| |
| | Open Source Versus Closed Source Security |
 | | Although you can take an open source project, compare it against a closed source project, and say that one is more secure than the other based on some number of observations or measurements, this determination will probably be based on factors other than the nature of the project's open or closed source code. |
 | | Secure design, source code auditing, quality developers, design process, and other factors, all play into the security of a project, and none of these are directly related to a project being open or closed source. |
 | | On the other hand, I've seen some vulnerabilities in open source software that are so obscure (some of the Sendmail prescan() vulnerabilities come to mind), that you wonder if it would be feasible to discover a similar issue in a closed source project at all. |
| www.securityfocus.com /columnists/269 (1101 words) |
|