Live data from Hacker News

'Securing Open Source Software Act' introduced to US Senate

hsgac.senate.gov

121–130 of 187 posts

Re: 'Securing Open Source Software Act' introduced to US Senate

#121

Reading the comments so far, I'm genuinely surprised that more folks haven't applied a "follow the money" lens to their analysis. To me, it reads as a bald-faced attempt to discourage public sector entities from using OSS solutions, when in fact there are perfectly good and definitely >100% secure proprietary offerings that cost a reasonable amount when purchased from the sorts of vendors that pay lobbyists to "help"…

They're trying to destroy FOSS ...by hiring FOSS developers? I don't buy it. More like, log4j was an actual real big issue for government agencies because they use rely on tons of open source projects and haven't previously done much to make sure that that supply chain is robust. This would help to change that. Federal contractors don't need to sell proprietary software to make money -- they make more money selling F…

> haven't previously done much to make sure that that supply chain is robust

I'm doubtful that anything short of requiring thorough security/pen testing on everything in the dependency tree would have prevented log4shell. And if that is the goal here, who is going to pay for that? Most open source projects don't have that kind of funding.

Re: 'Securing Open Source Software Act' introduced to US Senate

#122
post #116

Earlier quoted context omitted.

Unless it specifies who this just means they'll throw a few billion to Teksystems, CGI or whoever and then say that it was a failure like HealthCare.gov

That spawned a lot of good things. Check out 18F and USDS.

There are special exceptions, but definitely not the norm.

Re: 'Securing Open Source Software Act' introduced to US Senate

#123

For those curious about what it actually is: > The Securing Open Source Software Act would direct CISA to develop a risk framework to evaluate how open source code is used by the federal government. CISA would also evaluate how the same framework could be voluntarily used by critical infrastructure owners and operators. This will identify ways to mitigate risks in systems that use open source software. The legislatio…

I'm really curious how this would have protected the government from log4shell. Log4j is (or at least was) one of the more reputable open source projects.

This kind of feels like doing something for the sake of doing something about log4shell, without actually solving any problems. And will undoubtedly result in the government paying more taxpayer dollars for software that complies with this new framework.

Re: 'Securing Open Source Software Act' introduced to US Senate

#124

Earlier quoted context omitted.

I think a lot of people will disagree, which is cool and I'm fine with that but I do hope that this discussion can be had. > The problem is that somewhere someone who is supposed to be held to some standard decided to pull that code in without looking at it Why is it that there is no standard applied to those who publish code for distribution purposes? Why do we want that to be the case? Again, publishing to Github o…

> Why is it that there is no standard applied to those who publish code for distribution purposes? Because it's rude to make demands of someone who is doing you a favor. Because a system that adds costs to profit-free work will collapse. Because your "distribution" line-in-the-sand doesn't exist. I assume you're thinking of NPM or pypi, but ex. Debian doesn't ask people before including their packages, and ex. nixos…

> Because your "distribution" line-in-the-sand doesn't exist. I assume you're thinking of NPM or pypi, but ex. Debian doesn't ask people before including their packages, and ex. nixos pulls directly from those "non-distribution" channels.

Correct, I'm talking about publishing to a package index. The fact that the line is murky right now isn't important, that's exactly the sort of thing we should be clarifying and changing.

> Okay; let's also make a moral standard of paying people when we derive value from their work. I think it should be perfectly fine for us to say "did you do the bare minimum to repay the person who gave you this code to use?".

I don't think it's an "either/or" situation, the two are not exclusive. I would like to see more funding for open source software, but that doesn't solve the fundamental issue. It's also extremely hand-wavy. Do I pay you a monthly stipend to implement 2FA?

It also assumes that open source developers aren't getting "paid". They are. Github is free, PyPI is free. You are using services for free, that is a form of payment, or at least a social contract between various developers. So it should be reasonable then to negotiate that contract, eg: PyPI saying "if you use us as a distributor of your code, we need you to enable 2FA", which they now do.

> We do that because we benefit.

Who's we? Because a lot of people don't benefit. When there's a supply chain compromise because a developer used a weak password and no 2FA people are harmed.

> We'd like people to keep giving things away even though they don't have to. If you try to impose costs on them for doing that, you'll alter the incentives so that they do the rational thing and stop giving stuff away, and/or start charging for it.

Of course, and I'd like to keep those incentives as much as possible. I think there is a very happy medium here that isn't strictly "if I publish open source code for distribution I can do no wrong whatsoever, I have no obligations whatsoever". PyPI and other distributors now enforce that if your code gets to be very popular you must enable 2FA. That is a cost, but it's a very minimal cost targeted to a small group.

What I'm advocating for is that we standardize a set of responsibilities as an industry for those who distribute code. They can be very minimal and still have massive impact.

The alternative, in my opinion, is that we'll see increased regulation, because these problems aren't going away and they're going to get worse if we don't collectively try to improve.

Re: 'Securing Open Source Software Act' introduced to US Senate

#125
Why the focus on open source?

The reason log4shell had such a big impact is because of how ubiquitous it was. Sure being free gives OSS a bit of an advantage in becoming ubiquitous, especially as a library.

But there's also plenty of proprietary software that is ubiquitous as well. And proprietary software has plenty of bad security bugs too.

Re: 'Securing Open Source Software Act' introduced to US Senate

#126
post #121

Earlier quoted context omitted.

They're trying to destroy FOSS ...by hiring FOSS developers? I don't buy it. More like, log4j was an actual real big issue for government agencies because they use rely on tons of open source projects and haven't previously done much to make sure that that supply chain is robust. This would help to change that. Federal contractors don't need to sell proprietary software to make money -- they make more money selling F…

> haven't previously done much to make sure that that supply chain is robust I'm doubtful that anything short of requiring thorough security/pen testing on everything in the dependency tree would have prevented log4shell. And if that is the goal here, who is going to pay for that? Most open source projects don't have that kind of funding.

> everything in the dependency tree

With reasonable prioritization, we can probably do a lot to reduce the threat long before we get near everything.

> who is going to pay for that?

Well, this bill does seem to involve hiring FOSS devs, maybe that's partly what they'd do?

Re: 'Securing Open Source Software Act' introduced to US Senate

#127

Earlier quoted context omitted.

More or less of a big issue than the revolving door of Microsoft bugs?

Different types of issues with different solutions. When you have a support contract with the original developer of a piece of code, you can demand the original developer fix the code.

That same solution still works for FOSS, you just actually need to pay for it. The situation for FOSS is even better because you also have the option of paying any other person to fix the code. Hopefully that's kinda what this bill does, though?

Re: 'Securing Open Source Software Act' introduced to US Senate

#128
There's a funny bite here that seems long-term good.

The gov has a large culture of tapping integrators who do not give back to OSS, just use, basically the middle man, and leave behind fragile one-offs. Such abandonware should overwhelm recieving depts within 6-12mo, and bringing back integrators for the treadmill of patching superfluous npm CVEs would break their budgets.

So that means pressure to, well, not do that. Either the integrators get more involved, or part of the budgets finally goes to people who are.

Re: 'Securing Open Source Software Act' introduced to US Senate

#129
So… I’m reading this from the perspective of working 100% professionally on open source software and I don’t understand at all what implications this has for my work being declared public infrastructure. I don’t think it’s being funded, which I guess isn’t surprising because not funding infrastructure is literally a meme which has been going for years. I don’t think anything is being offered to help secure the software I work on. It kind of reads like a vague threat? I don’t mean to be glib at all, but if you’re declaring something public infrastructure and you’re ostensibly a public servant, maybe making me feel scared of you isn’t a great look?

Re: 'Securing Open Source Software Act' introduced to US Senate

#130

Earlier quoted context omitted.

No the people hired will be IBM consultants and such with long lists of meaningless qualifications and no GitHub profile.

No the people hired will be IBM consultants and such with long lists of meaningless qualifications and no MicroSoft profile.

Oh no, they’ll have all the Microsoft certifications too.
Post reply on HN