4 Jul 2008 01:42
Open Source Security and the Mozilla Metrics Program
Hi all A common argument about FOSS is "open source is more/less/elephant secure than closed source". Conflated with this is the "there are more security holes/bugs in Firefox than IE/Safari/etc" discussion. To those of us who have spent time getting to the bottom of both discussions there haven't been a lot of data and statistics with any real science associated with them. Indeed a lot of the metrics used by the security researchers and media are outright unreliable and occasionally subject to some bias. The Mozilla project has initiated a metrics program/project to track bugs and develop a baseline model for secure development. You can read about the project at http://blog.mozilla.com/security/2008/07/02/mozilla-security-metrics-project/. The project is advised by Rich Mogull (http://securosis.com/about/) - a well respected ex-Gartner security boffin. The site and the associated collateral is well worth a read and the results look to be interesting. Regards James Turnbull --(Continue reading)
RSS Feed