Tues June 4th Webcast: Best Practices for Continuous Integration with Cars.com. Click Here To Register.
Welcome | Sign In
TechNewsWorld.com
Discussion

TechNewsWorld Talkback

 
ECT News Community   »   TechNewsWorld Talkback   »   Rob undermines his own opinion.



Rob undermines his own opinion.
Posted by sgt_jake on 2004-02-19 12:59:42
In reply to Rob Enderle
1) "a source-code leak generates a huge amount of discussion about why source code on the Internet is a bad thing."
Actually, the discussion is about why a _source code leak_ is a bad thing, not whether or not source code _on the 'net_ is a bad thing. The danger is in whether or not your trade secrets, methods or code can be stolen or used by competitors as much as it is about your code getting exploited by unscrupulous crackers. For the Open Source community, those 'trade secrets', 'methods' and 'code' are explicitly allowed to be used (although not stolen), so the only danger is having it exploited. This brings us to where your opinion falls flat;
2) "Remember that the open-source community uses the thousands-of-monkeys method to ensure security".
Ignor the inferred insult in this statement and take it at face value, and let us see if it works. You stated "…a small amount of Microsoft source code was leaked to the web", yet less than 24 hours later one of those 'thousands-of-monkeys' found a vunerability. It would seem, Rob, that a single monkey banged his keyboard for a few hours, and helped Microsoft find a mal-formed sentence that creates a vulnerability (I guess Shakespear they are not).
3) "If there is even a chance that someone who has not been properly qualified touched a financial application or the platform on which that application resides, IT will fail the audit."
Really, the entire audit argument is fallacious, but I'll play along - You'll of course fail if someone is not qualified to touch a financial application or platform, because you've failed the physical or network security requirements for the audit - NOT because the person who _wrote_ the application is suspect. Furthermore, a financial audit is not a software audit - the methods may be the same, but the requirements are not.
4) "You had to ensure that no one who wasn't approved at the proper level touched anything that impacted a critical piece of corporate IP or had even a glancing relationship with financial reporting."
Interesting point, but deeply flawed and puts Microsoft in a poor position - if you were a financial services company and ran your application on Windows software, would your audit include checks on everyone who ever had access to the Microsoft campus or servers, whether they be employees or not? Even so, since Microsofts code has been leaked, wouldn't you fail any audit by default for using Microsoft software that has now been 'touched' by people not 'approved at the proper level'? How would this be different from RedHat? IBM? Anyone else using Linux?
5) "I would have had a field day with open-source software, where patches are often received or discussed with outside entities who actually could work for foreign governments or competitors, where collaboration could easily be reinterpreted as collusion, and where the very mention of the thousands of people looking at a product would result in a front-page comment in an unsatisfactory audit."
I'm sure you would, but you'd still be wrong, and biased. Patches are audited by the 'thousand-monkeys' as they come in, even by Americans, and if that patch doesn't have a name on it it will likely be discarded before it's even considered. You could suggest that it might hint at collusion, but since collusion by definition is a "secret agreement between two or more parties for a fraudulent, illegal or deceitful purpose", and Open Source is done in public, that would seem to be a pretty stupid suggestion. How would one 'collude' on a patch if a thousand monkeys were watching?
In short Rob, this was a fine bit of "'coulda' woulda' shoulda'", but your suggestions and conclusions are based entirely on personal bias, not personal experience. And what I find ammusing is that you've entirely avoided the comments made by analysts like yourself, who addressed the leaked code instead of the 'advocacy group' you fingered as having made a monumental blunder by scoffing at that leaked code;
"It's sad that it was released, and it's sad it was written so [badly] from a security standpoint" -- Forrester Research's Director Michael Rasmussen.




 * Topic  Author  Date
Re: Can Open-Source Software Survive an Audit?  Rob Enderle  2004-02-17 21:02:48
Re: Can Open-Source Software Survive an Audit?  beaner  2004-02-24 06:19:24
Re: Can Open-Source Software Survive an Audit?  RobEnderle  2004-02-24 08:20:23
Re: Can Closed-Source Software Survive an Audit? (was Open)  heron  2004-02-22 20:41:15
Re: Can Closed-Source Software Survive an Audit? (was Open)  RobEnderle  2004-02-24 08:06:47
Rob undermines his own opinion.  sgt_jake  2004-02-19 12:59:42
Re: Rob undermines his own opinion.  RobEnderle  2004-02-20 09:55:04
I call hypocracy  bangular  2004-02-24 05:33:38
Re: I call hypocracy  RobEnderle  2004-02-24 08:14:22
Interesting  sgt_jake  2004-04-15 08:14:40
Re: Can Open-Source Software Survive an Audit?  jejones3141  2004-02-19 04:04:20
Re: Can Rob Enderle Survive Reality?  timransom  2004-02-18 20:44:12
Re: Can Open-Source Software Survive an Audit?  ptarra  2004-02-18 14:05:38
Re: Can Open-Source Software Survive an Audit?  beaner  2004-02-18 13:27:35
Playing fast and loose with your terms  shadow255  2004-02-18 11:15:07
Re: Playing fast and loose with your terms  RobEnderle  2004-02-20 09:25:26
Re: Playing fast and loose with your terms  cricketjeff  2004-02-20 10:01:04
Re: Playing fast and loose with your terms  RobEnderle  2004-02-20 11:32:51
Contradictions  JoeBunting  2004-02-24 04:52:15
Re: Contradictions  RobEnderle  2004-02-24 07:52:36
Re: Playing fast and loose with your terms  beaner  2004-02-23 07:23:09
Re: Playing fast and loose with your terms  RobEnderle  2004-02-24 08:27:26
Re: Playing fast and loose with your terms  cricketjeff  2004-02-20 16:11:42
Re: Playing fast and loose with your terms  RobEnderle  2004-02-24 08:48:54
Troll your boat, troll your boat, gently down the streeeeam  bangular  2004-02-18 13:04:46
Re: Troll your boat, troll your boat, gently down the streeeeam  bangular  2004-02-19 02:47:43
Re: Troll your boat, troll your boat, gently down the streeeeam  cricketjeff  2004-02-20 06:11:08
Re: Troll your boat, troll your boat, gently down the streeeeam  bangular  2004-02-19 17:18:27
Re: Troll your boat, troll your boat, gently down the streeeeam  beaner  2004-02-19 09:12:37
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-20 08:53:30
Re: Troll your boat, troll your boat, gently down the streeeeam  beaner  2004-02-23 08:08:52
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-24 08:36:20
Re: Troll your boat, troll your boat, gently down the streeeeam  beaner  2004-02-23 08:00:28
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-24 09:42:54
Re: Troll your boat, troll your boat, gently down the streeeeam  beaner  2004-02-27 07:01:32
Re: Troll your boat, troll your boat, gently down the streeeeam  cricketjeff  2004-02-20 10:07:40
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-20 11:47:05
Re: Troll your boat, troll your boat, gently down the streeeeam  cricketjeff  2004-02-20 14:34:19
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-20 17:07:52
Re: Troll your boat, troll your boat, gently down the streeeeam  bangular  2004-02-23 14:00:50
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-24 09:54:11
Re: Troll your boat, troll your boat, gently down the streeeeam  bangular  2004-02-24 10:40:08
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-24 11:14:21
Re: Troll your boat, troll your boat, gently down the streeeeam  bangular  2004-02-24 13:27:47
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-24 14:10:10
Re: Troll your boat, troll your boat, gently down the streeeeam  cricketjeff  2004-02-21 06:39:38
Re: Troll your boat, troll your boat, gently down the streeeeam  RobEnderle  2004-02-24 09:00:57
Re: Can Open-Source Software Survive an Audit?  jmpnop  2004-02-18 10:19:40
Re: Can Open-Source Software Survive an Audit?  RobEnderle  2004-02-20 07:52:51
Re: Can Open-Source Software Survive an Audit?  pasikoistinen  2004-02-26 01:46:13
Re: Can Open-Source Software Survive an Audit?  ixnayrox  2004-02-17 21:08:56
Re: Can Open-Source Software Survive an Audit?  RobEnderle  2004-02-20 10:30:36
Re: Can Open-Source Software Survive an Audit?  beaner  2004-02-23 07:51:47
Re: Can Open-Source Software Survive an Audit?  RobEnderle  2004-02-24 14:33:19
Re: Can Open-Source Software Survive an Audit?  phfcpa  2004-02-21 07:19:36
Re: Can Open-Source Software Survive an Audit?  RobEnderle  2004-02-24 09:15:42
Re: Can Open-Source Software Survive an Audit?  alfarom  2004-02-24 05:45:42
Re: Can Open-Source Software Survive an Audit?  RobEnderle  2004-02-24 09:27:45
Re: Can Open-Source Software Survive an Audit?  alfarom  2004-02-24 13:47:46
Re: Can Open-Source Software Survive an Audit?  RobEnderle  2004-02-24 15:00:56
Personally, you're wrong...  DarkProximity  2004-02-25 09:46:24
Re: Personally, you're wrong...  Smithy2004  2004-02-25 13:23:05
sorry, I had to leave  DarkProximity  2004-02-26 10:21:45
hehe... let me explain.  DarkProximity  2004-02-26 05:58:42
Jump to:
Your Name: [modify]
* Subject:
Choose Icon:

Submissions containing gratuitous promotions or advertisements
will not be posted. [Message Board and Community Rules]


* Comments:

Notify me by e-mail when someone responds to my post.

Facebook Twitter LinkedIn Google+ RSS
Cloud-Aware Network Management
Read real-time case studies
ManageEngine