October 13, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Dennis Byron
Open Source Software Up the Stack
Dennis Byron’s blog on open source software: A longtime market research analyst follows what “the movement” means to business integration—in applications, infrastructure, as services, as architecture and as functionality.

« Podcast: Talking to... Bob Bickel of Ringside, open source social computing startup | Main | More research on why the open source market is disappearing »

July 22, 2008
How does the open source LAMP stack up to Fortify’s methodology?

Fortify Software has a good PR agency. Just as the open source software (OSS) community gathers for OSCON the week of July 21 and LinuxWorld on August 4, the security-software-and-services company has released a damning report on OSS security. It’s a slow news period so all the online (and I assume printed) publications lead with the news. The firestorm on the blogosphere is predictable. Every story and posting mentions Fortify. As I said, Fortify has a good PR agency.

It’s hard to argue against the methods that Fortify recommends open source communities adopt. Patrick Lightbody explained some similar solutions in his article here on ebizQ in September 2007. We will talk about them as well in our August 20, 2008 OSS Roundtable, with Jim Zemlin of the Linux Foundation, Ross Altman of Sun, and Dominic Sartorio of the Open Solutions Alliance.

But the survey paints OSS with an awful broad brush based on a few projects out of tens of thousands. Thinking of Jim, Ross and Dominic led me to ask myself (and Fortify—answer to follow if provided) why the projects tested were picked and why some of the more popular projects—embodied in the term, the LAMP stack—were not. The Fortify document says the reason is that the projects selected were implemented in Java and Java is the most popular enterprise-level development language.

So maybe this is really a study about Java security issues. But JavaOne happened in June. Like I said, Fortify has a good PR agency.

Posted by dennisb in OSS Development |Digg This|Add to del.icio.us

Trackback Pings

TrackBack URL for this entry:
http://www.ebizq.net/mt/mt-tb.cgi/3591

Comments

Posted by: Dennis at July 24, 2008 08:46 AM | Permalink

Post a comment




Remember Me?

(you may use HTML tags for style)

We ask that you type your code (displayed below) in the text box.This code is an image that cannot be read by a machine. It prevents automated programs from submitting comments.


Code:



Most Recent ebizQ Blog Entries
ADVERTISEMENT
Subscribe to this blog’s feed
My Work Elsewhere
Blog Roll
This Work
Accountability:The opinions expressed in this blog are solely representative of the blog's author, and not of ebizQ

Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
Enterprise Service Bus: The case for 'e'SBs
Date: Oct 16, 2008
Time: 14:00 PM ET
(18:00 GMT)

REGISTER TODAY!
BPM for Insurance: Are You Staying Competitive?
Date: Oct 28, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map

Live Chat