March 21, 2002

Putting too much trust in Open Source

dave b writes "Interesting piece on ZDNet UK about the need to review source code systematically."
From the article: "The open-source community has long prided itself that the 'many eyes' approach will catch flaws in the code - but some are worried that the checking
isn't being done

In the past three months, the open-source community has been given a wake-up call.

While Microsoft has concentrated on reviewing its flagship Windows source code as part of a new focus on security, Internet watchdogs have released
the details of three widespread flaws in open-source applications usually shipped with the Linux operating system."

Link: ZDNet article on Open Source code review and security

