On CBS MoneyWatch: 12 Tough Questions to Ask Your Parents
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 7 of 24:
Next »
« Previous
Useless without the ability to reproduce from the buildchain
Unless you have access to all the source code to the operating system, drivers, applications and compile/build toolchain, restricted access to the source code provides little in the way of added security.

Harmful code can be inserted at any point in the compile, build and provision processes. Either by accident, eg Microsoft accidentally shiping Nimda in .NET to South Korea ...
http://www.sophos.com/virusinfo/articles/nimda_korea.html
... or by hidden intent ...
http://www.techlawjournal.com/cong106/encrypt/19990928a.htm#weldon1
"But the point is that when John Hamre briefed me, and gave me the three key points of this change, there are a lot of unanswered questions. He assured me that in discussions that he had had with people like Bill Gates and Gerstner from IBM that there would be, kind of a, I don't know whether it's a, unstated ability to get access to systems if we needed it. Now, I want to know if that is part of the policy, or is that just something that we are being assured of, that needs to be spoke. Because, if there is some kind of a tacit understanding, I would like to know what it is."

Without the ability to reproduce each component of the software from scratch to compare with the binary that Microsoft ships, Microsoft's restricted access is effectively useless.

Also the NDA required to access the source code effectively limits peers in the software industry, those with experence in creating competing applications, from viewing the source code from the start.

Pig Iron
http://groups.google.com/groups?selm=slrna4k6r5.jhf.heretic%40heretic.ihug.co.nz
Posted by: David Mohring   Posted on: 09/20/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

I'm first!  Confused by religion | 09/19/04
Excuses Excuses  nucrash | 09/20/04
No computer at home?  Anton Philidor | 09/20/04
I have several at home...  Confused by religion | 09/20/04
When life loses its meaning and purpose  Anton Philidor | 09/20/04
Drip... drip... drip...  Linux User 147560 | 09/19/04
Useless without the ability to reproduce from the buildchain  David Mohring | 09/20/04
ANd yet, so many governments disagree with you.  No_Ax_to_Grind | 09/20/04
hmm yes of course  crocd | 09/20/04
And yet, the governments of 60 countries wanted to do security audits.  B.O.F.H. | 09/20/04
I want to as well  crocd | 09/20/04
So your point is this is a good thing. I agree.  No_Ax_to_Grind | 09/20/04
Depends if you can change it  crocd | 09/20/04
No you can't change it, that's what open source is for.  No_Ax_to_Grind | 09/20/04
That is not why they are showing the code!  B.O.F.H. | 09/20/04
True. So why do they want to see the code?  Anton Philidor | 09/20/04
BOFH, a question for you.  No_Ax_to_Grind | 09/20/04
You don't like that someone actually read the article and smacked you?  B.O.F.H. | 09/20/04
Unless they can compile it, MS shared source is a sham!  Xunil_Sierutuf | 09/20/04
Stated reasons for this program don't make sense.  Anton Philidor | 09/20/04
Also  michael-t | 09/20/04
ms office code? Only?  michael-t | 09/20/04
Umm, already done.  No_Ax_to_Grind | 09/20/04
This could be only the latest in a loss of faith in Microsoft.  B.O.F.H. | 09/20/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

SmartPlanet

Click Here