<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>CTOvision - Latest Comments in The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.disqus.com/</link><description>CTOvision.com is for the enterprise CTO </description><atom:link href="https://ctovision.disqus.com/the_number_one_reason_to_move_to_open_source_security/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Mon, 27 Apr 2009 14:40:48 -0000</lastBuildDate><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-21538874</link><description>&lt;p&gt;Thanks much John, I appreciate the comments and links.  I just jumped over to your &lt;a href="http://ICHnet.org" rel="nofollow noopener" target="_blank" title="ICHnet.org"&gt;ICHnet.org&lt;/a&gt; site and had a quick look around.  I'll be spending more time on there shortly and would recommend others do the same.&lt;/p&gt;&lt;p&gt;Cheers, &lt;br&gt;Bob&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob Gourley</dc:creator><pubDate>Mon, 27 Apr 2009 14:40:48 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-21538873</link><description>&lt;p&gt;All points are valid.  What is missing from the discussion is the process by which government maps requirements to available solutions whether COTS or Open Source.    Neither source of innovation is leveraged effectively as we government has lost its ability to track, assess and acquire any innovative solutions due to the disastrous outsources of these functions to defense contractors who lack access to this market or the incentives to promote existing solutions over custom development.&lt;/p&gt;&lt;p&gt;This issue was barely touched in the just released Defense Science Board report on IT Acquisition &lt;a href="http://www.acq.osd.mil/dsb/reports/2009-04-IT_Acquisition.pdf" rel="nofollow noopener" target="_blank" title="http://www.acq.osd.mil/dsb/reports/2009-04-IT_Acquisition.pdf"&gt;http://www.acq.osd.mil/dsb/...&lt;/a&gt;.   The good news is that the new IT-Acquisition Advisory Council (IT-AAC), headed up by former Army PEO EIS Kevin Carroll and former AF Secretary Mike Wynne.  Preliminary findings are posted at &lt;a href="http://www.ICHnet.org" rel="nofollow noopener" target="_blank" title="www.ICHnet.org"&gt;www.ICHnet.org&lt;/a&gt;. Recommendations for process improvement can be sent to Kevin.Carroll@ICHnet.org.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Weiler</dc:creator><pubDate>Mon, 27 Apr 2009 13:36:46 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-731045504</link><description>&lt;p&gt;Thanks much John, I appreciate the comments and links.  I just jumped over to your &lt;a href="http://ICHnet.org" rel="nofollow noopener" target="_blank" title="ICHnet.org"&gt;ICHnet.org&lt;/a&gt; site and had a quick look around.  I&amp;amp;#039ll be spending more time on there shortly and would recommend others do the same.&lt;/p&gt;&lt;p&gt;Cheers,&lt;br&gt;Bob&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob Gourley</dc:creator><pubDate>Mon, 27 Apr 2009 11:40:48 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-373949273</link><description>&lt;p&gt;Thanks much John, I appreciate the comments and links.  I just jumped over to your &lt;a href="http://ICHnet.org" rel="nofollow noopener" target="_blank" title="ICHnet.org"&gt;ICHnet.org&lt;/a&gt; site and had a quick look around.  I&amp;amp;#039ll be spending more time on there shortly and would recommend others do the same.&lt;/p&gt;&lt;p&gt;Cheers,  &lt;br&gt;Bob&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob Gourley</dc:creator><pubDate>Mon, 27 Apr 2009 11:40:48 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-731045500</link><description>&lt;p&gt;All points are valid.  What is missing from the discussion is the process by which government maps requirements to available solutions whether COTS or Open Source.    Neither source of innovation is leveraged effectively as we government has lost its ability to track, assess and acquire any innovative solutions due to the disastrous outsources of these functions to defense contractors who lack access to this market or the incentives to promote existing solutions over custom development.&lt;/p&gt;&lt;p&gt;This issue was barely touched in the just released Defense Science Board report on IT Acquisition &lt;a href="http://www.acq.osd.mil/dsb/reports/2009-04-IT_Acquisition.pdf" rel="nofollow noopener" target="_blank" title="http://www.acq.osd.mil/dsb/reports/2009-04-IT_Acquisition.pdf"&gt;http://www.acq.osd.mil/dsb/reports/2009-04-IT_Acq...&lt;/a&gt;.   The good news is that the new IT-Acquisition Advisory Council (IT-AAC), headed up by former Army PEO EIS Kevin Carroll and former AF Secretary Mike Wynne.  Preliminary findings are posted at &lt;a href="http://www.ICHnet.org" rel="nofollow noopener" target="_blank" title="http://www.ICHnet.org"&gt;www.ICHnet.org&lt;/a&gt;. Recommendations for process improvement can be sent to Kevin.Carroll@ICHnet.org.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Weiler</dc:creator><pubDate>Mon, 27 Apr 2009 10:36:46 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-373949272</link><description>&lt;p&gt;All points are valid.  What is missing from the discussion is the process by which government maps requirements to available solutions whether COTS or Open Source.    Neither source of innovation is leveraged effectively as we government has lost its ability to track, assess and acquire any innovative solutions due to the disastrous outsources of these functions to defense contractors who lack access to this market or the incentives to promote existing solutions over custom development.&lt;/p&gt;&lt;p&gt;This issue was barely touched in the just released Defense Science Board report on IT Acquisition &lt;a href="http://www.acq.osd.mil/dsb/reports/2009-04-IT_Acquisition.pdf" rel="nofollow noopener" target="_blank" title="http://www.acq.osd.mil/dsb/reports/2009-04-IT_Acquisition.pdf"&gt;http://www.acq.osd.mil/dsb/reports/2009-04-IT_Acq...&lt;/a&gt;.   The good news is that the new IT-Acquisition Advisory Council (IT-AAC), headed up by former Army PEO EIS Kevin Carroll and former AF Secretary Mike Wynne.  Preliminary findings are posted at &lt;a href="http://www.ICHnet.org" rel="nofollow noopener" target="_blank" title="http://www.ICHnet.org"&gt;www.ICHnet.org&lt;/a&gt;. Recommendations for process improvement can be sent to Kevin.Carroll@ICHnet.org.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Weiler</dc:creator><pubDate>Mon, 27 Apr 2009 10:36:46 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-21538872</link><description>&lt;p&gt;Joemaz- Thanks for the input. I think I agree with most of that, and maybe I could have written that to sound less binary.  I think in most cases enterprises want commercially supported open source.  I think it is just human nature that IT program managers would like to be able to use any software before paying for services so being able to use open source software for free while starting up is attractive, but fielding something across the enterprise is best done with commercially supported open source.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sun, 19 Apr 2009 04:55:25 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-21538871</link><description>&lt;p&gt;Bob- Thanks for the note.  I've heard that argument quite a bit, but frequently it seems to be made by folks from proprietary companies.  Anyway, I have to admit this factor is at play.  The more that open source is used the more people will try to attack it.  But I really believe that software that is designed to be more secure is more secure, and there are quite a bit of ways to prove that. I would, however, like to argue with the person that told you most major public and private institutions do not use open source products.  The fact that the person said that proves to me he or she is not an expert.  I think the majority of them use open source. Don't all organizations use BIND? How else would they be able to use networks if they don't use that?  I probably shouldn't be holding that up as an exemplar of security, but it does what it is supposed to very well and now, thanks to the open source community, has great DNSSec features that all should turn on.   And when it comes to OS's and traditional applications, I think Gartner said something like 85% use open source.  I think your expert associate should do some more digging.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sun, 19 Apr 2009 04:49:17 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-21538870</link><description>&lt;p&gt;Bob, I believe your view on open software is far to binary.   The seeming appeal of Open Software is that it is free  ----  until you need to integrate it, support it , or train to it.  But I'll just skip over the infra-structure advantages of commercial open source software like MS and Oracle sell in terms of configuration management critical to enterprise operations and go right to security.  I get that openness leads to better security over time as the user community will find and fix defects (though if you want Linux patches immediately you might want to consider Oracle Unbreakable Linux), but what about the adversary who develops maleware from the open environment and keeps in the "war reserve mode (warm)" until it wants an effect?  To summarize I am not are arguing agains open source SW as you define it, but suggesting there are places and uses where open source makes sense and others (far more in the IC) were commerically open SW is the better approach.&lt;br&gt;joemaz&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph M. Mazzafro</dc:creator><pubDate>Sun, 19 Apr 2009 02:00:44 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-731045499</link><description>&lt;p&gt;Joemaz- Thanks for the input. I think I agree with most of that, and maybe I could have written that to sound less binary.  I think in most cases enterprises want commercially supported open source.  I think it is just human nature that IT program managers would like to be able to use any software before paying for services so being able to use open source software for free while starting up is attractive, but fielding something across the enterprise is best done with commercially supported open source.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sun, 19 Apr 2009 01:55:25 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-373949270</link><description>&lt;p&gt;Joemaz- Thanks for the input. I think I agree with most of that, and maybe I could have written that to sound less binary.  I think in most cases enterprises want commercially supported open source.  I think it is just human nature that IT program managers would like to be able to use any software before paying for services so being able to use open source software for free while starting up is attractive, but fielding something across the enterprise is best done with commercially supported open source.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sun, 19 Apr 2009 01:55:25 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-731045498</link><description>&lt;p&gt;Bob- Thanks for the note.  I&amp;amp;#039ve heard that argument quite a bit, but frequently it seems to be made by folks from proprietary companies.  Anyway, I have to admit this factor is at play.  The more that open source is used the more people will try to attack it.  But I really believe that software that is designed to be more secure is more secure, and there are quite a bit of ways to prove that. I would, however, like to argue with the person that told you most major public and private institutions do not use open source products.  The fact that the person said that proves to me he or she is not an expert.  I think the majority of them use open source. Don&amp;amp;#039t all organizations use BIND? How else would they be able to use networks if they don&amp;amp;#039t use that?  I probably shouldn&amp;amp;#039t be holding that up as an exemplar of security, but it does what it is supposed to very well and now, thanks to the open source community, has great DNSSec features that all should turn on.   And when it comes to OS&amp;amp;#039s and traditional applications, I think Gartner said something like 85% use open source.  I think your expert associate should do some more digging.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sun, 19 Apr 2009 01:49:17 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-373949269</link><description>&lt;p&gt;Bob- Thanks for the note.  I&amp;amp;#039ve heard that argument quite a bit, but frequently it seems to be made by folks from proprietary companies.  Anyway, I have to admit this factor is at play.  The more that open source is used the more people will try to attack it.  But I really believe that software that is designed to be more secure is more secure, and there are quite a bit of ways to prove that. I would, however, like to argue with the person that told you most major public and private institutions do not use open source products.  The fact that the person said that proves to me he or she is not an expert.  I think the majority of them use open source. Don&amp;amp;#039t all organizations use BIND? How else would they be able to use networks if they don&amp;amp;#039t use that?  I probably shouldn&amp;amp;#039t be holding that up as an exemplar of security, but it does what it is supposed to very well and now, thanks to the open source community, has great DNSSec features that all should turn on.   And when it comes to OS&amp;amp;#039s and traditional applications, I think Gartner said something like 85% use open source.  I think your expert associate should do some more digging.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sun, 19 Apr 2009 01:49:17 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-373949267</link><description>&lt;p&gt;Bob, I believe your view on open software is far to binary.   The seeming appeal of Open Software is that it is free  ----  until you need to integrate it, support it , or train to it.  But I&amp;amp;#039ll just skip over the infra-structure advantages of commercial open source software like MS and Oracle sell in terms of configuration management critical to enterprise operations and go right to security.  I get that openness leads to better security over time as the user community will find and fix defects (though if you want Linux patches immediately you might want to consider Oracle Unbreakable Linux), but what about the adversary who develops maleware from the open environment and keeps in the "war reserve mode (warm)" until it wants an effect?  To summarize I am not are arguing agains open source SW as you define it, but suggesting there are places and uses where open source makes sense and others (far more in the IC) were commerically open SW is the better approach. &lt;br&gt;joemaz&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph M. Mazzafro</dc:creator><pubDate>Sat, 18 Apr 2009 23:00:44 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-21538869</link><description>&lt;p&gt;Well, not so fast.  While I agree with most of what Vass says, it's also the case that open source stuff becomes a target the more that it's used.  Just look at what's happening with Firefox these days.  Many of the point releases are because of security issues, and not simply to add functionality.  An expert within the Intelligence Community told me, "most major public and private institutions do NOT use open source products (including the Intel. Community) and thus, they do not receive the security scrutiny that the commercial products get."&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sat, 18 Apr 2009 19:54:27 -0000</pubDate></item><item><title>Re: The Number One Reason To Move To Open Source: Security</title><link>http://ctovision.com/2009/04/the-number-one-reason-to-move-to-open-source-security/#comment-731045496</link><description>&lt;p&gt;Well, not so fast.  While I agree with most of what Vass says, it&amp;amp;#039s also the case that open source stuff becomes a target the more that it&amp;amp;#039s used.  Just look at what&amp;amp;#039s happening with Firefox these days.  Many of the point releases are because of security issues, and not simply to add functionality.  An expert within the Intelligence Community told me, "most major public and private institutions do NOT use open source products (including the Intel. Community) and thus, they do not receive the security scrutiny that the commercial products get."&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sat, 18 Apr 2009 16:54:27 -0000</pubDate></item></channel></rss>