Reading the comments so far, I'm genuinely surprised that more folks haven't applied a "follow the money" lens to their analysis. To me, it reads as a bald-faced attempt to discourage public sector entities from using OSS solutions, when in fact there are perfectly good and definitely >100% secure proprietary offerings that cost a reasonable amount when purchased from the sorts of vendors that pay lobbyists to "help"…
If they were really trying to secure the code, shouldn't the bill be called the "Securing Software Act"? It's not like closed source software is magically immune to vulnerabilities
'Securing Open Source Software Act' introduced to US Senate
131–140 of 187 posts
Re: 'Securing Open Source Software Act' introduced to US Senate
#132Earlier quoted context omitted.
Different types of issues with different solutions. When you have a support contract with the original developer of a piece of code, you can demand the original developer fix the code.
That same solution still works for FOSS, you just actually need to pay for it. The situation for FOSS is even better because you also have the option of paying any other person to fix the code. Hopefully that's kinda what this bill does, though?
FOSS usually does not have warrantees, SLAs, or developers in particular locations with particular credentials. The government has processes that they must follow for paying contractors, so “just pay them” is not something that can easily be done last minute, (and sometimes, not at all without a literal act of Congress.) Also the financial and obligatory relationship between them and the developer is much different, and must be managed differently.
Really, it is very important for people doing technology projects at the government to understand the difference between calling up the developer of Windows and calling up the developer of Git. Those are two very different relationships.
Re: 'Securing Open Source Software Act' introduced to US Senate
#133For those curious about what it actually is: > The Securing Open Source Software Act would direct CISA to develop a risk framework to evaluate how open source code is used by the federal government. CISA would also evaluate how the same framework could be voluntarily used by critical infrastructure owners and operators. This will identify ways to mitigate risks in systems that use open source software. The legislatio…
"Oh, great, more STIGs." How about they take some millions and PAY THE OSS PROJECTS?
Re: 'Securing Open Source Software Act' introduced to US Senate
#134Earlier quoted context omitted.
> Federal contractors don't need to sell proprietary software to make money -- they make more money selling FOSS software. tech companies in general are making billions using FOSS.
Of course, which is why I think viewing this as a push for proprietary software is not a fair assessment. Increasing your company's development costs is not a way to make more profit. The point of this is that you can't treat proprietary software dependencies the same way you treat FOSS. Community FOSS projects just don't have the same development process and governance model that proprietary software does. And so, t…
Re: 'Securing Open Source Software Act' introduced to US Senate
#135Earlier quoted context omitted.
Of course, which is why I think viewing this as a push for proprietary software is not a fair assessment. Increasing your company's development costs is not a way to make more profit. The point of this is that you can't treat proprietary software dependencies the same way you treat FOSS. Community FOSS projects just don't have the same development process and governance model that proprietary software does. And so, t…
That’s assuming these individuals aim to make profit for their entity. The risk raised above was corruption, with tax paid development cost going to their uncles company, with a big fat kickback under the table.
The root comment suggested that somehow this was a smear on FOSS, intended to sell more proprietary software. However, this doesn’t hold up, because FOSS components are widely used by all of the big proprietary software vendors in this space too.
Re: 'Securing Open Source Software Act' introduced to US Senate
#136LF OpenSSF "criticality score" for 100K Github repos, https://github.com/ossf/criticality_score & https://docs.google.com/spreadsheets/d/1uahUIUa82J6WetAqtxCM... > Generate a criticality score for every open source project. Create a list of critical projects that the open source community depends on. Use this data to proactively improve the security posture of these critical projects ... A project's criticality score…
Re: 'Securing Open Source Software Act' introduced to US Senate
#137Earlier quoted context omitted.
I think a lot of people will disagree, which is cool and I'm fine with that but I do hope that this discussion can be had. > The problem is that somewhere someone who is supposed to be held to some standard decided to pull that code in without looking at it Why is it that there is no standard applied to those who publish code for distribution purposes? Why do we want that to be the case? Again, publishing to Github o…
Do you demand that every screwmaker make aircraft-grade screws? Aircraft makers need screws and it would be very convenient to them to be able to go down to any hardware store and just buy whatever screw they want since they are all up to spec. No need to evaluate their suppliers since everybody is required to make things up to their demanding standards. The problem with this is that not everybody needs expensive air…
I'm not suggesting that software developers be required to do anything if they're just writing code, and I'm not suggesting that they do things to some sort of extreme, as you seem to be implying, if they do distribute their code for use.
> explicitly hobbyist-grade or inadequate for purpose that poses a problem
Well, no, they're not explicitly hobbyist-grade. That would be fine if someone were just publishing code and saying "don't use this", but they are publishing code for distribution to package repositories. They don't have to do that, they could just leave it as open source code that isn't distributed, and note that it's not production quality explicitly as you suggest.
Perhaps a more appropriate analogy would be if you were making dinner. You go to the farmer's market and someone with a booth their says "I'm giving away some free fruit, here you go". You would hope that someone who set up a stand at the market would be giving you fruit that's edible. If you went home and ate it, and then you got sick because it didn't meet food quality standards, you would not be the one liable, the vendor would be. "But the vendor gave it away for free!" Yes, but other than software the person giving you something is in fact liable for its quality.
Anyway, analogies suck, I'm sure this misses plenty of important bits. Rather than argue about analogies, let's clarify the actual argument.
1. No one forces anyone to publish their code for distribution purposes
2. When you publish code with the intent for others to use it there should be an obligation to provide basic quality standards to avoid that code doing others harm
Re: 'Securing Open Source Software Act' introduced to US Senate
#138Earlier quoted context omitted.
That same solution still works for FOSS, you just actually need to pay for it. The situation for FOSS is even better because you also have the option of paying any other person to fix the code. Hopefully that's kinda what this bill does, though?
It’s “the same” in a really broad hand-wavy sort of way. It’s not the same practically speaking. FOSS usually does not have warrantees, SLAs, or developers in particular locations with particular credentials. The government has processes that they must follow for paying contractors, so “just pay them” is not something that can easily be done last minute, (and sometimes, not at all without a literal act of Congress.)…
Finding out that you have a problem when you don't have a support contract and then looking around for someone to work on the thing is not the same thing as having a support contract, although in some cases it can be a sufficient substitute and it's certainly cheaper in the best case (like any other form of skipping insurance).
Depending on context, providing the "support contract" internally is also an option.
Re: 'Securing Open Source Software Act' introduced to US Senate
#139Reading the comments so far, I'm genuinely surprised that more folks haven't applied a "follow the money" lens to their analysis. To me, it reads as a bald-faced attempt to discourage public sector entities from using OSS solutions, when in fact there are perfectly good and definitely >100% secure proprietary offerings that cost a reasonable amount when purchased from the sorts of vendors that pay lobbyists to "help"…
Holy shit this is a terrible idea. I can’t think of a better way to discourage people from using open source than to punish organizations for “not making meaningful contributions” to it. As a heavy open source user, contributor, and author, I’m begging you to stay the fuck away from regulating users. That’s the fastest way to destroy open source.
Re: 'Securing Open Source Software Act' introduced to US Senate
#140Earlier quoted context omitted.
Ehh, I don't disagree with where you start but I do with where you end. If it is a money thing then it probably has more to do setting up "standards" and "compliance" requirements that you must me to use FOSS software in the government. Then federal contractors and other big FOSS organizations repackage their existing solution as "Government ISO-MITRE, PCI, Whatever-BS-Acronym-we-can-come-up-with" compliant and charg…
These corporate sponsored legislators are really good at writing policy that sounds good to the public but really helps their corporate sponsor's bottom lines in practice. This bill wouldn't exist if it wasn't designed by large corporate software firms looking to taint, or profit from, FOSS in some way.