The view that open source software (OSS) is more secure than proprietary software is "very true", says Nhlanhla Mabaso, manager of the Open Source Centre at the CSIR`s Meraka Institute. The South African government certainly has accepted the idea that security by obscurity is trumped by the benefits of the "many eyeballs" phenomenon.
Kevin Mitnick, famous for having spent time in jail for cybercrimes, says that he`d rather attack OSS, because he can see the code. This has sparked renewed debate about the matter.
The basic arguments on the issue are summarised well in David A Wheeler`s book, "Secure Programming for Linux and Unix HOWTO". According to Wheeler, the US Department of Homeland Security`s security expert, Bruce Schneier, says smart engineers should "demand open source code for anything related to security", not only because more people get to spot and fix vulnerabilities, but because the public availability of the source enforces the discipline on programmers to write clear code that adheres to standards.
The Floss move has positive security implications. After all, it is safer to be free than to be a slave.
Nhlanhla Mabaso, manager, the Open Source Centre at the CSIR`s Meraka Institute
However, not everyone agrees it is that simple. While the potential exists, "simply being open is no guarantee of security", says former Bugtraq moderator Elias Levy. Another expert warns that Floss users risk being lulled into a false sense of security.
Proponents of proprietary software say the ability to check and fix code does not mean people actually do so, while the availability of code means exploitable vulnerabilities are easier to find.
However, Mabaso believes that lack of access to the source doesn`t mean crackers can`t get access by disassembling the code or reverse engineering it, and that this is all that is required to attack a piece of software. However, access to the source code is a necessary requirement to audit code and fix vulnerabilities, once they are discovered.
High-tech crime is prevalent in SA, and "most of the major financial institutions do regard it as a major threat," says Cobus Venter, the CSIR`s resident expert on cyber forensics.
"I cannot say that a distinct difference exists between the operating systems," he adds. "For most it is primarily a human problem, as most penetrations happen using known exploits and work due to bad configuration of the system."
The CSIR has established training materials for law enforcement agencies focusing on cyber forensics, according to Venter, and has trained more than 50 "first responders" to help combat cybercrime.
<B>ITWeb Security Summit 2006</B>
At the ITWeb Security Summit 2006, from 8 to 9 March, top international security experts from the CSIR, MasterCard International, Gartner, Microsoft, Symantec, McAfee, Cisco, Check Point, Computer Associates and OpenHand will join forces to help you understand the insider threat to your business, as well as the strategies, technology and processes most effective in dealing with this changing threat environment.
In two separate keynote sessions at the conference, well-known author and ex-hacker, Kevin Mitnick will also offer an exclusive insider`s view of the low-tech threats to high-tech security, with advice for preventing "social engineering" hacks and how to mitigate the risk that wireless networks pose to sensitive corporate data.
More information about the conference and delegate bookings are available online at www.itweb.co.za/securitysummit or by contacting Denise Breytenbach at (011) 807-3294 or denise@itweb.co.za.
Free software could play a key role in the CSIR`s "quick reaction" strategy, says Mabaso, because this environment requires the ability to develop solutions speedily as well as the ability to have them shared across a number of departments, such as the police, correctional services and justice. "The free software collaboration model facilitates this," he says. "I hope my colleagues at the CSIR defence, peace, safety and security will demonstrate this in the near future."
He adds an interesting twist to the question of whether cybercrime is more prevalent on proprietary platforms than on open source systems. "There is a more common, yet somewhat subtle form of high-tech crime. This is in the form of bad business practice, seriously dodgy high-tech advice and tricky or illegal adverts run by some of the high-tech organisations.
"A classic example is that of Microsoft. These guys were sued and found guilty for a number of bad business practices in Korea, the US, and Europe. In the US they were forbidden by a high court judge from distributing proprietary software to school children in poverty stricken areas. In the UK they were asked to stop running adverts claiming that GNU/Linux has a higher total cost of ownership. Yet none of this has stopped them from doing these things in SA and other parts of Africa. They have registered software patents in SA, in spite of the Patent Act, the National Advisory Council on Innovation paper on free software (http://www.naci.org.za/floss/) and the fact that these patent applications were rejected more than once in the US.
"In short, the Floss move has positive security implications. After all, it is safer to be free than to be a slave. Free software guarantees freedom and solidarity within the information society. It aligns perfectly with the needs of a developmental state. It guarantees the freedom to innovate with a sense of security from legal threats. A country that takes its security seriously, would put its key ICT systems in the hands of its own security cleared engineers and not vendors," he adds.

