Free Republic
Browse · Search
Smoky Backroom
Topics · Post Article

To: zeugma
The incident mentioned in the article has nothing to do with Firefox being hacked. Apparently the wiki software they were running was buggy.

Um, yes, it does have something to do with Firefox being hacked. Any networked computer is only as secure as the least secure component running on it. Clearly, the "more eyes creates better security" theory is blown to shreds for the vast number of open source projects.
11 posted on 10/05/2005 7:22:14 AM PDT by Bush2000 (Linux -- You Get What You Pay For ... (tm)
[ Post Reply | Private Reply | To 10 | View Replies ]


To: Bush2000
Um, yes, it does have something to do with Firefox being hacked.

Can you show me anything in the article that anything about Firefox being hacked?

Clearly, the "more eyes creates better security" theory is blown to shreds for the vast number of open source projects.

Clearly, the "more eyes creates better security" theory is blown to shreds for the vast number of open source projects.

A pretty bold claim based on a perl-based wiki module being hacked. All software has bugs. The debugging process is an ongoing thing. Pretty good proof of the ongoing nature of this process is the fact that even without source code, we still see regular hacks of IE, which is, in todays terms pretty old and (allegedly) mature code. The open source model doesn't eliminate the possibility of defects, but it does make remediation quicker and more transparent for the most part. Some of us lappreciate that.

12 posted on 10/05/2005 7:55:28 AM PDT by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 11 | View Replies ]

To: Bush2000; N3WBI3; MikeinIraq
Um, yes, it does have something to do with Firefox being hacked.

Um...no, it doesn't.

The article clearly states "...attackers looking to exploit a bug in the TWiki collaboration software..."

So the hack was on the Twiki software...not Firefox.

Clearly, the "more eyes creates better security" theory is blown to shreds for the vast number of open source projects.

Please. Much bigger holes were blown in the "closed source is more secure" argument with the sheer volume of viruses, trojans and worms spewed by Micro$lop's malware.

You guys have to go out of your way to find isolated instances of security breaches. Me, I get hundreds of copies of Microsoft's incompetence in the form of worm-based attacks in my web logs and e-mail viruses in my inbox on a weekly basis.

13 posted on 10/05/2005 9:01:36 AM PDT by Prime Choice (E=mc^3. Don't drink and derive.)
[ Post Reply | Private Reply | To 11 | View Replies ]

To: Bush2000
Clearly, the "more eyes creates better security" theory is blown to shreds for the vast number of open source projects.

That's quite an unsupported leap to take from the information posted in the article. Specifically:

"After the July attack, the Mozilla Foundation changed procedures to be sure that security fixes were applied to the Spread Firefox server software, but administrators overlooked the TWiki application, which was no longer being used, Schroepfer said. "This one particular piece of software was an oversight and happened to not get updated," he said.

So the crack of the web site in question involved exploiting a known and fixed bug. The patch for which hadn't been applied since the web site wasn't using the software.

15 posted on 10/05/2005 9:25:16 AM PDT by whd23
[ Post Reply | Private Reply | To 11 | View Replies ]

Free Republic
Browse · Search
Smoky Backroom
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson