Version: 2008

Comments on: 11 open-source projects certified as secure

Under contract with the Department of Homeland Security, Coverity seeks to establish a new security baseline for open-source applications.

Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
Potentially secure
by Astinsan January 8, 2008 8:56 AM PST
Most of these items have the potential of being secure. A improper setting Postfix, php and perl can be disastrous.

I know you were really talking about the source code though. Mature projects are usually pretty good.
Reply to this comment
Good point!
by kingttx January 8, 2008 3:22 PM PST
That is a good point. Although I was going to use this for a good-hearted jab at some anti-PHP folks on our LUG list, I just can't bring myself to twist up the logic like that. Like you say, bad settings can screw up secure source.
Sec Code != Sec App
by the osd guy January 9, 2008 3:20 PM PST
What about design flaws?
What about info disclosures?
What about denial of service issues?
What about unxepected parse failures?
What about ...

There is more to secure applications than making sure ur buffers are correctly sized. Static analysis cant fully guarentee that and fuzz testing can only verify the product is as reliable as the fuzzer's randomizor logic.
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement