Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security

Sardonix Source Code Security Auditing Portal 7

Crispin Cowan writes "We have just announced the Sardonix source code security auditing portal. Sardonix is intended to help, encourage, and preserve community security auditing of open source programs. The "many eyes" effect is enabled by open source software, but is not assured. Sardonix seeks to measure who is actually reviewing the source, and reward that work with public props.

Crispin"

This discussion has been archived. No new comments can be posted.

Sardonix Source Code Security Auditing Portal

Comments Filter:
  • Along the lines of a different side of the "security" issue, The Edge Report [edgereport.com] has posted an interesting article talking about the national security implications of closed source software. While the infiltration of Microsoft by Al Qaeda may have been only a rumor, the article [edgereport.com] explores a world where this could happen. And guess what? We're living in it. It closes with a powerful statement: "Closed source software vendors, in the name of National Security: Open your Code!".

    http://www.edgereport.com/article.php?sid=135 [edgereport.com]

    --
  • The simple truth: Wirex is out to make a profit.

    They've already had their DARPA contracts, and what have they contributed? No-exec patches for Linux. That's about it.

    If the government had done their homework, they would have seen there are plenty of other companies that are NOT trying to capitalize on the security hype, and have a much greater pull and understanding of the community than Wirex. This project will fail, simply because Wirex cannot maintain and engage the community to an extent that it will become the premier bug-squashing center of the open source universe. If that is not the point of the project, then the money is wasted anyway.

    I'd much rather see the US funding non-profit software-security initiatives. It needs to be non-profit, and not affiliated with any one vendor. They need to be actively involved in the security community; not just post a message when they get funding. I think we'd see much greater success.

The use of money is all the advantage there is to having money. -- B. Franklin

Working...