Hello Ash,

I understand your scepticism.  There are a lot of companies in the world who
are eager to steal your information and exploit your computer and surfing
habits.  Believe me, it's a daily occurrence in my world - I'm an IT
administrator and consultant focusing on system security.

The best reason to use Open Source Software (OSS), in my opinion is due to
integrity.  The work of people who write OSS in general is, by definition,
freely available for inspection and discussion.  You can take the code that
makes up these products and peruse it for any form of devious act or attempt
to elicit information.  Try doing that with any proprietary product (and I
do mean any product).

The sheer volume of people doing coding working on OSS products means that
if there are vulnerabilities or dirty deeds within the product, they are
sure to be found sooner or later.  And when they are found, there is a
direct trail of evidence back to the person who created and implemented the
code.  The recriminations of such an act would be swift and decisive
throughout the OSS community.

My best examples of the benefit of OSS is this.  I have a magazine in my
possession with an article there-in which states the writer had submitted a
"remote execution of code" vulnerability directly to Microsoft regarding
their Windows XP OS a full 8 months before the article was published.  The
article further detailed how the author had no response to repeated requests
for update on the solution for the entire time.  The Author finally decided
to publish the article in an attempt to force Microsoft's hand to fix this
glaring issue.  I watched this proceeding intently.  It took another 10
months for Microsoft to fix the problem.  This is not a unique issue with
Microsoft's proprietary programs or any other proprietary program.  I was a
software tester for a time as well.  In my experience, this kind of "blind
eye" to vulnerabilities that are inconvenient is an unfortunate standard
practise with proprietary software.  On the other hand, most of the
vulnerabilities in my OSS software and Operating Systems are fixed within
days, if not hours of them becoming public.

>From my point of view as a security consultant, that is why you should use
OSS.  The pride, integrity, and possibly criminal liability of the coders is
at stake when they put their effort into OSS products.

Regards,
Andrew Vliet

Reply via email to