Why open source is more secure than proprietary systems
Photo by Kelly Sikkema

Why open source is more secure than proprietary systems

With the creation of the Government Digital Service (GDS) four years ago, open source software was thrust into the public sector spotlight in the UK. The government chief technology officer at that time, Liam Maxwell, co-authored the report ‘Better for Less’ which set out the policies that gave government IT management the remit to pursue the advantages of two specific technologies –cloud and open source software.

The report identified how these two technologies can drive cost and efficiency savings at the same time as meeting the government’s requirements for digital transformation. However, while cloud has undoubtedly become a resounding success in the public sector, open source hasn’t gained the same traction, with certain misconceptions acting as key barriers to adoption.

One of the major barriers to public sector organisations considering open source software is the concern over levels of security. Because open source software is built by communities of developers, with the source code publicly available, there’s a common misconception that it is inherently less secure and therefore more risky than closed source options. Misformed media coverage does little to allay fears either, as organisations are quick to attribute data breaches to the nature of open source software as opposed to (as is more often the case) poor operational and security practices. (A good example of this could be seen with 2014’s Heartbleed bug.)

In reality, open source presents no more of a security risk than a closed solution. On the contrary, the so-called ‘thousand eyes’ argument maintains that, with so many individuals working with the source code of these projects, potential vulnerabilities and design flaws are uncovered and resolved much faster than with programs built on the proprietary code. As noted in a recent article published by Gadgette.com,

“while it’s true that open source means anyone can look at the code, that also means that you’re getting a lot more eyes and expertise than private source code ever will. The benefit of this is that everyone using your code is invested in ensuring it’s safe and secure”.

In a previous blog post we discussed how achieving a secure open source infrastructure and application environment requires much the same approach as with commercial software. The same principles apply, with only the implementation details differing. The most prominent difference is the transparency that exists with open source software.

Originally published on the Ixis blog.

要查看或添加评论,请登录

Mike Carter ????的更多文章

  • Drupal 7 Transition Planning

    Drupal 7 Transition Planning

    The Drupal 7 content management system (CMS), which was originally scheduled to reach the end of life in November 2021,…

  • Drupal vs. WordPress: Exploring the Advantages

    Drupal vs. WordPress: Exploring the Advantages

    When it comes to content management systems (CMS), two names stand out: Drupal and WordPress. Both have their…

  • The Drupal 7 End-of-Life Countdown

    The Drupal 7 End-of-Life Countdown

    The Drupal 7 news was a relief for editors, website administrators, IT Managers and all involved in website maintenance…

  • What To Expect When Taking Your Drupal Acquia Exams

    What To Expect When Taking Your Drupal Acquia Exams

    With a string of successful Acquia certifications amongst the development and support team at Ixis, including several…

  • Is it time for Drupal 10 yet?

    Is it time for Drupal 10 yet?

    People are only just thinking about moving from Drupal 8 to Drupal 9 (a small and less time-consuming exercise…

  • Get Your Campaigns to Market Earlier with Drupal 9

    Get Your Campaigns to Market Earlier with Drupal 9

    As marketers and content editors, one of your biggest frustrations is not getting content out quick enough, right?…

    1 条评论
  • When is Drupal 9 Coming out?

    When is Drupal 9 Coming out?

    Many production websites out there are still happily running on Drupal 7, whilst newer ones have been started on Drupal…

  • Can Drupal be used for mobile?apps?

    Can Drupal be used for mobile?apps?

    Mobile apps. Why are they still such a popular request when we’re well served by web browsers and responsive themes…

    2 条评论
  • Going global: multiple websites, singular strategy

    Going global: multiple websites, singular strategy

    Exploring the challenges for worldwide organisations in maintaining consistency across the web. Online presence has…

  • How to choose a managed service provider for your Drupal website

    How to choose a managed service provider for your Drupal website

    You’ve chosen to build the site on Drupal for a long list of powerful reasons – you love its flexibility and…

社区洞察

其他会员也浏览了