LWN.net Logo

Fortify: open source software is a security risk for businesses

Fortify: open source software is a security risk for businesses

Posted Jul 26, 2008 19:31 UTC (Sat) by cde (subscriber, #46554)
Parent article: Fortify: open source software is a security risk for businesses

I have used Fortify myself (as part of my job) to audit the source code of a very large Java
web application. Let me say that not only the tools is greatly overpriced, but it also
produced about 98% of false positives. A manual inspection of the source would have been not
only extremely less expensive, and at the same time more relevant.


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds