{"id":5449,"date":"2022-01-14T03:03:46","date_gmt":"2022-01-14T03:03:46","guid":{"rendered":"https:\/\/pabconference.com\/google-says-open-source-software-should-be-more-secure-the-register\/"},"modified":"2022-01-14T03:03:46","modified_gmt":"2022-01-14T03:03:46","slug":"google-says-open-source-software-should-be-more-secure-the-register","status":"publish","type":"post","link":"https:\/\/wijhha.com\/index.php\/2022\/01\/14\/google-says-open-source-software-should-be-more-secure-the-register\/","title":{"rendered":"Google says open source software should be more secure \u2022 The Register"},"content":{"rendered":"<p><\/p>\n<div id=\"body\">\n<p>In conjunction with Thursday&#8217;s White House meeting in which tech companies discussed the security of open source software, Google proposed three initiatives to bolster national cybersecurity.<\/p>\n<p>The meeting was arranged last month by US National Security Adviser Jake Sullivan, amid the scramble to fix the Log4j vulnerabilities that preoccupied so many people over the holidays.  Sullivan asked the invited companies \u2014 a group that includes Amazon, Apple, Google, IBM, Microsoft and Oracle \u2014 to share ideas on how to improve the security of open source projects.<\/p>\n<p>Google&#8217;s chief legal officer, Kent Walker, said in a blog post that just as government and industry have worked to support legacy, shoddy systems and software, the Log4j overhaul \u2014 which is still in progress \u2014 has demonstrated that open source software needs the same attention as critical infrastructure.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\">\n        <noscript><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_software\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YeDoDi5cqnQ0oyq4iHnVuwAAABc&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt=\"\"\/><\/p>\n<p>        <\/noscript>\n    <\/div>\n<p>\u201cFor too long, the software community has been comfortable in assuming that open source software is generally secure due to its transparency and assuming that &#8216;many eyes&#8217; have been watching to discover and solve problems,&#8221; Walker said.  &#8220;But in reality, while some projects have a lot of eyes on them, others have little or none at all.&#8221;<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\">\n            <noscript><\/p>\n<p>                    <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_software\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44YeDoDi5cqnQ0oyq4iHnVuwAAABc&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt=\"\"\/><\/p>\n<p>            <\/noscript>\n        <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\">\n                <noscript><\/p>\n<p>                        <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_software\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33YeDoDi5cqnQ0oyq4iHnVuwAAABc&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt=\"\"\/><\/p>\n<p>                <\/noscript>\n            <\/div>\n<\/p><\/div>\n<p>He noted Google&#8217;s various efforts to be part of the solution, and outlined several potential public-private partnerships that were mentioned at the meeting:<\/p>\n<ul>\n<li>To select the list of important open source projects<\/li>\n<li>To create basic standards for security, maintenance, source, and testing<\/li>\n<li>To create a maintenance market, to match volunteers with projects in need<\/li>\n<\/ul>\n<p>All ideas are commendable, if not particularly radical, unexpected, or novel.<\/p>\n<p>Knowing which open source projects have the most reach is certainly important to understanding where bugs will have the greatest impact.  Google software engineers have already been thinking about defining &#8220;critical importance&#8221; in the context of the program, so work is in progress.  In fact, there is a program to establish the degree of importance for other programs.<\/p>\n<p>As for the core criteria, the Open Source Security Foundation is already in place, and we already have frameworks like Supply Chain Levels that Google devised for the software business.  So this is also a work in progress.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\">\n            <noscript><\/p>\n<p>                    <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_software\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44YeDoDi5cqnQ0oyq4iHnVuwAAABc&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt=\"\"\/><\/p>\n<p>            <\/noscript>\n        <\/div>\n<p>Walker&#8217;s description of an organization to connect projects with volunteer helpers working in companies is much like any of the many open-source sustainability efforts, only without the specific monetary component of GitHub or Patreon sponsors.<\/p>\n<p>\u201cMany leading companies and organizations do not realize how many parts of their critical infrastructure rely on open source,\u201d Walker said.  &#8220;This is why it is imperative that we see more public and private investment in keeping this ecosystem healthy and secure.&#8221;<\/p>\n<p>That&#8217;s what everyone keeps saying, even though it&#8217;s not often pushed.<\/p>\n<h3 class=\"crosshead\">\n  <span>strength in union<\/span><br \/>\n<\/h3>\n<p>Mike Hanley, GitHub&#8217;s chief security officer, also had something to say on the matter: &#8220;First, there must be a collective industry and community effort to secure the software supply chain,&#8221; he said in a blog post.  &#8220;Second, we need better support for open source maintainers to make it easier to secure their projects.&#8221;<\/p>\n<p>Katie Mousoris, founder of Luta Security, said in her speech <em>record<\/em> In a phone interview, Google, as part of what it describes as one percent security, has done a lot of good work in terms of its own product security and security related to its software ecosystem.  But she said that this work is purely voluntary.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\">\n            <noscript><\/p>\n<p>                    <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_software\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33YeDoDi5cqnQ0oyq4iHnVuwAAABc&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt=\"\"\/><\/p>\n<p>            <\/noscript>\n        <\/div>\n<p>\u201cIf the US government is interested in securing open source, it needs to be more serious in terms of providing support to the open source community other than volunteering, philanthropic work from one percent security like Google, Microsoft and other elites, and the top providers that have been invited to The White House today.<\/p>\n<p>Moussouris suggested that we need to adopt a model that more closely resembles the global basic income of the developer community, in part because it is difficult to determine which projects are important and which are not.<\/p>\n<p>&#8220;The open source community definitely needs some form of universal basic income, because there are projects that start out as hobbies by one individual, and anticipating popularity becomes very difficult,&#8221; she said.<\/p>\n<p>She said these projects often exist without much attention until a vulnerability appears and people realize that there is only one supervisor.  While the government should value the contributions of large companies like Google and its peers, &#8220;it cannot count on volunteer philanthropy, labor and donations from security giants at 1 percent if it is going to solve this problem,&#8221; she said.<\/p>\n<p>When asked whether licensing software that imposes financial support obligations on large users of open source projects might help, Moussouris was not certain that licensing was the ideal approach to making open source more sustainable and more secure.  But it has expressed support for the transfer of revenue from the haves to the have-nots as a general goal.<\/p>\n<p>\u201cIf the idea is to pay more of those who take advantage of open source and more of that dividend money towards those who build open source \u2014 like in the moderators, and those who do it for free, or for very little financial support \u2014 if the goal is Putting more of those profits derived from open source back into the hands of maintainers, I support that.\u201d<\/p>\n<p>Moussouris added that getting money from maintainers of open source software can be complicated.  It is often not easy to decide who to pay or how to pay.  &#8220;You can&#8217;t just cut a check from the government to an individual, and that&#8217;s true all over the world,&#8221; she said.<\/p>\n<p>Another issue not mentioned among Google&#8217;s proposals is the need for specific security skills in the bug fixing process.  Moussouris noted the lack of root cause analysis using Log4j which allowed the development of multiple variants beyond the initial fix.  She said the Log4j developers did not understand the scope of the reported vulnerability.<\/p>\n<p>\u201cThis is a problem that will not be solved by getting more developers into it [the problem] These are different job roles.  &#8220;So this is a gap in what everyone here is talking about in terms of support.&#8221;  \u00ae<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In conjunction with Thursday&#8217;s White House meeting in which tech companies discussed the security of open source software, Google proposed<span class=\"more-dots\">&#8230;<\/span><\/p>\n","protected":false},"author":1,"featured_media":5450,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-5449","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-featured","no-post-thumbnail"],"_links":{"self":[{"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/posts\/5449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/comments?post=5449"}],"version-history":[{"count":0,"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/posts\/5449\/revisions"}],"wp:attachment":[{"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/media?parent=5449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/categories?post=5449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wijhha.com\/index.php\/wp-json\/wp\/v2\/tags?post=5449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}