Enterprise open source Toolkit
Story: Open source 'lacks enterprise-grade security'
Deliberately misleading conclusions
I agree that this is FUD designed for non-technical managers. It is deliberately misleading.
Firstly, is it fair to compare, say, Apache (with a development cadre of possibly 100s) with an open source project started by a 16 year old in his mother's basement? Of course not.
The quality of their code and security records are not in the same league.
The same can be said for comparing Oracle with MS Access. They are both databases - one is really rather good and the other one...? Well, enough said.
At least with open source software, tools exist to scientifically and objectively quantify the quality of the development team and support communities around them (SQO-OSS) - something not possible with closed source software by its very nature.
BTW, the NSA and GCHQ use a huge amount of Open Source technologies like Linux. Do you think they'd allow themselves to use insecure software?
Full Talkback thread




