Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: 5thGenTexan
Unless you are personally reviewing and merging changes, there is a potential security risk.

I find it to be quite the opposite - Closed source software tends to have way more security holes than OSS. BY FAR. Closed source relies upon obfuscation and has significantly less programmers at their disposal. Open source and many eyes naturally results in more elegant code and far quicker discovery of exploitable code. I don't use ANY closed source programs anymore... that I can think of... Other than Windows on some boxes, and the antivirus applications it requires BECAUSE of it's closed source mentality.

And 'merging changes'? Most programs nowadays handle their updates automatically - You may have to hang out on the application's forum for a while to see if there are problems, but other than that, it is much the same as closed source, with the only difference being that you, the end user, have the option of actually SEEING the changes, and can go right to the source code to do so. You don't get to see the crappy code hiding behind closed source - If that gives you some feeling of 'professionalism', let me assure you that is not the case.

19 posted on 11/26/2012 12:05:27 PM PST by roamer_1 (Globalism is just socialism in a business suit.)
[ Post Reply | Private Reply | To 11 | View Replies ]


To: roamer_1
Closed Source versus Open Source does not in and of itself make for better security. If that were the case, the discussions about the need for antivirus solutions on mobile devices would be around iOS, but they are not. They are about Android.

It has more to do with the target's market share than the sourcing model. Hacking Mac OS when it was 9% of the market share wouldn't make news. Hackers went after Windows because that made news. Interestingly, now that Mac OSX is getting to he 30% share, it is coming under attack. In the mobile space, Android is the market leader. So it gets teh attention target on its back.

The difference is that Android's internals are open for analysis. Yes, there is a large, faster moving community that is evolving the code base quicker than a big company minded Microsoft. But there is also opportunity for someone to find adn exploit the hole rather than fix it. This was exactly what happened with the Android game malware that sent your contacts adn personal information to a server in China a year or so ago. And that fast moving dynamic is changing as well under Google, who is becoming the big company minded beast. They will become "the man" to the economic politics driven hacker. And to the attention seeking hacker.

My comment on merging sources was that unless you personally review source changes to both the OS and the apps you use (compiling them all locally), you are placing some implicit trust in the open source community. Nothing more.

It is a matter of where you personally want to place trust and accept risk. Just don't be lulled into believing the open source community is fully trustworthy - remember, many of the Windows hackers are part of the open source community.

30 posted on 11/26/2012 1:37:50 PM PST by 5thGenTexan
[ Post Reply | Private Reply | To 19 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson