Re: CRIME GNU Help

From: Crispin Cowan (crispin@private)
Date: Mon Jul 14 2003 - 21:46:33 PDT

  • Next message: Andrew Plato: "RE: CRIME GNU Help"

    Kuo, Jimmy wrote:
    
    >Is there any study that shows that using Open Source results in savings?
    >
    It is an issue with a lot of moneyed axes to grind, and therefore you 
    can find studies supporting whatever position you desire to take. You 
    might as well ask for studies supporting the (non)existance of God; the 
    results will be about as passionate, and about as useful.
    
    Caveat: I have strong views on both the open source and God issues, but 
    to keep it topical to the CRIME list, y'all are just going to have to 
    guess/google what those views might be :)
    
    More topical to the CRIME list is my favorite open source quality study:
    
        Miller, B.P., Fredrikson, L., and So, B., An Empirical Study of the
        Reliability of UNIX Utilities. Communications of the ACM 33, 12
        (December 1990), 32-44. Also appears in German translation as Fatale
        Fehlerträchtigkeit: Eine Eimpirische Studie zur Zuverlassigkeit von
        UNIX-Utilties, iX (March 1991).
        ftp://grilled.cs.wisc.edu/technical_papers/fuzz.pdf.
    
    The interesting result was that GNU utilities failed *far* less often 
    (and thus were less vulnerable) than comparable commercial UNIX utilities.
    
    This 1991 study was followed up in 2000 *Fuzz* Revisited: A 
    Re-examination of the Reliability of UNIX *...*  
    <http://opensource.asti.dost.gov.ph/advocacy/fuzz-revisited.pdf>  The 
    follow-on study found a similar result: an over-all very poor 
    vulnerability rate, but that the GNU and Linux programs were 
    significantly more secure than the commercial programs.
    
    So on the broad TCO question, who knows. But on the narrower software 
    security question, open source consistently wins.
    
    Crispin
    
    -- 
    Crispin Cowan, Ph.D.           http://immunix.com/~crispin/
    Chief Scientist, Immunix       http://immunix.com
                http://www.immunix.com/shop/
    



    This archive was generated by hypermail 2b30 : Mon Jul 14 2003 - 22:09:52 PDT