Live data from Hacker News

'Securing Open Source Software Act' introduced to US Senate

hsgac.senate.gov

51–60 of 187 posts

Re: 'Securing Open Source Software Act' introduced to US Senate

#51

Earlier quoted context omitted.

They're trying to destroy FOSS ...by hiring FOSS developers? I don't buy it. More like, log4j was an actual real big issue for government agencies because they use rely on tons of open source projects and haven't previously done much to make sure that that supply chain is robust. This would help to change that. Federal contractors don't need to sell proprietary software to make money -- they make more money selling F…

More or less of a big issue than the revolving door of Microsoft bugs?

Different types of issues with different solutions. When you have a support contract with the original developer of a piece of code, you can demand the original developer fix the code.

Re: 'Securing Open Source Software Act' introduced to US Senate

#52
post #15

Earlier quoted context omitted.

> but we should impose a moral standard in lieu of a legal one I agree with you, but these moral obligations tend to get enshrined in law eventually (or quickly! See Covid)

They're gonna get enshrined into law eventually one way or the other. If we do it ourselves and we're effective at limiting the damage we cause we'll be able to maintain control over our own processes. If we don't it will be taken out of our hands.

> If we don't it will be taken out of our hands.

Which will take the code out of theirs. Disincentivize sharing, and sharing goes away.

Re: 'Securing Open Source Software Act' introduced to US Senate

#53

Reading the comments so far, I'm genuinely surprised that more folks haven't applied a "follow the money" lens to their analysis. To me, it reads as a bald-faced attempt to discourage public sector entities from using OSS solutions, when in fact there are perfectly good and definitely >100% secure proprietary offerings that cost a reasonable amount when purchased from the sorts of vendors that pay lobbyists to "help"…

They're trying to destroy FOSS ...by hiring FOSS developers? I don't buy it. More like, log4j was an actual real big issue for government agencies because they use rely on tons of open source projects and haven't previously done much to make sure that that supply chain is robust. This would help to change that. Federal contractors don't need to sell proprietary software to make money -- they make more money selling F…

> Federal contractors don't need to sell proprietary software to make money -- they make more money selling FOSS software.

tech companies in general are making billions using FOSS.

Re: 'Securing Open Source Software Act' introduced to US Senate

#54

Earlier quoted context omitted.

Additionally, “The legislation also requires CISA to hire professionals with experience developing open source software to ensure that government and the community work hand-in-hand and are prepared to address incidents like the Log4j vulnerability.” So we should definitely expect at least some minute changes to the open source economy, itself.

This is the worst part. "Experience developing open source software" is both entirely vague and specific at the same time, likely conjuring up an image of some developer with green boxes on a GitHub repo or something, which is terrible. This is going to force the creation of some sort of silly criteria for what constitutes that experience, of which suits in federal agencies, and the political pressure and politicians…

What criteria would you like to see here?

Re: 'Securing Open Source Software Act' introduced to US Senate

#55
post #53

Earlier quoted context omitted.

They're trying to destroy FOSS ...by hiring FOSS developers? I don't buy it. More like, log4j was an actual real big issue for government agencies because they use rely on tons of open source projects and haven't previously done much to make sure that that supply chain is robust. This would help to change that. Federal contractors don't need to sell proprietary software to make money -- they make more money selling F…

> Federal contractors don't need to sell proprietary software to make money -- they make more money selling FOSS software. tech companies in general are making billions using FOSS.

Of course, which is why I think viewing this as a push for proprietary software is not a fair assessment. Increasing your company's development costs is not a way to make more profit.

The point of this is that you can't treat proprietary software dependencies the same way you treat FOSS. Community FOSS projects just don't have the same development process and governance model that proprietary software does. And so, the assessment of these projects is necessarily different.

Re: 'Securing Open Source Software Act' introduced to US Senate

#56

FWIW, while this specific act may not be enforcing significant regulation, software developers need to understand that there's a ticking clock. Modern civic engineers went without any significant regulation, and then that changed. Software is young, it's in the phase where people aren't dying too often for the public to care. But breaches are leading to massive privacy problems, real wars and conflicts are increasing…

> It is absurd that anyone can anonymously provide open source code, with no assurances whatsoever, and that can end up in critical software. While you're welcome your position and your ideas on how to solve these problems, I believe that the logic you're applying punishes the provider and not the consumer. Nobody is forcing anyone to use OSS without auditing every damn line, if that's their requirement. Telling peop…

Nobody is telling them to share their work and distribute it to others as a package. As I said, I don't think there should be any restrictions on anyone to publish code.

Re: 'Securing Open Source Software Act' introduced to US Senate

#57

Earlier quoted context omitted.

I think a lot of people will disagree, which is cool and I'm fine with that but I do hope that this discussion can be had. > The problem is that somewhere someone who is supposed to be held to some standard decided to pull that code in without looking at it Why is it that there is no standard applied to those who publish code for distribution purposes? Why do we want that to be the case? Again, publishing to Github o…

> Why is it that there is no standard applied to those who publish code for distribution purposes? Because it's rude to make demands of someone who is doing you a favor. Because a system that adds costs to profit-free work will collapse. Because your "distribution" line-in-the-sand doesn't exist. I assume you're thinking of NPM or pypi, but ex. Debian doesn't ask people before including their packages, and ex. nixos…

> Debian doesn't ask people before including their packages, and ex. nixos pulls directly from those "non-distribution" channels.

Then Debian (or NixOS) are publishing the code for distribution, and Debian (or NixOS) should be morally obligated to do the bare minimum to make the code acceptable for others to use.

Re: 'Securing Open Source Software Act' introduced to US Senate

#58

Reading the comments so far, I'm genuinely surprised that more folks haven't applied a "follow the money" lens to their analysis. To me, it reads as a bald-faced attempt to discourage public sector entities from using OSS solutions, when in fact there are perfectly good and definitely >100% secure proprietary offerings that cost a reasonable amount when purchased from the sorts of vendors that pay lobbyists to "help"…

Ehh, I don't disagree with where you start but I do with where you end.

If it is a money thing then it probably has more to do setting up "standards" and "compliance" requirements that you must me to use FOSS software in the government. Then federal contractors and other big FOSS organizations repackage their existing solution as "Government ISO-MITRE, PCI, Whatever-BS-Acronym-we-can-come-up-with" compliant and charge a premium over something they already sale.

I don't think this will hurt FOSS, at the end of the day FOSS is nothing more than someone saying "here's something I wrote or whatever." and sharing it, anything that tries to make more than that isn't talking about FOSS anymore.

Re: 'Securing Open Source Software Act' introduced to US Senate

#59

Earlier quoted context omitted.

> It is absurd that anyone can anonymously provide open source code, with no assurances whatsoever, and that can end up in critical software. While you're welcome your position and your ideas on how to solve these problems, I believe that the logic you're applying punishes the provider and not the consumer. Nobody is forcing anyone to use OSS without auditing every damn line, if that's their requirement. Telling peop…

Nobody is telling them to share their work and distribute it to others as a package . As I said, I don't think there should be any restrictions on anyone to publish code.

I don't know what your background or interest in this issue is, but I'm glad that the overwhelming majority of people do not find this perspective to be reasonable or compelling.

In the meantime, if you don't like the MIT license, don't use software published under it.

Re: 'Securing Open Source Software Act' introduced to US Senate

#60

Earlier quoted context omitted.

I'm going to disagree, I think. The problem isn't on the push side, it's on the pull side. People throwing random-quality code in github is fine. People deciding to amalgamate that into distributions and publish it is fine. The problem is that somewhere someone who is supposed to be held to some standard decided to pull that code in without looking at it, and that is the problem. NO WARRANTY is partially about legal…

I think a lot of people will disagree, which is cool and I'm fine with that but I do hope that this discussion can be had. > The problem is that somewhere someone who is supposed to be held to some standard decided to pull that code in without looking at it Why is it that there is no standard applied to those who publish code for distribution purposes? Why do we want that to be the case? Again, publishing to Github o…

Do you demand that every screwmaker make aircraft-grade screws? Aircraft makers need screws and it would be very convenient to them to be able to go down to any hardware store and just buy whatever screw they want since they are all up to spec. No need to evaluate their suppliers since everybody is required to make things up to their demanding standards.

The problem with this is that not everybody needs expensive aircraft-grade screws. Most people only need hobbyist-grade screws, or construction-grade screws. The requirements depend on their usage and it is up to the consumer to correctly identify their requirements and use the appropriate product that is fit for purpose.

The problem with software today is the rampant, careless usage of hobbyist-grade dependencies in critical software. It is the fault of the entities including dependencies that are explicitly hobbyist-grade or inadequate for purpose that poses a problem. It should not be the responsibility of makers of hobbyist-grade screws to produce aircraft-grade screws because the aircraft makers want to go to Home Depot and pick out whatever screw is the cheapest.

The solution that matters today is holding the consumers of these endless software dependencies to task for the usage of substandard or even defective software components, whether open source or proprietary, like every other industry where you must use suppliers that are fit for purpose. To demand a change to the software that is explicitly marked as unfit for purpose is to solve the problem of a aircraft manufacturer using screws from Home Depot by making Home Depot required to only stock aircraft-grade screws while demanding they keep the prices the same.

Post reply on HN