Security Basics mailing list archives

Re: Why open source software is more secure


From: Alexander Klimov <alserkli () inbox ru>
Date: Mon, 12 May 2008 17:44:01 +0300 (IDT)

It is not clear what is "more secure". For example, if we define
that software is secure if it has no exploitable bugs, then it
is either secure or it is not.

I suspect that there is only a small number of non-trivial
secure software and all of them are happened to be OSS -- this
is not because open process magically makes software secure, but
because these specimens were written by security zealots.

Why most of software is not secure? It is very simple to answer:
because nobody really cares (even if they claim they do,
"normal" people do not behave accordingly). Most of the users do
not care and thus commercial software is not secure (by the way,
according to EULA liability is usually limited to the price you
pay to get the software); most of the developers are not
security zealots and thus OSS software is not secure.

-- 
Regards,
ASK


Current thread: