FUD vs. CounterFUD
"The very nature of the open source process should rule Linux out of defense applications. The open source process violates every principle of security. It welcomes everyone to contribute to Linux. Now that foreign intelligence agencies and terrorists know that Linux is going to control our most advanced defense systems, they can use fake identities to contribute subversive software that will soon be incorporated into our most advanced defense systems...
"Advocates of the Linux operating system claim that its security can be assured by the openness of its source code. They argue that the 'many eyes' looking at the Linux source code will quickly find any subversions. Ken Thompson, the original developer of the Unix operating system -- which heavily influenced Linux -- proved otherwise. He installed a back door in the binary code of Unix that automatically added his user name and password to every Unix system. When he revealed the secret 14 years later, Thompson explained, 'The moral is obvious. You can't trust code that you did not create yourself. No amount of source-level verification or scrutiny will protect you from using untrusted code.'"
- Dan O'Dowd, CEO, Green Hills Software
Well, for starters this guy is abusing the Thompson example in a couple of ways. Technically, the C compiler was not open source at the time Thompson put in his back door -- you needed an AT&T source license to see it legally. But the more fundamental point is this: nothing prevents someone at a closed-source shop from doing exactly the same thing.
O'Dowd is making the unstated assumption that somehow closed-source development prevents the placement of code unexpected by users in a way open-source development doesn't. The widespread prevalence of easter eggs in closed-source code, like the Mac dogcow or the flight simulator embedded in Excel '97, shows this is nonsense. Managers are essentially helpless to prevent this sort of thing.
If I were an enemy spy, I would much rather bribe a closed-source programmer to slip a deadly easter egg into DOD software than send a patch to an open-source project -- my risk of detection would be far less that way.
- Eric S. Raymond, Open Source Initiative
Sources: http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&newsId=20040408005676&newsLang=en>,
private email from ESR