Of security and open source software

July 2013 Information Security

Muggie van Staden. “To say open source is less or more secure than anything else would be to miss the point.”
Muggie van Staden. “To say open source is less or more secure than anything else would be to miss the point.”

When it comes to open source software, the topic of security is always hotly debated. It seems that in addition to it being free, open source software is inherently less secure than what is available through its proprietary counterpart. At least that is what the cynics would have you believe.

But just like the Free Fallacy (patent pending), the security one is not any less incorrect. The fact remains that there are security risks associated to all software code. Just like any piece of hardware will eventually fail, so too does any piece of software inherently have a security risk. These risks can either be used for nefarious purposes or are as rudimentary as typos in programming syntax. However, irrespective of the platform used, companies need to mitigate their risk.

More secure, less secure?

To say open source is less or more secure than anything else would be to miss the point. All software has bugs and security issues are everywhere. How the platforms deal with these security issues are what sets them apart.

With proprietary software you have a small pool of developers that have access to the source code. The theory is that this closed system is inherently more secure because you are limiting the amount of people who can see inside the code and identify holes. Yet, as is evident through a well-known organisation that frequently releases patches on Tuesdays, this still does not mean the system is completely secure.

The very nature of open source means that any person has access to its inner workings. Certainly, there are many flavours and customisations to it but that is a result of the greater number of people who are developing solutions for open source software. Security holes become a bit of a numbers game here. Given the amount of open source developers and communities in the world, the chances of them picking up bugs in code are significantly higher than the closed pool of developers with proprietary systems.

Backdoor in

Think about it. If the developer of a proprietary system builds a backdoor in it that leaves an organisation open for attack, who would be able to check it? Only the limited number of developers that have access to that source code can monitor it. And once a hack has been discovered, it is often too late for the company in question as the damage would have already been done.

On the other side of the coin, you have open source developers who constantly monitoring code for malicious backdoors, bugs, or even simple typos in syntax. This community becomes a significant extension to the internal development team of a company and provide support around the clock, 365 days a year.

Greater good

Open source is pushing people to work together to make solutions better. It is one of the ultimate communities of interest. The developers work together for the greater good of the software and share bug fixes freely and quickly with each other. This fast turnaround time can hardly be matched in proprietary developers due to the sheer difference in numbers.

And while everybody loves a good underdog story of one against many, when it comes to security I know I prefer to have the many on my side working together to ensure my system stays as up to date as possible, while reducing the amount of security bugs.

For more information contact Obsidian Systems, +27 (0)11 794 8055, www.obsidian.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Managed security solutions for organisations of all sizes
Information Security News & Events
Cyber attackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...
Troye exposes the Entra ID backup blind spot
Information Security Infrastructure
If you trust Microsoft to protect your identity, think again. Many organisations naively believe that Microsoft’s shared responsibility model covers Microsoft Entra?ID – formerly Azure AD – but it does not.

Read more...
Secure data protection without hardware lock-in
Infrastructure Information Security News & Events
New Veeam Software Appliance empowers IT teams to achieve instant protection with Veeam’s fully preconfigured, software-only appliance, delivering enterprise-ready simplified deployment and operational efficiency, robust cyber resilience.

Read more...
Check Point launches open, vendor-neutral MDR services
Information Security News & Events Products & Solutions
New Check Point MDR 360° and MXDR 360° offerings deliver 24/7 managed continuous threat monitoring protection across endpoints, cloud and network environments with built-in identity threat detection and 160+ integrations across hybrid, multi-vendor environments.

Read more...
Credential theft surges in South Africa
NEC XON Information Security
NEC XON issues a critical cybersecurity warning about the dual threat of massive credential theft and AI-powered cyberattacks sweeping across the region, with an increasing number of incidents and evolving threat tactics.

Read more...
Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.