Irish SEO,  Marketing & Webmaster Discussion

 

Security with open source

This is a discussion on Security with open source within the Security forums, part of the Server / Technical Administration Tips and Queries category; Hi Guys, like allot of designers out there at the moment I use a fleet of different opens source web ...


Go Back   Irish SEO, Marketing & Webmaster Discussion > Webmaster Help > Server / Technical Administration Tips and Queries > Security

Register Forum Rules FAQDonate Members List Calendar Search Today's Posts Mark Forums Read


Notices

Reply

 

LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-12-2007, 11:06 AM
Frontpage User
 
Join Date: Jul 2006
Posts: 7
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
aaron_kenny will become famous soon enough
Default Security with open source

Hi Guys,

like allot of designers out there at the moment I use a fleet of different opens source web technologies including CMS, rich text editors, image manipulation tools, forums etc.

My question is, generally have any of you been concerned with potential security issues with any of these technologies.

For example, the other day I came across a mambot for Joomla which would not only serve my clients needs but would also save me loads of time and effort. However knowing that the client (who will have to remain unnamed) is very conscious of online security the thought occured to me, how do I really know that this mambot doesn't have some underlying method of tracking sensitive customer details and the likes.

Now obviously I researched this mambot and discovered that it's perfectly safe and has been certified by Joomla.
However as an open question I'd be interested in hearing your thoughts?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 07-12-2007, 11:16 AM
blacknight's Avatar
Web Slave
Recent Blog:
 
Join Date: Jan 2006
Location: Ireland
Posts: 6,319
blacknight is a splendid one to beholdblacknight is a splendid one to beholdblacknight is a splendid one to beholdblacknight is a splendid one to beholdblacknight is a splendid one to beholdblacknight is a splendid one to beholdblacknight is a splendid one to behold
Send a message via ICQ to blacknight Send a message via AIM to blacknight Send a message via MSN to blacknight
Default

The main problem with ANY cms is that most people seem to install them and then forget to upgrade / patch them

Some OSS software has a good security track record, but other projects definitely don't (wordpress springs to mind!)

As for nefarious plugins etc., while I haven't come across any I don't think it's simply a matter of open vs. closed source. A lot of commercial software "calls home" as well
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 07-12-2007, 03:59 PM
Forbairt's Avatar
respect my AW-THOR-IT-AYY
 
Join Date: Jun 2007
Location: My Office, Dublin
Posts: 2,023
Nominated 2 Times in 1 Post
Nominated TOTW/F/M Award(s): 1
Forbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enough
Send a message via AIM to Forbairt Send a message via MSN to Forbairt Send a message via Yahoo to Forbairt Send a message via Skype™ to Forbairt
Default

Quote:
Originally Posted by blacknight View Post
The main problem with ANY cms is that most people seem to install them and then forget to upgrade / patch them
In relation to this a problem I find is that unless you've a support agreement with your client and a new patch comes out ... well .. you can't justify patching it for them. It leaves you feeling kinda bad and wondering what happens if XYZ gets exploited.

I tend to come across clients who aren't interested in the support agreements and it leaves me in the same boat I guess do I or don't I go for the open source but as Blacknight said its happens even in commercial software
__________________
Forbairt Media | Web Design & Development Galway / Dublin, Ireland - coming soon ... ( vague but descriptive isn't it )
Recent Work: Safari Club African Safari Holidays - South Africa Safaris
Other Stuff: FluffyLinkulator Rapid Inclusion Service Tools
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #4 (permalink)  
Old 07-12-2007, 10:32 PM
Arch-Stanton's Avatar
Member
Recent Blog: Lose Pounds
 
Join Date: Jan 2006
Posts: 98
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Arch-Stanton will become famous soon enough
Default

I am a great believer in open source technologies and in my experience the open source tends to more secure in some cases than proprietary software.

An example that comes to mind would be RHEL and CentOS, they are exactly the same and RHEL uses the CentOS community to find bugs and enhance the RHEL product.

With regard to Joomla, there are a couple of thousand extensions in their directory and they only certify (with regard to security updates) extensions that are in the core release of the product and not 3rd party extensions.

You could say that any piece of software is exploitable , so it really down to the resources of the developer as to how secure something is over time.

.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 05-03-2008, 11:34 PM
nevf's Avatar
Director of Nothingness
 
Join Date: Aug 2006
Location: Ireland, Mayo
Posts: 268
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
nevf will become famous soon enough
Send a message via MSN to nevf Send a message via Skype™ to nevf
Default

I put a lot of faith in open source, at least they're always being updated, they're more widely available, and hackers don't aim for them. Their vulnerabilities are often quickly located and reported upon release, and I always google apps, before i use them...

I personally, have little faith in commercial software, except in some cases. I always try to keep costs down, but if I feel that security is bad on open source, i always go for commercial. for example phpbb2, however I feel that phpBB3 is a massive improvement. if phpbb3 wasn't improved, i would either go for smf or vbulletin.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Tags
open, security, source

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads

Thread Thread Starter Forum Replies Last Post
Do you use open source software? blacknight General Chat 16 11-05-2008 09:59 PM
Open Source Software for Windows blacknight Desktop Computer Issues 0 19-03-2007 02:03 PM
Free / Open Source Graphics Editors? blacknight Webmaster Discussion 0 20-11-2006 09:22 AM
IIA Netvisionary Awards Voting Now Open blacknight Webmaster Discussion 0 07-10-2006 07:40 PM


All times are GMT +1. The time now is 04:07 AM.


Powered by: vBulletin Version 3.7.3, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Hosted in Ireland by Blacknight - Test your ISP |Irish Hosting Directory| Armchair.ie|Logo by Eden Web Design|Avatars by Afterglow |Latest Blog Entries | VPS HostingAd Management by RedTyger

Search Engine Friendly URLs by vBSEO 3.2.0