What will it take to make open source software more secure for the U.S government (and everyone else)? That's the question top of mind at the Secure Open Source Software Summit (SOSS) taking place this week.
The SOSS event is hosted by the Open Source Security Foundation (OpenSSF), which is part of the Linux Foundation. With open source software being integral to critical infrastructure in sectors like energy, water, and manufacturing, the summit focused on addressing security challenges related to its use. Attendees included officials from the White House National Security Council, the Cybersecurity and Infrastructure Security Agency (CISA), and over 20 major technology companies like IBM, Google and Microsoft.
The 2023 event, in many respects, was a followup to one held in 2022 at the White House to figure out ways to improve open source software security. In fact, part of the SOSS event was an opportunity for the OpenSSF to detail some of the progress it’smade in the past year with the release of the SOSS Vision Brief, though much work remains.
"Open source is really a public good, and no one constituent can make it secure on their own, be it public, private sector or the community," Omkhar Arasaratnam, general manager, at the OpenSSF, told SDxCentral. "Where we are going to continue to focus is on being that bridge between these three stakeholders to ensure that open source software continues to be secure by construction."
Moves to secure open source software, thus farAt the summit, The OpenSSF announced several key achievements it has managed over the past year.
The OpenSSF claims that it has helped to educate over 20,000 developers on secure coding practices and invested in assisting open source projects to find and fix vulnerabilities, and advanced digital signature technology to validate software packages.
Arasaratnam also specifically pointed to the supply chain levels for software artifacts (SLSA) project, which had its SLSA 1.0 release in April as being a key milestone.SLSA is a framework that aims to help define and ensure the integrity of software artifacts throughout the software supply chain.
Talking open source software security at SOSSAt the SOSS event, Arasaratnam said the goal was to get people that are extremely opinionated from both the public sector and private sector on the issues of securing open source software to provide their views.
Among those that did provide their view in the closed door sessions were Anne Neuberger, deputy national security advisor for Cyber and Emerging Technologies at The White House, and Kemba Walden, acting national cyber director at The White House among others. With all the feedback and insights collected at the event, the goal moving forward is to create tangible goals and milestones towards further improving the state of open source software security.
"We've committed to Neuberger to come back to her in six months with a midterm update as well as next year to do this again,"Arasaratnam said.
While there is likely money that will be required to further secure open source software, Arasaratnam wants to take a pragmatic approach, by first understanding what the requirements are for how to solve the problem.
"A lot of people think about security, especially within open source, as this large intractable impossible problem to solve," he said. " I would like us to make incremental sustainable progress."
Comments