Executives from Amazon, Microsoft, Google, and other top tech companies called for bigger investments in open source security and better developer support at a White House meeting today.
“Open source software has been truly transformative for private and public sector organizations alike, dramatically accelerating the pace of innovation over the last decade with benefits for organizations of all shapes and sizes,” Amazon Chief Security Officer Steve Schmidt said in a statement.
“The importance and pervasive use of open source software along with an increasing range of security threats have made it clear that all stakeholders must work together with even greater diligence to ensure that these tools remain both open and secure,” he continued. “We look forward to partnering with key stakeholders in the government, enterprise, and open source communities to continue to enhance these efforts.”
The White House summit follows several pervasive cyberattacks including one targeting Apache’s popular Java logging library, Log4j, that’s used in nearly every enterprise app and cloud service. This includes those built by companies at the White House meeting including Amazon, Microsoft, and Google.
As with most open source software vulnerabilities and exploits, Log4j ignited another debate over whether open source is inherently less secure than proprietary code.
Earlier this month, the Federal Trade Commission warned companies to immediately patch any Log4j vulnerabilities in their projects or face legal action. And it also indicated it would take a tougher stance on open source vulnerabilities in the future.
“These projects are often created and maintained by volunteers, who don’t always have adequate resources and personnel for incident response and proactive maintenance even as their projects are critical to the internet economy,” the alert said. “This overall dynamic is something the FTC will consider as we work to address the root issues that endanger user security.”
A few days later, the Apache Software Foundation (ASF), which is one of the world’s largest open source organizations, posted a blog that said for-profit software vendors that use open source code in their product must be held accountable for security flaws, too.
“We can’t fix open source supply chain issues by focusing exclusively on the upstream producer,” ASF wrote.
The foundation noted that “only a tiny percentage of downstream companies” that use open source code in their products participate in their continued maintenance and security efforts. “Security directives MUST avoid placing additional unfunded burdens on the few maintainers who are already doing the work.”
Google Cloud CISO Phil Venables and VP of Cloud Infrastructure Eric Brewer also attended the White House meeting. And in a subsequent blog, Google Chief Legal Officer Kent Walker called for greater public and private investment in securing open source. He also noted Google’s own contributions, which include providing $100 million to support third-party foundations like OpenSSD that manage open source security priorities and fix vulnerabilities.
At the White House meeting, Google execs proposed “a public-private partnership to identify a list of critical open source projects — with criticality determined based on the influence and importance of a project — to help prioritize and allocate resources for the most essential security assessments and improvements,” Walker wrote.
The cloud provider also called on industry and government to work together to establish baseline standards for security, maintenance, and testing so critical infrastructure and other important systems can continue to use open source projects. “These standards should be developed through a collaborative process, with an emphasis on frequent updates, continuous testing, and verified integrity,” Walker wrote.
Oracle, IBM RedHat, and Microsoft’s GitHub also participated in the White House summit.
“Open source software underpins the vast majority of the software we all use daily — just one or two lines of vulnerable code can have a global ripple effect across the billions of developers and services that rely on it,” GitHub Chief Security Officer Mike Hanley said in a statement after the meeting. “Addressing software supply chain security is a team sport. Through partnerships with governments, academia, developers, and other organizations, together we can make a significant impact on the future of software security, and today’s discussion is an important step in securing the world’s code together.”
Comments