Secure Coding mailing list archives

Re: Open source fertile ground for foul play?


From: "Kenneth R. van Wyk" <Ken () KRvW com>
Date: Sun, 15 Feb 2004 16:13:22 +0000


Crispin Cowan wrote:

Trojans have been inserted into both open source and closed source 
programs. Discovery time for the open source programs was on the order 
of days (TCP Wrappers, the Linux Kernel), while discovery time in the 
closed source applications (e.g. InterBase 
<http://news.com.com/2100-1001-250896.html?legacy=cnet>) was years. At 
that, it was only discovered six months after Borland opensourced the 
code.


Great examples, thanks. 

Another rebuttal to Jones's article can be found on O'Reilly Net at 
http://www.oreillynet.com/pub/wlg/4436, FYI.


Cheers,

Ken van Wyk






Current thread: