ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Enterprise open source Toolkit

Linux developers prioritise security

Published: 03 Feb 2005 09:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Developers of the Linux kernel created a security mailing list this week to air future vulnerability information regarding the open source operating system's core code.

The list, which the developers plan to announce soon, is an answer to some open source developers' concerns that reports of security flaws were getting lost in the large amount of email messages sent to the kernel team.

"We aim to keep the process as open as possible," said Chris Wright, Linux kernel developer at Open Source Development Labs. "Sometimes, people prefer to report security vulnerabilities in private to make sure the implications are understood and the fix is known before going public. This is in place to facilitate that and keep things from falling through the cracks."

The mailing list will be the contact point for security issues in the kernel and is the result of several weeks of mulling over how accessible to the public the list should be.

Disclosure of security issues has been a heated debate, both for the kernel development group and in the software community at large. While some argue that publicly revealing a software bug in popular software hurts the security of the Internet, others point out that flaws are generally caused by poor development procedures and a lack of focus on security.

The current practice in the commercial software industry is to request that security researchers who find flaws wait until the software company has created a fix and is ready to release the update before divulging details of the vulnerability. However, the creator of the original Linux kernel, Linus Torvalds, condemned taking that approach in Linux development.

"I personally prefer as much openness as possible and feel pretty comfortable with it," he said in a recent email interview with ZDNet UK sister site CNET News.com. "It requires -- but thus also encourages -- a certain level of security to be in place, and people who feel nervous about that level of security at any point in time thus tend to argue against openness."

Compared with commercial software makers and even the Linux vendor security list, Vendor-sec, the Linux kernel development team appears to be adopting that goal of open disclosure.

In a draft statement regarding the list, the kernel team stated: "We prefer to fully disclose the bug as soon as possible. It is reasonable to delay disclosure when the bug or the fix is not yet fully understood, the solution is not well-tested or for vendor coordination. However, we expect these delays to be short -- measurable in days, not weeks or months."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
60 out of 124 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Featured Talkback

In association with Intel
Its the applications and device drivers that run on windows that cement its dominance. How many people would fork out hundreds of pounds for Vista if Linux ran all the software and kit they wanted to use.

By: pround

Read full story:
Windows' dominance stifles demand for Linux

Discussions

roger andre roger andre

Unwittingly Working For Google.

Sunday 12 October 2008, 10:49 PM

6 comments
roger andre roger andre

Skype Spying Debacle

Sunday 12 October 2008, 6:43 PM

1 comment
bagalibaba bagalibaba

CHEAP SELL, TOP QUALITY

Sunday 12 October 2008, 4:12 PM

1 post