5 ms·
Or, alternatively: 3 AM on a Sunday, you discover a critical bug in a library provided by a third party. Commercial support: You call them. It takes an entire
by generalk 10y ago
Or, alternatively:
3 AM on a Sunday, you discover a critical bug in a library provided by a third party.
Commercial support: You call them. It takes an entire day of awkward back and forth emails and phone calls, but you eventually get an engineer to send you a a patched library for testing. It works.
Later, when auditors ask you about vulnerabilities, you can ensure them that you track $VENDORS supported long-term releases, and your contract has a security and support SLA.
Open source support: you find nothing on Google or Stack Overflow. You haven't looked at this source since your initial code review (you're a bank, you review all third-party code in use.) It's 3am, you're tired, and none of this is making sense. You've posted in the projects IRC channel but nobody's listening, and there's no good responses to your posts to the mailing list. You have to pull other team members out of bed, and together you get a reasonable test and patch implemented, which for some reason the maintainers aren't accepting quickly (if ever) and now you're running a local fork of your library. Hope your internal security auditing practices are solid, because there's no guarantee you didn't accidentally create a vulnerability during your pre-morning hackathon.
---
I don't love commercial software typically, but the support and auditing benefits are frequently the overriding factor when choosing for a regulated industry.
- raesene6 10y agosome good points there, but LOL about all 3rd party code being audited.
- IceyEC 10y agoMost importantly, you can pass the blame to the third party organization rather than bringing that in house
- tluyben2 10y agoWe had to: not one line of code not audited, 3rd party or otherwise. Frontend and backend.
- raesene6 10y agoWow, can I ask was it a big stack? And when you say audited, do you mean manual code review, static analysis or something else? How far down the stack did it go? I'd be genuinely interested to hear, as it's something I see bandied around a lot but extremely rarely followed through on as code reviewing a modern stack is a huge proposition, and manual code review is very expensive/time consuming.