The Risks of Decomposing Software Components
The Linux Foundation's Open Source Security Foundation (OSSF) is addressing the challenge of timely software component updates to prevent security vulnerabilities like Log4J. In an interview with Alex Williams of The New Stack at the Open Source Summit in Vancouver, Omkhar Arasaratnam, the new general manager of OSSF, and Brian Behlendorf, CTO of OSSF, discuss the importance of making software secure from the start and the need for rapid response when vulnerabilities occur.
In this conversation, they highlight the significance of Software Bill of Materials (SBOMs), which provide a complete list of software components and supply chain relationships. SBOMs offer data that can aid decision-making and enable reputation tracking of repositories. The interview also touches on the issues with package managers and the quantification of software vulnerability risks. Overall, the goal is to improve the efficiency and effectiveness of software component updates and leverage data to enhance security in enterprise and production environments.
Learn more from The New Stack:
Creating a 'Minimum Elements' SBOM Document in 5 Minutes
Enhance Your SBOM Success with SLSA
Inside a $150 Million Plan for Open Source Software Security
AUSTIN, TEX. —Everyone uses open source software — and it’s become increasingly apparent that not nearly enough attention has been paid to the security of that software. In a survey released by The Linux Foundation and Synk at the foundation’s Open Source Summit in Austin, Tex., this month, 41% of organizations said they aren’t confident in the security of the open source software they use.
At the Austin event, The New Stack’s Makers podcast sat down with Brian Behlendorf, general manager of Open Source Security Foundation (OpenSSF), to talk about a new plan to attack the problem from multiple angles. He was interviewed for this On the Road edition of Makers by Heather Joslyn, features editor at The New Stack.
Behlendorf, who has led OpenSSF since October and serves on the boards of the Electronic Frontier Foundation and Mozilla Foundation, cited the discovery of the Log4j vulnerabilities late in 2021, and other recent security “earthquakes” as a key turning points.“I think the software industry this year really woke up to not only the fact these earthquakes were happening,” he said, “and how it's getting more and more expensive to recover from them.”
The Open Source Security Mobilization Plan sprung from an open source security summit in May. It identifies 10 areas that will be targeted for attention, according to the report published by OpenSSF and the Linux Foundation:
Security education.
Risk assessment.
Digital signatures, such as though the open source Sigstore project.
Memory safety.
Incident response.
Better scanning.
Code audits.
Data sharing.
Improved software supply chains.
Software bills of material (SBOMs) everywhere
The price tag for these initiatives over the initial two years is expected to total $150 million, Behlendorf told our Makers audience.
The plan was sparked by queries from the White House about the various initiatives underway to improve open source software security — what they would cost, and the time frame the solution-builders had in mind. “We couldn't really answer that without being able to say, well, what would it take if we were to invest?” Behlendorf said. “Because most of the time we sit there, we wait for folks to show up and hope for the best.”
The ultimate price tag, he said, was much lower than he expected it would be. Various member organizations within OpenSSF, he said, have pledged funding. “The 150 was really an estimate. And these plans are still being refined,” Behlendorf said. But by stating specific steps and their costs, he feels confident that interested parties will feel confident when it comes time to make good on those pledges.
Listen to the podcast to get more details about the Open Source Security Mobilization Plan.
Live From the World Economic Forum Industry Strategy Meeting: Breaking the Blockchain Hype - Ep.68
This is a live recording from a panel I moderated at the World Economic Forum Industry Strategy Meeting. The speakers included Shwetha Shetty Senior Director, Corporate Strategy Group, of SAP, Adam Ludwin, CEO of Chain, Brian Behlendorf, executive director of HyperLedger the Linux Foundation and Sheila Warren, project head of blockchain and distributed ledger technology at the World Economic Forum.We dive into the pros and cons of using blockchains for elections. which types of problems are best-suited to be solved by blockchain, why B2B applications of blockchain might come before B2C products and what kinds of identity-related data might be safe to put on a blockchain. Plus, Adam reveals some entertaining anecdotes about Silicon Valley safaris and how old World’s Fair tickets could have an analog to blockchain systems today.
Episodes I referenced during the discussion in case listeners want to dive more into the elections topic:
Tomicah Tillemann episode on the blockchain voting pilot in West Virginia: http://unconfirmed.libsyn.com/battling-corruption-with-blockchain-technology-tomicah-tillemann-of-the-blockchain-trust-accelerator-ep018
Alex Gladstein episode with more on blockchain-based voting: http://unconfirmed.libsyn.com/alex-gladstein-of-the-human-rights-foundation-on-the-first-crypto-war-ep021
Tweets about blockchain-based voting:
Matt Blaze’s objecton to blockchain-based voting: https://twitter.com/mattblaze/status/1002921011854143488
Vitalik’s response: https://twitter.com/VitalikButerin/status/1004203105611726849
Tomicah Tillemann’s response: https://twitter.com/TomicahTD/status/1004325810252197888
To address the question at the end about blockchain-based passports:
2 Katie Haun episodes on using blockchain-based systems to solve the problems of "breeder documents" and fraud, waste and abuse:
Fraud, waste and abuse: http://unchainedpodcast.co/live-from-inforum-at-the-commonwealth-club-blockchain-and-cryptocurrency-the-basics-with-kathryn-haun
Breeder documents: http://unchainedpodcast.co/federal-prosecutor-kathryn-haun-on-how-criminals-use-bitcoin-and-how-she-catches-them
Episode with Vinny Lighal, founder of Civic, which is working on a blockchain-based identity solution: http://unchainedpodcast.co/bitcoin-oracle-vinny-lingham-on-why-bitcoin-is-overpriced
Thank you to our sponsor!
Blockchain Warehouse: https://www.blockchainwarehouse.com
Learn more about your ad choices. Visit megaphone.fm/adchoices
Blockchains and Databases at OSCON (Interview)
We went back into the archives to conversations we had around blockchains and databases at OSCON 2017. We talked with Monty Widenius, creator of MariaDB the open source forever fork MySQL, Brian Behlendorf, Executive Director of Hyperledger, the open source collaborative effort hosted by The Linux Foundation to advance blockchain technologies, and Tague Griffith, Head of Developer Advocacy at Redis Labs, the home of open source Redis and commercial provider of Redis Enterprise.
Join the discussion
Changelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!
Sponsors:
Auth0 – The world’s #1 authentication-as-a-service platform. Sign up with our URL and get the free plan or try the enterprise plan for 21 days. No credit card required.
DigitalOcean – Get DigitalOcean Spaces free for 2 months. Securely store and deliver any amount of data with the same simplicity you’ve come to expect from us. Instantaneously create a cost-effective, reliable storage space using our drag-and-drop UI or API.
Toptal – Hire the top 3% of freelance software developers, designers, and finance experts. Email adam@changelog.com for a personal introduction.
GoCD – GoCD is an on-premise open source continuous delivery server created by ThoughtWorks that lets you automate and streamline your build-test-release cycle for reliable, continuous delivery of your product.
Featuring:
Monty Widenius – Website, GitHub, X
Brian Behlendorf – Website, GitHub, X
Tague Griffith – GitHub, X
Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
Michael “Monty” Widenius on Wikipedia
MariaDB
Getting started with MariaDB for developers
Business Source License 1.1
Business Source License - FAQ
Projects using BSL 1.1
Adopting and Developing BSL Software
Brian Behlendorf on Wikipedia
Hyperledger
Hyperledger Projects
Redis Labs
The Changelog #45: Redis In-Memory Data Store with Salvatore “antirez” Sanfilippo
Redis Open Source
Something missing or broken? PRs welcome!