SecurityFocus.com: Wide Open Source - Is Open Source really more secure than closed? | Linux Today

SecurityFocus.com: Wide Open Source – Is Open Source really more secure than closed?

Written By
Web Webster
Web Webster
Apr 17, 2000

[ Thanks to LinuxBoy for this link.
]

“If Open Source were the panacea some think it is, then every
security hole described, fixed and announced to the public would
come from people analyzing the source code for security
vulnerabilities, such as the folks at OpenBSD, the Linux Auditing
Project, or the developers or users of the application.”

But there have been plenty of security vulnerabilities in
Open Source Software that were discovered, not by peer review, but
by black hats. Some security holes aren’t discovered by the good
guys until an attacker’s tools are found
on a compromised
site, network traffic captured during an intrusion turns up signs
of the exploit, or knowledge of the bug finally bubbles up from the
underground.”

“Why is this? When the security company Trusted Information
Systems (TIS) began making the source code of their Gauntlet
firewall available to their customers many years ago, they believed
that their clients would check for themselves how secure the
product was. What they found instead was that very few people
outside of TIS ever sent in feedback, bug reports or
vulnerabilities. Nobody, it seems, is reading the source.”

Complete
Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.