September 2, 2007 12:46 PM PDT

Open source a natural for anti-virus software?

Consider: a large population of users who can report virii. Many people with the same "itch" (to be free of virii). A subsegment of both communities with the aptitude and interest in killing these virii.

Should be a perfect market for open source, right? Architecture of participation and all that....ClamAV seems to make the argument that it is.

The answer may not be so straightforward, according to Chris Pirillo:

Don't you find it a bit odd that some of these companies sell protective tools that slow our systems down, but also sell products that will allegedly speed our systems up?

What if the leading anti-virus, anti-spyware, anti-malware products were open source rather than commercial in nature?

He then quotes Peter Schwankl who argues (incomprehensibly to my mind) that open source would make virus problems worse, not better, because the virii would become more, well, virulent, whereas the antivirus programs would become too hard to crack....If you're lost as to how open source would create either problem, you're not alone.

We live in a world where there are bad people who want to write virii. We will always live in this world. While we live in this world, I think we're better off taking a community approach to antivirus: a community to report problems and a community to fix problems. That's what open source provides.

Antivirus is a classic example of where open source should thrive. The key to doing so, however, is lowering the barriers to contribution of virus alerts and definitions (and fixes), not raising them.

Recent posts from The Open Road
Travelocity takes flight by standardizing on Red Hat
Making sense of a VMware acquisition of Red Hat
Palm's Treo Pro finds a ever decreasing potential market
Q&A: Red Hat's JBoss business hits overdrive
So you want to comply with the GPL...
Add a Comment (Log in or register) 7 comments (Page 1 of 1)
Open Source is a good solution
by deshpaaa September 2, 2007 4:03 PM PDT
I second you. Open Source approach for a anti-virus should work as a good approach. A more community driven intiative will be a more natural way.
Amit
http://www.amit-deshpande.com/
Reply to this comment
Best Antivirus
by sam_sw17 September 2, 2007 9:23 PM PDT
The Best Antivirus of all is Nod32
viral_b_panchal@yahoo.com
viral_b_panchal@hotmail.com
viral_b_panchal@indiatimes.com
viral_panchal2007@yahoo.com
viral.b.panchal.london@gmail.com
info@viralpanchal.com
Reply to this comment
Not so hot
by fatalflaw September 2, 2007 11:40 PM PDT
First: open source = downloadable source code = too much information for VXers. Second - what if the guy responsible for releasing new signatures has a problem at work or with girlfriend/wife/cat that day? I'm not persuaded that there would be sufficient motivation to see it's covered. So we are exposed. Third - there is an increased risk that a VXer masquerading as a legit contributor could add code for his/her own purposes. Conclusion: I prefer a secretive, financially motivated, paranoid a/v provider.
Reply to this comment
Clearly the message....
by PACSferret September 3, 2007 12:18 AM PDT
Hasn't got through. Another quote from Peter Schwankl:
"
an open source community wouldn?t have the dedicated resources that a company does to produce consistent, worthwhile, and stable-running AV software
"
Haven't we heard that line before?
Reply to this comment
Flawed Argument
by royrusso September 3, 2007 6:18 AM PDT
@fatal

[http://Second - what if the guy responsible for releasing new signatures has a problem at work or with girlfriend/wife/cat that day? I'm not persuaded that there would be sufficient motivation to see it's covered. So we are exposed. Third - there is an increased risk that a VXer masquerading as a legit contributor could add code for his/her own purposes.|http://Second - what if the guy responsible for releasing new signatures has a problem at work or with girlfriend/wife/cat that day? I'm not persuaded that there would be sufficient motivation to see it's covered. So we are exposed. Third - there is an increased risk that a VXer masquerading as a legit contributor could add code for his/her own purposes.]

What if the guy working at a corporate anti-virus vendor has a bad day? Since their code and processes are a black box to us, we'd never know.

The point of OSS is that their are many (sometimes hundreds) of eyeballs looking at code committals. Any deceptive practice by one individual will likely not pass the smell test.
Reply to this comment
Still not so hot
by fatalflaw September 3, 2007 3:23 PM PDT
@Flawed

[http://What if the guy working at a corporate anti-virus vendor has a bad day? Since their code and processes are a black box to us, we'd never know.|http://What if the guy working at a corporate anti-virus vendor has a bad day? Since their code and processes are a black box to us, we'd never know.] First: any top-tier a/v provider will have rotas and plans to cover situations like this, they can afford to, and they can't afford not to, and they didn't become top-tier by screwing that kind of thing up. My argument is not concerned with resources, it's the management of those resources, which IMHO is necessarily too diffuse in an open source community. Second: If an OS a/v vendor's processes are open, that is again giving too much information to VXers, allowing them for example to pick their moment to launch a more effective attack because fred and barbara are away for the weekend.

[http://deceptive practice by one individual will likely not pass the smell test.|http://deceptive practice by one individual will likely not pass the smell test.] Yes ok I accept that.

Still ... it just feels wrong to me to open this stuff up, like saying it's ok to leave your car unlocked because it has an immobiliser.
Reply to this comment
Hot is hot
by royrusso September 3, 2007 4:50 PM PDT
@fatal

[First: any top-tier a/v provider will have rotas and plans to cover situations like this, they can afford to, and they can't afford not to, and they didn't become top-tier by screwing that kind of thing up.]

If they're so awesome, why do we still have an ongoing virus problem, and why are their products becoming infinitely bloated? I can tell you from personal experience, from years of training and consulting in corporate environments... I've dealt with an awful lot of pinhead developers and IT managers at very large corporations. Just because they're "big and successful" doesn't mean they exactly have decent coding practices. (Often, good marketing + inertia wins over good tech).

[Second: If an OS a/v vendor's processes are open, that is again giving too much information to VXers, allowing them for example to pick their moment to launch a more effective attack because fred and barbara are away for the weekend.]

Then why is Linux so much more secure than Windows? (Note: I am a Windows user and not a Linux shill)

[http://Still ... it just feels wrong to me to open this stuff up, like saying it's ok to leave your car unlocked because it has an immobiliser.|http://Still ... it just feels wrong to me to open this stuff up, like saying it's ok to leave your car unlocked because it has an immobiliser.]

A better analogy, I'd argue, is saying your car is much safer with a neighborhood watch program than with the local police watching it. I'd bet on the neighbors, as they have a vested interest in keeping the neighborhood clean.
Reply to this comment
Powered by Jive Software
advertisement
  • About The Open Road

  • Matt Asay brings a decade of in-the-trenches open-source business and legal experience to the Open Road, with an emphasis on emerging open-source business strategies and opportunities. Matt is general manager of the Americas division and vice president of business development at Alfresco, a company that develops open-source software for content management. He is a member of the CNET Blog Network and is not an employee of CNET. Disclosure.

Add this feed to your online news reader
Google
Yahoo
MSN

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

advertisement
On The Insider: Miley to Celebrate 16 with Mickey
Advanced
search
Advanced
search
Visit other CBS Interactive sites