Although OpenSource is gaining in popularity, I guess this article serves as a caveat -
"DHS finds flaws in 180 open source software projects"
http://www.betanews.com/article/DHS_finds_flaws_in_180_open_source_software_projects/1200003935
Although OpenSource is gaining in popularity, I guess this article serves as a caveat -
"DHS finds flaws in 180 open source software projects"
http://www.betanews.com/article/DHS_finds_flaws_in_180_open_source_software_projects/1200003935
Interesting story.
Thanks for sharing.
Glad I don't run linux....
FUD, you mean? or at least tending that way.
Y'all just waking up to that? jeeze, I've seen bits of that in my email alerts for a while now.
try
http://www.news.com/8301-10789_3-9843682-57.html
January 8, 2008 7:10 AM PST
11 open-source projects certified as secure
"Coverity, which creates automated source-code analysis tools,"
machine code testing source code, I wonder how imaginative it is. No matter, moving along..
"San Francisco-based Coverity, working in collaboration with Stanford University and under a contract from the Department of Homeland Security, is analyzing source code to certify that open-source projects written in C, C++, and Java are secure. Coverity has not disclosed the amount of the DHS contract."
this almost has as many scare-me points as a tell-everyone-the-sky-is-falling spam.
please notice that Coverity can *only check software it has source code for*, which sorta means it's only *able* to find flaws in open source! And it found that few since 2006? wow. Considering the number of open source projects that aren't even half-baked yet...
good luck getting flaws found in Microsoft OS's or Office or IE code, Apple stuff, Sun Java, or hp notebook helper apps, most any of the giveaways here, Quickbooks, 3com router code, most antivirus and firewall code, uhh....
well, I think you can add your own examples.
glad you don't run Linux? *how* many M$ security patches come out in a year? Sure, you can trust 'em.
comments?
P.S. I wonder if these folks are gonna figure out why the 'electronic border fence' code ain't working? Think they'll get to vet the biometric database source or the "Real ID" security?
http://www.latimes.com/news/nationworld/nation/la-na-realid12jan12,1,2275630.story
Real ID is postponed for 5 years
WASHINGTON -- The Bush administration hit the brakes Friday on a controversial law requiring Americans to carry tamper-proof driver's licenses, delaying its final implementation by five years, until 2017.
A number of states have balked at the law, objecting to it largely over cost and privacy concerns. But under the administration's new edict, states that continue to fight compliance with the law face a penalty: Their residents will be forbidden from using driver's licenses to board airplanes or enter federal buildings as of May 11 of this year.
DHS would seem to need some kind of distraction...
You must log in to post.