Defense Dept. committee has open-source leaning
As Government Computer News reports, the U.S Department of Defense has singled out open source in the National Defense Authorization Act for Fiscal Year 2009 (H.R. 5658). The gist? The Defense Department sees open source as a way to cut costs and boost security, and it wants more of it.
While open source has attained legislative approbation in Latin America and elsewhere, this is first time I can remember seeing it in a Congressional bill.
Currently, the open-source language is focused on aerial vehicles, but it's instructive all the same:
The committee is concerned by the rising costs and decreasing security associated with software development for information technology systems. These rising costs are linked to the increasing complexity of software, which has also resulted in increasing numbers of system vulnerabilities that might be exploited by malicious hackers and potential adversaries. The committee encourages the department to rely more broadly on (open-source software) and establish it as a standard for intra-department software development.
If you're an open-source project lead or commercial vendor, this language is a step in the right direction. If you're a proprietary-software vendor, well, perhaps you side with the Business Software Alliance (funded by Microsoft and others), which has been lobbying hard against the bill.
I don't personally feel that open source needs to be legislated to be adopted. Indeed, I'm aware of widespread adoption of open source within the Department of Defense already, commercial and otherwise. Perhaps this legislative action will accelerate adoption further, but again, I'm not sure that open source needs any assistance here. The cream has a way of rising to the top, and open source keeps rising.
Perhaps someone needs to introduce a bill to handicap open source's rise in order to help out those starving proprietary vendors? :-)
Matt Asay brings a decade of in-the-trenches open-source business and legal experience to The Open Road, with an emphasis on emerging open-source business strategies and opportunities. Matt is vice president of business development at Alfresco, a company that develops open-source software for content management. He is a member of the CNET Blog Network and is not an employee of CNET. Disclosure. You can follow Matt on Twitter @mjasay. 



http://secunia.com/advisories/search/?search=red+hat
And that's just red hat. Give me a break. Most software is insecure whether it is open source or proprietary.
All software have flaws. That doesn't make them all equally flawed.
Last year there were less vulnerabilities in Outlook than in Mozilla's mail reader (Thunderbird.) I mean, come on, how can a product be *less* secure than Outlook, right? Just proves Open Source means nothing when it comes to security.
As a security architect I'm sorry to say that most software developers today (whether open or closed source) have no idea about basic application security, and much less about broader security issues.
Ironically today Microsoft is one of the very few companies that "get" security, mandating a Secure SDLC. More companies and open source projects need to adopt processes such as security code reviews, security testing, employee rotation, third-party audits, etc.
The vast majority of OSS flaws get fixed before they are exploited. Most proprietary(notably MS) don't.
Proprietary code is usually more secure, and it doesn't take a computer programmer to know that. I agree with Miark01 on one thing: they shouldn't be worrying about security, but accountability.
- by January 22, 2009 2:32 PM PST
- > "I don't personally feel that open source needs to be legislated to be adopted"
- Reply to this comment
-
(8 Comments)It does need help, because right now, open source as well as "free" software is prohibited by policy of most Services within the DOD.
However, I don't think they need to make it mandatory as much as just get rid the policies prohibiting it (as well as about 90% of the rest of the DOD's IT policies, which are mostly outdated and asinine.)