Holey Linux just got more holey
C|Net | at | by Mike
In the past three months, the open-source community has been given a wake-up call. Internet watchdogs have released the details of three widespread flaws in open-source applications usually shipped with the Linux operating system. The flaws could compromise the security of computers on which the applications are installed, prompting some developers to urge the open-source community to take another look at popular code. But most fear the majority of members won't bother.
"No one is doing auditing," said Crispin Cowan, chief scientist at Linux maker WireX Communications, one of several companies selling a version of the OS with additional security options. Cowan is the founder of Sardonix, a Web site aimed at organizing groups of people who want to review major open-source software. "Reviewing old code is tedious and boring and no one wants to do it," Cowan said.