Globe Computer Systems Limited
 
 
Home
Hardware
Software
Accessories
Consumables
About us
Contact us
 
 
 

Opensource security moves to next step

Open-source security moves to next step

Eleven projects are certified as secure in government-backed initiative led by source code analysis specialist Coverity.

Source code analysis expert Coverity has found and helped fix more than 7,500 security flaws in open-source software, and published a list of the 11 open-source projects working fastest to sort them out.

The work is part of a U.S. government-backed project to harden open-source code.

"We applaud the developers responsible for the 11 open-source projects that have advanced to the second rung of code security and quality," said David Maxwell, open-source strategist for Coverity.

The Open Source Hardening Project, sponsored by the U.S. Department of Homeland Security, uses Coverity's Scan, which grades projects on a "ladder" according to their progress at fixing and preventing flaws.

Eleven projects have been awarded the newly announced status of Rung 2, including those known as Amanda, NTP, OpenPAM, OpenVPN, Overdose, Perl, PHP, Postfix, Python, Samba, and TCL. According to Coverity, this new development means users will be able to "select these open-source applications with even greater confidence."

Several other projects are expected to advance to Rung 2 over the next few months. The Open Source Hardening Project began in January 2006 and was expanded early in 2007 to cover a list of 150 projects.

Coverity uses static source-code analysis to spot errors in code, such as open brackets. Projects on Rung 2 will move on to use the company's "satisfiability" techniques, which use a bit-accurate representation of a software system, translating every relevant software operation into Boolean values (true and false) and Boolean operators (such as and, not, or).

Coverity claims this type of analysis is a first in commercial programming and is able to spot hundreds more bugs than the tools available on Rung 1.

Although the project is clearly improving the security of open-source software, some have expressed concern that coverage of its results may produce bad publicity in the form of headlines about security flaws in open-source software.

Peter Judge of ZDNet UK reported from London.

 
Stay safe while using Microsoft Office 2003...
The business end of Cisco...
SQL Server 2008 delayed until third quarter...
Opensource security moves to next step...
Apple announces ultrathin laptop, movie rentals...
Hitachi to form hard drive company with Toshiba, Fujitsu?...
Clear unwanted apps from Windows' Startup list...
New multigraphics chip designs from AMD and Nvidia...
Windows XP SP3 To Include Vista Elements, Researchers Say...
Windows XP SP3 preview shows up to 10% speed improvements...
New software...
Western Digital bills its new RE2GP drive as the "greenest" ever...
Western Digital joins the 320GB mobile drive party...
A day on the Surface: a handson look at Microsoft's new computing platform...
Windows gets a 'MiniMe'...
openSUSE 10.3 released...
Internet2 hits 100Gbps, could scale 10x beyond that...
Novell credits Microsoft for soaring Linux sales...
AMD unveils triplecore desktop chip...
Three cheers for portable Thunderbird...
IBM's Computing Breakthrough Promises Chips The Size Of Dust...
Google sets tongues wagging with Talk...
Toshiba announces trio of new mobile hard drive families...
Intel launches "Extreme" mobile core, gives sneak peek on 45nm designs...
eSoft ThreatWall 450 Web Security Gateway ...
Storm worm attacks have always come in the form of massive email campaigns, but researchers have spotted the attackers creating malicious Web sites....
Lenovo to offer Linux on laptops...
Google, Microsoft, Yahoo and others are developing nextgeneration technologies that make automate and personalize information search....
Intel Aims Both High And Low...
AMD details plans for mobile PC chip platform...

Terms and Conditions | © 2007 Globe Computer Systems Ltd.