Score: 3, Insightful

    As much as you might be right, it doesn't change the fact that it works. It's a little bit like the wikipedia problem - it can cite 100 sources that all use information lifted off wikipedia, it just seems reliable and independently confirmed even though there's really only one source. In this you got one piece of FUD "confirming" another piece of FUD and to the general public it will look like "massive independent confirmation" instead of "whole lot of FUD being passed aorund in their own FUD-circle". A lie doesn't become less of a lie if you keep repeating it, but it does become more credible unfortunately.

    --
    Live today, because you never know what tomorrow brings
  20. Open source bad? by buggy_throwback · · Score: 5, Funny
  21. Re:"Sells software"? Microsoft Partner! by timmarhy · · Score: 3, Insightful
    on your home version yes. a customer as big as the uk government? they have bulk licensing terms that ensure security fixes (provided they stay on the upgrade tread mill of course).

    such security fixes could dry up overnight on a OSS project. that's the whole point i'm trying to get through to people, start thinking like you've got 100 million dollar projects relying on this stuff. who are you going to trust this to, some guy called bob on sourceforge, or a multi billion dollar company with resources to get you out of the shit?

    --
    If you mod me down, I will become more powerful than you can imagine....
  22. Re:"Sells software"? Microsoft Partner! by wrook · · Score: 2, Informative

    OSS lacks QA - show me a OSS project that government is likely to use that has any quality assurances. the big font stating "use at own risk" is a massive turn off for government and rightly so.

    Um.. Microsoft's EULA basically says the same thing.

    Not only that, but with OSS you can actually do a risk assesment by inspecting the source code. In the case of proprietary software that gives no warantee, how can I asses my risk?

    What I find interesting is that in most cases you really want to "use at your own risk", after having assessed that risk properly. Because, if I buy a piece of software from Mario's Super Software company for $100, but it blows up in my face for $10 million.... my $100 refund isn't going to comfort me all that much...

  23. Re:"Sells software"? Microsoft Partner! by pipatron · · Score: 2, Funny

    It's a little bit like the wikipedia problem - it can cite 100 sources that all use information lifted off wikipedia, it just seems reliable and independently confirmed even though there's really only one source.

    citation needed.

    --
    c++; /* this makes c bigger but returns the old value */
  24. Fortify cited there own research by damburger · · Score: 2, Insightful

    Showing that a statistically insignificant number of Java applications failed a test by a proprietary system which nobody is allowed to decompile so they can reproduce the results.

    Hmm. Perhaps I am being a crotchety old science traditionalist, but the definition of the word 'research' seems to have changed of late.

    --
    If we can put a man on the moon, why can't we shoot people for Apollo-related non-sequiturs?
  25. Re:"Sells software"? Microsoft Partner! by IBBoard · · Score: 4, Informative

    Well the US DoD seems to be trusting to OSS with forge.mil. I know the company I work for does a variety of UK government contracts as well and we're using more and more open source (mainly Eclipse and its plugins, Protege and OWL in my area of work).

    Besides, what's the real difference between relying on an OSS project with no license fee for five years then (possibly) having to migrate and learn something new but similar versus being charged year on year for Office 2003 then having to migrate to 2007 and all its new UI and still being charged year on year?

  26. No, not homophobia by ed · · Score: 3, Informative

    Read the guy again

    The Conservatives have usually portrayed themselves as the family of family values, Married, 2.4 kids, stable etc

    But in real life enough Tory MPs were seen to be living a life other than they preached. One even died during a bout of erotic asphyxiation

    So it is Hypocrisy he is against, not same sex relationships

  27. Re:The British like Americans seem to be incompete by supervillainsf · · Score: 5, Informative

    We can also look here http://www.fortify.com/partners/technologyPartners.jsp and note that Microsoft is one of their partners.

  28. Re:"Sells software"? Microsoft Partner! by Anonymous Coward · · Score: 4, Insightful

    I'd trust my own employees with access to the sourcecode, or lacking employees competent in the area, consultants with the same source code access. With the consultants I'd also have the added bonus of being able to replace them, where they not able to fix my problems :)

    You know, you _do_ have to pay for support, FOSS or closed source. But you do get what you pay for. And with FOSS, that includes the ability to switch vendor without switching the software.

  29. Re:"Sells software"? Microsoft Partner! by myxiplx · · Score: 4, Interesting

    err... less of the FUD please.

    First of all, why on earth are you assuming a multi million dollar project is going to be using software supported by some guy called bob?

    Rewrite that as using open source software supported by Canonical, Novell, Red Hat or Sun, and all of a sudden Open Source is competing on much more equal footing, and your first argument goes out of the window. After all, you could just have easily bought some closed source software off 'Bob' for your multi-million pound project.

    What that, you don't trust Bob's software, and would rather buy from a big company? Funny that.

    And do you *really* think Microsoft's EULA disclaimers don't apply to large organizations? Bill Gates didn't get Microsoft to where they are today by the company being dumb. I've seen their volume license terms, and if anything they're *more* restrictive, not less. By all means, quote me a paragraph or two from one of these 'favourible' EULA's that show me I'm wrong, but somehow I don't think that's going to happen.

  30. Re:"Sells software"? Microsoft Partner! by donaldm · · Score: 3, Informative

    like the OSS crowd, i'm sure they merely sourced their data to fit their own agenda.

    Yes like FUD.

    OSS lacks QA - show me a OSS project that government is likely to use that has any quality assurances.

    Really I guess you have not looked at Redhat or Novel support.

    OSS takes control away from the customer as to who supplies their patches

    Now that trolling. If you don't like the software then you can always write your own. Of course if you like the software you can post bug reports or even fix it yourself and if you don't have the expertise you can hire someone to do that. Try doing that with closed source or proprietary software. As for the people who supply patches all you need to do is look at the "Help" or even the source to get the name of the people who are maintaining the package.

    these are merely the security concerns. yes there is the usual stupid argument of being able to see the source code - but here is a clue for you - that's hellish expensive and blows the OSS is cheap myth out of the water.

    Sigh! If you have done a cost benefit analysis then you would clearly see that a "supported" open source operating system is much more cheaper and reliable than a proprietary solution. You honestly don't think that just because you install a Linux distribution that everything is going to work forever, you need an administrator and depending on how much you value your data you will need some level of vendor support which is normally much cheaper than a proprietary solution.

    The grammar Nazi in me states you should always start a sentence with a capital letter as is a stand alone "I". After all that is very basic English.

    --
    There ain't no such thing as proprietary standards only proprietary formats. Standards are by definition open.
  31. Re:"Sells software"? Microsoft Partner! by Andy_R · · Score: 2, Insightful

    If security fixes dry up on OSS, the UK government can just get the source code and pay *anyone* to fix it. How is this better than relying on just one company, especially when that one company is a well-known scofflaw that has incurred the biggest fines in the history of EU law?

    --
    A pizza of radius z and thickness a has a volume of pi z z a
  32. Re:"Sells software"? Microsoft Partner! by cowbutt · · Score: 4, Informative

    I don't think anyone would propose that a government just take a random FOSS project from freshmeat.net and put it into production, least of all with anything resembling sensitive data.

    However, both Red Hat Enterprise Linux and SuSE Linux Enterprise Server have both achieved Common Criteria EAL4+ assurance, making them equivalent to Solaris, Windows Server 2003 and Windows XP in the eyes of the evaluation bodies and therefore suitable for many roles within government IT systems.

  33. This is when OS shines by Roger+W+Moore · · Score: 4, Insightful

    such security fixes could dry up overnight on a OSS project...start thinking like you've got 100 million dollar projects relying on this stuff.

    This situation is PRECISELY when open source shows its strength. Take the massive annual license fee that you would need to pay MS to provide such support and hire your own, competent IT staff to maintain the code you want. First this means that you are creating jobs in the UK rather than paying some foreign company which should be a very important consideration for the UK government especially in the current climate. Secondly you now have your own local experts to provide support, implement the features that you want, provide support etc. etc. This puts you in a far better position than having to ring up MS. You own guys will be familiar with your usage and can give advice based on what they know the code does rather than on black-box trial and error experience. Finally you are contributing any changes and code back to the community helping those people that pay the taxes in the first place. Since this may also encourage other firms to invest in local expertise rather than ship money abroad this can help the local economy.

  34. Comment removed by account_deleted · · Score: 3, Funny

    Comment removed based on user account deletion

  35. Bit of a Yorkshire bias?. by fantomas · · Score: 2, Insightful

    ok I am just having a laugh cos I know you were teasing too on the old north/south divide, we're all southern softies and you're hard as nails with ferrets down your trousers... but most of London doesn't vote Conservative. More like a split between Labour/Lib/Tory.

    I lived in Hackney for ten years and that's hardly a rich place, there's not a lot of love for Thatcher and now Cameron there. Reckon there's probably more Cameron voters in the posh end of Sheffield than in Hackney or Brixton...

    But yeah we probably got the Tories coming, very depressing. It's feeling more and more like the 30s every day, the BNP will probably get a lot of votes in the white working class heartlands as well, I think that's something we've got to worry about, when socialist voters turn national socialist....

    1. Re:Bit of a Yorkshire bias?. by boyko.at.netqos · · Score: 2, Insightful

      I usually just vote for who the Doctor endorses and be done with it!

      Voted for Harriet Jones first term, and against her second term, and against Harold Saxon.

      --
      I used to work for NetQoS. I no longer do, but want to keep the excellent karma attached to this account.
  36. Re:better than usa by Anonymous Coward · · Score: 4, Funny

    Whenever I worry that I'm an overly smug asshole, I look to Slashdot comments and thank CmdrTaco for giving us such a good breeding ground for idiots.

  37. Self-contradictory by ChameleonDave · · Score: 2, Insightful

    Why hasn't this story been fixed? The title says that the Conservatives have been criticised, and the summary says that Labour has been criticised by the Conservatives. You don't even have to be familiar with the facts to see the contradiction.

  38. Don't be so negative by Kupfernigk · · Score: 2, Informative
    Act. Write to your MP, if they are not Cons or Lib Dem then write to the Conservative Party, support their initiative and respond to the attack. Point out that IBM, Sun and other companies have significant OSS products, and that there are votes in getting back some of the UK software industry under UK control, and away from Redmond. A cynical initiative sometimes turns into a bandwagon. Last year David Davis resigned and fought what was considered to be a publicity seeking by-election: this year, civil liberaties are right up the political agenda. If you don't help to get a bandwagon rolling but sit on the sidelines whining about Thatcher, you are part of the problem with politics, not the solution.

    And yes, during the 80s and 90s I helped lobby Parliament on the value of the British electronics and software industries, served on DTI committees, talked to our MP and Euro MP. I didn't say "oh nasty Conservatives, don't get involved." That's pointless.

    --
    From scarped cliff or quarried stone she cries "A thousand types are gone, I care for nothing, no not one."
  39. Re:Next gov't? by Alioth · · Score: 3, Informative

    The Westminster government *is* the British government, regardless of who occupies the Scottish parliament.

  40. Re:Next gov't? by XSpud · · Score: 2, Informative

    To people who don't know about UK politics this post might imply that Scotland is not governed by the British (Westminster) government. Scotland still is, though many powers have been devolved to the Scottish parliament.

    If the Conservatives form the next British government, Scotland will still be affected.

    http://www.parliament.uk/about/how/role/devolved.cfm

  41. Re:"Sells software"? Microsoft Partner! by jonaskoelker · · Score: 2, Insightful

    Who are you going to trust this to, some guy called bob on sourceforge, or a multi billion dollar company with resources to get you out of the shit?

    I'm not going to trust a multi billion dollar company to get me out of shit if its track record clearly shows that it's not going to do what I need of it. If bob@sourceforge fails to be reliable too, with OSS I can at least hire anyone else; with proprietary software I can hire no one else.

    (Deciding whether or not the track record shows that is left as an exercise to the reader.)

  42. Re:"Sells software"? Microsoft Partner! by betterunixthanunix · · Score: 2, Insightful

    "or a multi billion dollar company with resources to get you out of the shit?"

    Oh, you mean like Red Hat? Or maybe Novell? Or any of the other dozens of billion dollar companies that sell open source software/support?

    The thing about Microsoft propaganda is that they always leave out key facts and details.

    --
    Palm trees and 8
  43. For fucks sakes. by jotaeleemeese · · Score: 3, Insightful

    Get involved in the party closer to your heart and change things (it is what I did when I was in my country, a place far more dangerous than the UK for opposition politicians).

    I frankly can't stand all this defeatist whining.

    --
    IANAL but write like a drunk one.
    1. Re:For fucks sakes. by Repossessed · · Score: 2, Insightful

      Get involved in the party closer to your heart and change things

      That's great and all but lets take a look at US, and to a large extent (gleaned from to many UK political blogs) UK, politics.

      To start with, most seats are going anywhere, there are no term limits for most offices, and party line voting means that elections are basically shams for many positions. There is only one national level office available in my state that is available to the party whose rhetoric (if not actions) mostly matches my ideals. It has been held by the same man for 8 years, until he actually loses the seat, I couldn't even run. And he's already selected his cronies, so I can't latch on to him.

      Thats the *good* part of the political scene, on the far end one of our senators has been serving for 38 years, having one reelection a 7th time in a row, partly on the basis that having a senior senator means we get a bigger slice of the pie when the federal tax money is divided up, and partly on the basis that he is the correct party for the state.

      Locally, the scene is even worse, since district lines are redrawn every year in order to ensure that as many incumbents as possible stay in office (this is a true non partisan effort, both parties participate in undermining democracy whenever they can). Ultimately, the only time its possible to move people out of office is when the die or retire, in which case a carefully selected patsy usually runs in their place, almost always this person will have gone to Yale, Harvard, or maybe Cambridge, where they studied brown nosing and selling out. Every now and then someone like Obama shakes things up, in which case they *still* go after the same cronies as the old regime, only now if you went to the University of Chicago, you have a shot as well.

      All of this of course ignores that my sexuality and religion make me not just unelectable, but also ensure the political suicide of any politician known to associate with me.

      TL; DR version: There is nobody for me to attach myself to, and no way for me to seriously run for office.

      --
      Liberte, Egalite, Fraternite (TM)
  44. Re:Unrelated statistics by CopaceticOpus · · Score: 2, Funny

    Don't be silly. The security of a technology company's public website is very important. If they truly believed the conclusions of their report, they would take steps to make sure their site was not hosted by open source software. Even if they don't manage the web server, they could easily request to be moved to a Windows/IIS machine.

  45. Re:"Sells software"? Microsoft Partner! by leoc · · Score: 2, Funny
    --
    STFU about slashdot bias.
  46. The main point is surely...... by mormop · · Score: 2, Insightful

    That this is the best evidence so far that Microsoft's new carey, sharey nice image is basically what many people have assumed it to be, i.e. bullshit.

    The scenario is nothing new. Bring in a friendly company, get them to slate the competition and then brag about how an "independent" analyst has found something meaningful. Similarly, as usual, the people who don't care still won't care, the whole thing will be forgotten and FOSS will continue to gain ground as those who know its true value will continue to use and propagate it.

    The important thing is to remember that we're still dealing with the same selfish, power hungry, lying, money grabbing, unethical, amoral, shower of shites that we were 5 years ago.

    --
    Hmmmmmm..... Deep fried and look like Squirrel.