Live data from Hacker News

'Securing Open Source Software Act' introduced to US Senate

hsgac.senate.gov

101–110 of 187 posts

Re: 'Securing Open Source Software Act' introduced to US Senate

#101
post #95

This is not a push for proprietary software. It's a prelude to regulatory capture where a bunch of highly paid consultants will need to bless your open source solution for big money. It's going to be like electrical contracting. You get someone cheap to do the wiring and then a union guy comes in to sign the papers and take a pound of flesh.

We already have this. You hire some idiot to sign off on your FIPS-140. They are getting paid under the table by IBM. They swear that the only way to comply with FIPS-140 is to use RHEL. The only company I ever worked at that hasn't fallen for this scam is Google, who self-certify everything including their crypto stack. But every other smaller company (i.e. all other companies) are just terrified of not getting gove…

FIPS validation does not have a self certify path

Re: 'Securing Open Source Software Act' introduced to US Senate

#102
Well I've just had the weekly "why can't you come here" call with my forign gf, failed to deliver on the couple tickets I have open at work, and posted my daily "barf into ~/stuff/*.c" to /prog/ so lets go through and read this instead of going and being with people.

TFA has no bill number so lets see if we can find it. Actually no, I'm not seeing it. Someone send me an HR? I'll update my comment if you do.

Re: 'Securing Open Source Software Act' introduced to US Senate

#103

Earlier quoted context omitted.

While skepticism is fair that should be motivation to do research to possibly find evidence of an ulterior motive. However just saying that all legislation is some scam without evidence doesn't make sense. For example, and I don't know the exact name, but the health care transparency act where pricing for treatments or whatever must be published. Who is that helping if you follow the money? Edit: I should have been m…

Maybe increased popularity to the legislator in question? Surely no bill comes without some ulterior motive.

Increased popularity isn't an ulterior (meaning hidden) motive, it's explicitly the foundation for democracy. The whole premise is that we exploit human selfishness for net good by setting up a system that (in theory) rewards making the largest number of people happy. There's nothing ulterior about that motive, it's the point.

Where things go wrong is when money becomes involved, because then the system rewards making the wealthiest people happy, not the largest number. That's an ulterior motive.

Re: 'Securing Open Source Software Act' introduced to US Senate

#104
"securing open source software act" would rationally mean funding the NSA or similar experts to help harden open source software, right? Or, hey, telling the NSA to disclose vulnerabilities they find in open source software so they can be patched, instead of sitting on them hoping nobody else notices. Right? No? Wait, what? It's just about telling the federal government to use less open source software? How does that make open source software more secure?

Re: 'Securing Open Source Software Act' introduced to US Senate

#105

"securing open source software act" would rationally mean funding the NSA or similar experts to help harden open source software, right? Or, hey, telling the NSA to disclose vulnerabilities they find in open source software so they can be patched, instead of sitting on them hoping nobody else notices. Right? No? Wait, what? It's just about telling the federal government to use less open source software? How does that…

A good move would be increasing funding for defensive security teams at NSA, especially those working on open-source software, and restoring the separation of governance/leadership between defensive and offensive security teams.

Re: 'Securing Open Source Software Act' introduced to US Senate

#106

Earlier quoted context omitted.

Of course, which is why I think viewing this as a push for proprietary software is not a fair assessment. Increasing your company's development costs is not a way to make more profit. The point of this is that you can't treat proprietary software dependencies the same way you treat FOSS. Community FOSS projects just don't have the same development process and governance model that proprietary software does. And so, t…

Respectfully, you have a too-reasonable hunch of how decisions are made at the executive level, and because of that, you're reaching an incorrect conclusion. The primary factor driving the decision making process is not cost but risk. Many fail to remember the lengths to which companies like Microsoft, Oracle, Sun and others went to create FUD around the adoption of OSS in the public sector. It involved lobbyists, ma…

Government contractors expensive tools are already heavily using open source tools. The whole log4j scandal that this bill is in response to is perfect evidence of exactly that.

It is not in the interest of 'proprietary' software vendors to fearmonger about OSS libraries. They too use OSS libraries just like everyone else does today.

It isn't 1995 anymore where a proprietary piece of software can run on a full stack of code written by the people who work locked away in a single building at one company. Everyone is using open source dependencies. There is nobody left that would benefit by demonizing open source libraries.

Re: 'Securing Open Source Software Act' introduced to US Senate

#107
post #97
post #96

We do B2B software in banking and this is something we've been anticipating for quite some time now. We were implicated in that log4j exploit via a (very) transitive, cross-language dependency. We killed 100% of our Java usage over this. We simply don't have enough in-house talent to make sure things are safe in that bucket. Our customers thought this was a glorious plan as well. I do think most of the pain should fa…

You ditched all java over a single bug? That seems extreme..... Did you ditch ssl over heartbleed?

> You ditched all java over a single bug?

A bug in a third-party dependency, no less.

Re: 'Securing Open Source Software Act' introduced to US Senate

#108

Earlier quoted context omitted.

Of course, which is why I think viewing this as a push for proprietary software is not a fair assessment. Increasing your company's development costs is not a way to make more profit. The point of this is that you can't treat proprietary software dependencies the same way you treat FOSS. Community FOSS projects just don't have the same development process and governance model that proprietary software does. And so, t…

> process and governance model that proprietary software does. except that a lot of proprietary software doesn't has anything like that either there is nothing in common proprietary dev practices which would have e.g. prevented log4j the main difference is that you can hold someone financially responsible in one case and not in the other (but in turn you can always fix any problem yourself, good luck fixing any propr…

It does when you sell it to the government, which is what this is about.

The federal government has rules regarding the acquisition of software products, and they have various governance and risk management requirements for various scenarios. Many of these were designed with proprietary software in mind.

The point of this bill is to update some of those requirements to make sense with the way OSS works.

Re: 'Securing Open Source Software Act' introduced to US Senate

#109
post #57

Earlier quoted context omitted.

> Why is it that there is no standard applied to those who publish code for distribution purposes? Because it's rude to make demands of someone who is doing you a favor. Because a system that adds costs to profit-free work will collapse. Because your "distribution" line-in-the-sand doesn't exist. I assume you're thinking of NPM or pypi, but ex. Debian doesn't ask people before including their packages, and ex. nixos…

> Debian doesn't ask people before including their packages, and ex. nixos pulls directly from those "non-distribution" channels. Then Debian (or NixOS) are publishing the code for distribution, and Debian (or NixOS) should be morally obligated to do the bare minimum to make the code acceptable for others to use.

no

Re: 'Securing Open Source Software Act' introduced to US Senate

#110
post #97
post #96

We do B2B software in banking and this is something we've been anticipating for quite some time now. We were implicated in that log4j exploit via a (very) transitive, cross-language dependency. We killed 100% of our Java usage over this. We simply don't have enough in-house talent to make sure things are safe in that bucket. Our customers thought this was a glorious plan as well. I do think most of the pain should fa…

You ditched all java over a single bug? That seems extreme..... Did you ditch ssl over heartbleed?

At the time, Java accounted for <1% of our codebase/product, so it made sense to do so.
Post reply on HN