Switzerland now requires all government software to be open source
1–10 of 44 posts
Re: Switzerland now requires all government software to be open source
#2Governments not knowing what their software is doing is a recipe for chaos.
Hopefully this also leads to more audits of said code.
Re: Switzerland now requires all government software to be open source
#3Re: Switzerland now requires all government software to be open source
#4Re: Switzerland now requires all government software to be open source
#5I have tried several times to get Node.js into the military on approved software lists for internal development and its a huge struggle. I suspect the main culprits are due to valid security concerns regarding package managers like NPM and old ignorant thinking about open source being either immature or open software being a wide open exploitation vector. That is really tough because there aren't official binaries of Node without NPM and ignorant thinking about open source is really persistent.
Re: Switzerland now requires all government software to be open source
#6https://opensource.com/government/12/8/brazil-forefront-open...
Re: Switzerland now requires all government software to be open source
#7This is really smart, and I hope this becomes the norm across all governments. Governments not knowing what their software is doing is a recipe for chaos. Hopefully this also leads to more audits of said code.
The xz fiasco earlier this year should encourage every organization to conduct such audits. A code smell could and should be enough for packages to not be supported.
Re: Switzerland now requires all government software to be open source
#8The US government, especially the military, is largely allergic to software. This is slowly starting to change, but only in small pockets. I am aware of three software teams in the military but they are highly specialized with small dedicated customers. I have tried several times to get Node.js into the military on approved software lists for internal development and its a huge struggle. I suspect the main culprits a…
A lot of the supply chain failures I can think of, were open source projects.
I’m not saying node or OSS has no place, but there is more than something to do t being a security issue.
How many years was heartbleed exploitable despite “all the eyes on it”?
The good part about OSS is all the people that can review it, the bad part is all the people that can review it. Now… which one is more incentivized today ignoring a future military use?
It only works when assets are put into hardening existing code.
Re: Switzerland now requires all government software to be open source
#9Regarding the "Several European countries are betting on open-source software for their technology. In the United States, eh, not so much." I thought software developed by the US govt is public domain? At least that's how I remember sqlite got it's license because it was developed for the US Navy.
[0] https://fosdem.org/2024/schedule/event/fosdem-2024-3401-the-...