After Log4j, Open-Source Software Is Now a National Security Issue

Image for article titled After Log4j, Open-Source Software Is Now a National Security Issue

Photo: Dünzlullstein bild (Getty Images)

For years, developers of free, open-source software have been telling anyone who will listen that their projects needs better financial assistance and more oversight. Now, after a number of disastrous incidents involving open-source code, the federal government and Silicon Valley may finally be listening.

A meeting at the White House on Thursday saw executives from some of the tech sector’s biggest companies meet with administration officials to discuss the need for better security in the open-source community. The list of attendees included big names like Google, Facebook, Microsoft, Amazon, Oracle, and Apple, among others.

Unlike proprietary software, open-source software is free, publicly inspectable, and can be used or modified by anybody. Because of how useful open-source tools can be, big corporations will often utilize them for development purposes. But, unfortunately, open-source projects need oversight and funding to remain secure—and they don’t always get it. For years, open-source developers have complained that their software needs better support from Big Tech and other institutional actors—an issue that is finally gaining some mainstream attention.

It’s not hard to see why the White House has convened its meeting right now. Just a month or so ago, a pernicious bug was found in the popular open-source Apache logging library log4j. The troubled program, which is used by just about everybody, led to widespread panic throughout the tech industry, as companies scrambled to patch the systems and products that relied upon the library for success. (Officials from the Apache Software Foundation were also present at Thursday’s meeting.)

Log4j isn’t the only open-source debacle to occur lately. Just last week, the creator of two widely used software tools decided to inexplicably disable them via a number of bizarre software updates. Marak Squires, the man behind popular JavaScript libraries Faker and Colors, weirdly blitzed the programs and managed to take down thousands of other software projects that relied on them for success.

In short: There’s clearly room for improvement and, thankfully, attendees of the recent White House meeting seem fairly amenable to it. At the meeting, White House national security advisor Jake Sullivan apparently called open-source software a “key national security issue.” Similarly, Google’s President of Global Affairs and Chief Legal Officer Kent Walker published a statement to the company blog on Thursday arguing that he wanted to see better support for the open-source community.

“For too long, the software community has taken comfort in the assumption that open-source software is generally secure due to its transparency and the assumption that ‘many eyes’ were watching to detect and resolve problems,” said Walker. “But in fact, while some projects do have many eyes on them, others have few or none at all.”

In his statement, Walker further suggests increased public and private support for open-source projects, the establishment of security and testing baselines, and the development of a rubric for identifying “critical” projects—the kind that get a lot of use (i.e., probably something like log4j).

What exactly the government and other members of Big Tech have in mind for better open-source security isn’t entirely clear at this point, but the fact that they’re talking about it seems like a good sign.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
เผยโฉม Playstation VR2 สำหรับเครื่อง PS5 ดีไซน์สุดล้ำพร้อมจอย Sense Controller thumbnail

เผยโฉม Playstation VR2 สำหรับเครื่อง PS5 ดีไซน์สุดล้ำพร้อมจอย Sense Controller

ในงาน CES 2022 ที่ผ่านมา Sony ประกาศเปิดตัว Playstation VR2 สำหรับเครื่อง PS5 ไปแล้ว แต่ในงานเรายังไม่ได้เห็นดีไซน์ตัวเครื่องใด ๆ มีเพียงโลโก้เท่านั้น ล่าสุดภาพดีไซน์ตัวเครื่องทางการก็ถูกปล่อยออกมาแล้วครับ โดย Sony เผยดีไซน์ Playstation VR2 แบบชัด ๆ คู่กับจอย Sense Controller ใหม่ด้วย ตัวอุปกรณ์ใช้สีขาว-ดำ เช่นเดียวกับเครื่อง PS5 ครับ ตัว VR มีความบางและกะทัดรัดมากขึ้นเมื่อเทียบกับรุ่นก่อน ส่วนจอยก็มาในทรงกลมที่เพิ่มความล้ำขึ้นไปอีกครับ PSVR2 ยังคงเชื่อมต่อกับ PS5 ผ่านสายเหมือนเดิม แต่รอบนี้ใช้เพียงแค่สาย USB-C เพียงเส้นเดียวลดการเชื่อมต่อที่ยุ่งยาก ในส่วนของฟีเจอร์จะรองรับระบบ Haptic Feedback, Eye Tracking, ความละเอียด 4K HDR 90Hz/120Hz มุมมองกว้าง 110° ครับผม ในส่วนของราคาและวันวางจำหน่ายตอนนี้ยังไม่มีประกาศทางการออกมานะครับ แต่เชื่อว่าเร็ว ๆ…
Read More
Επιτέλους, το OnePlus 10 Pro βγαίνει εκτός Κίνας, σε περίπου 4 εβδομάδες thumbnail

Επιτέλους, το OnePlus 10 Pro βγαίνει εκτός Κίνας, σε περίπου 4 εβδομάδες

Ίσως να μην χρειαστεί να περιμένετε πολύ περισσότερο για να πάρετε στα χέρια σας την πρώτη ναυαρχίδα της χρονιάς της OnePlus — το OnePlus 10 Pro. Το τηλέφωνο είναι διαθέσιμο μόνο στην Κίνα αυτή τη στιγμή, αλλά μια νέα διαρροή μπορεί να μας έδωσε την παγκόσμια ημερομηνία κυκλοφορίας του. Σύμφωνα με τον tipster Yogesh Brar…
Read More

NBC Universal’s channels are staying on YouTube TV

The YouTube / NBC drama is officially over. After reaching a temporary deal to keep NBC Universal channels on YouTube TV, the companies officially resolved their despite Saturday afternoon. "We’re thrilled to share that we’ve reached a deal to continue carrying the full NBCUniversal portfolio of channels," YouTube wrote on its blog. "That means you…
Read More
This QD-OLED Alienware Monitor is a Real Curveball thumbnail

This QD-OLED Alienware Monitor is a Real Curveball

This QD-OLED Alienware Monitor is a Real CurveballShare SubtitlesOffEnglishAlienware’s latest 32-inch monitor is promising a 240 Hz refresh rate and a point-zero-three pixel response time.PublishedJanuary 8, 2024We may earn a commission from links on this page.Video Program GuideMost PopularLatest VideosTech NewsScienceio9EartherMost PopularSlide 1 of 16Now playing03:02Teenage Engineering’s TP-7 Is the Ferrari of Tape RecordersNow playing03:31Director
Read More
Best Audible Book For People Who Like Buffy And The Spice Girls thumbnail

Best Audible Book For People Who Like Buffy And The Spice Girls

Congratulations! You have almost reached that part of the year when time has no meaning, which means you finally have time to listen to all those audio books you’ve been meaning to get around to on Audible. I recently reupped my subscription to Audible because I couldn’t miss the latest Buffy audio book. And, lo’
Read More
Index Of News
Total
0
Share