Live data from Hacker News

'Securing Open Source Software Act' introduced to US Senate

hsgac.senate.gov

71–80 of 187 posts

Re: 'Securing Open Source Software Act' introduced to US Senate

#71
post #2

So will they help fund the projects now, or will they just express their opinions on how your unpaid work should be done?

Without the text of the bill should show up here eventually: https://www.congress.gov/bill/117th-congress/senate-bill/491...

There's no way to actually know. Everything not based on the text of the bill is pure speculation.

Re: 'Securing Open Source Software Act' introduced to US Senate

#72
https://news.ycombinator.com/item?id=32956218#32957137

> FWIW, while this specific act may not be enforcing significant regulation, software developers need to understand that there's a ticking clock.

There are several initiatives from LF's OpenSSF and startup Chainguard.

Sept 2022, "Concise Guide for Evaluating Open-Source Software", https://github.com/ossf/wg-best-practices-os-developers/blob...

Sept 2022, "Show off your Security Score: Announcing Scorecards Badges", https://openssf.org/blog/2022/09/08/show-off-your-security-s...

Re: 'Securing Open Source Software Act' introduced to US Senate

#73
post #32

Seems like they are taking the right approach. Instead of trying to regulate OSS, they're funding CISA to help make it more secure.

What will the CISA actually do?

It turns taxpayer money into individually owned Teslas.

Joking aside, they do actually have a github: https://github.com/cisagov

Re: 'Securing Open Source Software Act' introduced to US Senate

#74

Reading the comments so far, I'm genuinely surprised that more folks haven't applied a "follow the money" lens to their analysis. To me, it reads as a bald-faced attempt to discourage public sector entities from using OSS solutions, when in fact there are perfectly good and definitely >100% secure proprietary offerings that cost a reasonable amount when purchased from the sorts of vendors that pay lobbyists to "help"…

If they were really trying to secure the code, shouldn't the bill be called the "Securing Software Act"?

It's not like closed source software is magically immune to vulnerabilities

Re: 'Securing Open Source Software Act' introduced to US Senate

#75
This is not a push for proprietary software. It's a prelude to regulatory capture where a bunch of highly paid consultants will need to bless your open source solution for big money.

It's going to be like electrical contracting. You get someone cheap to do the wiring and then a union guy comes in to sign the papers and take a pound of flesh.

Re: 'Securing Open Source Software Act' introduced to US Senate

#76
post #74

Reading the comments so far, I'm genuinely surprised that more folks haven't applied a "follow the money" lens to their analysis. To me, it reads as a bald-faced attempt to discourage public sector entities from using OSS solutions, when in fact there are perfectly good and definitely >100% secure proprietary offerings that cost a reasonable amount when purchased from the sorts of vendors that pay lobbyists to "help"…

If they were really trying to secure the code, shouldn't the bill be called the "Securing Software Act"? It's not like closed source software is magically immune to vulnerabilities

They'll change the name as soon as FOSS developers spend millions to hire lobbyists.

Re: 'Securing Open Source Software Act' introduced to US Senate

#77

Reading the comments so far, I'm genuinely surprised that more folks haven't applied a "follow the money" lens to their analysis. To me, it reads as a bald-faced attempt to discourage public sector entities from using OSS solutions, when in fact there are perfectly good and definitely >100% secure proprietary offerings that cost a reasonable amount when purchased from the sorts of vendors that pay lobbyists to "help"…

Ehh, I don't disagree with where you start but I do with where you end. If it is a money thing then it probably has more to do setting up "standards" and "compliance" requirements that you must me to use FOSS software in the government. Then federal contractors and other big FOSS organizations repackage their existing solution as "Government ISO-MITRE, PCI, Whatever-BS-Acronym-we-can-come-up-with" compliant and charg…

These corporate sponsored legislators are really good at writing policy that sounds good to the public but really helps their corporate sponsor's bottom lines in practice. This bill wouldn't exist if it wasn't designed by large corporate software firms looking to taint, or profit from, FOSS in some way.

Re: 'Securing Open Source Software Act' introduced to US Senate

#78

This is not a push for proprietary software. It's a prelude to regulatory capture where a bunch of highly paid consultants will need to bless your open source solution for big money. It's going to be like electrical contracting. You get someone cheap to do the wiring and then a union guy comes in to sign the papers and take a pound of flesh.

Maybe, if electrical contracting used blockchains like sigstore, https://www.sigstore.dev/ from OpenSSF, https://openssf.org.

Re: 'Securing Open Source Software Act' introduced to US Senate

#79
DHS (Dept. of Homeland Security) CISA (Cybersecurity and Infrastructure Security Agency) CSAC (Cybersecurity Advisory Committee) TAC (Technical Advisory Council) subcommittee report, June 2022, https://www.cisa.gov/sites/default/files/publications/June%2...

> The Technical Advisory Council Subcommittee was established to leverage the imagination, ingenuity, and talents of technical experts from diverse background and experiences for the good of the nation. The subcommittee was asked to evaluate and make recommendations tactical and strategic in nature. These Cybersecurity Advisory Committee (CSAC) recommendations for the June Quarterly Meeting focus on vulnerability discovery and disclosure.

  Mr. Jeff Moss, Subcommittee Chair, DEF CON Communications 
  Mr. Dino Dai Zovi, Security Researcher
  Mr. Luiz Eduardo, Aruba Threat Labs
  Mr. Isiah Jones, National Resilience Inc.
  Mr. Kurt Opsahl, Electronic Frontier Foundation 
  Ms. Runa Sandvik, Security Researcher
  Mr. Yan Shoshitaishvili, Arizona State University 
  Ms. Rachel Tobac, SocialProof Security
  Mr. David Weston, Microsoft
  Mr. Bill Woodcock, Packet Clearing House 
  Ms. Yan Zhu, Brave Software

Re: 'Securing Open Source Software Act' introduced to US Senate

#80
post #52

Earlier quoted context omitted.

They're gonna get enshrined into law eventually one way or the other. If we do it ourselves and we're effective at limiting the damage we cause we'll be able to maintain control over our own processes. If we don't it will be taken out of our hands.

> If we don't it will be taken out of our hands. Which will take the code out of theirs. Disincentivize sharing, and sharing goes away.

> Disincentivize sharing, and sharing goes away.

And existing proprietary software companies will rejoice, as the barrier to entry in the software market will again be very high.

Post reply on HN