I'm just wondering whether I should mention I use some sourceforge code for
my own projects. Got an interview coming up and am thinking that large
companies will write the whole lot themselves and keep it proprietry.
However there aree some really good open source projects that companies can
use to speed stuff up. But they must be paranoid that someone is updating
this and could be anywhere in the world. They can have their own objectives.

So, would you step through and test a small, but very useful, project. Or
would you re-write it?

Pulling code out of a project, changing it and not reporting your changes is
against the OSL. I'm just wondering whether security concious companies
actually use front-end open source stuff.

I'm guessing not. But i'd prefer to step through open source stuff and check
it's credibility, than use closed source. I just think that would take far
much longer, and possibly as expensive as checking the open stuff ...

Views appreciated. My usenet email does work, and I will check in 24 hours.
Everything is totally confidential, I'd just appreciate a viewpoint.


If they are smart they do. Open Source has a far lower incidence of bugs,
AND lower incidence of backdoors, AND lower incidence of open exploits.

Writing something in house does have some advantages. The more popular a
program is, the more its probed, exploits found, and searched out for
exploitation. So "security thru obscurity" does actually work for much of
whats out there.

But its probably a moot question anyway. It seems almost impossible to
convince a corporation that its safer going with open source.

What does the project brief say?  If the needs can be met in full by an  
off-the-shelf item (open source or proprietry) then use it.

 From the developers pov you can be as slack in security as you like - you  
ain't even gonna get to install your stuff on the production servers  
yourself so you best be building a rock solid build kit and if your app  
needs anything remotely akin to admin/root privs then it just ain't gonna  
fly.  You probably won't even get a sniff of user login for the production  
data servers.

You will spend your life in that grey limbo land known as UAT forever  
struggling for sufficient resources.

Have fun.
