• Home
  • Privacy Policy
Breaking News, US News, World News and Bollywood News
  • Home
  • Technology
    Microsoft previews Edge Developer Tools for Visual Studio

    How to deploy with Vercel and MongoDB Atlas without even trying

    Uno Platform advances WebAssembly support

    Uno Platform advances WebAssembly support

    Traditional architecture still has a place in the cloud

    Traditional architecture still has a place in the cloud

    What is Flutter? Mobile app development for Android, iOS, and more

    What is Flutter? Mobile app development for Android, iOS, and more

    Choosing your Java IDE | InfoWorld

    Choosing your Java IDE | InfoWorld

    8 great new JavaScript language features in ES12

    The best new features in .NET 6

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Entertainment
    Wordle 380 July 4 daily hints: Can’t solve today’s Wordle? Three clues to help with answer | Gaming | Entertainment

    Wordle 380 July 4 daily hints: Can’t solve today’s Wordle? Three clues to help with answer | Gaming | Entertainment

    Jenny Agutter returns for Railway Children sequel 52 years later | Films | Entertainment

    Jenny Agutter returns for Railway Children sequel 52 years later | Films | Entertainment

    Chainsaw Man anime release date reveal and trailer 2 TOMORROW? | Gaming | Entertainment

    Chainsaw Man anime release date reveal and trailer 2 TOMORROW? | Gaming | Entertainment

    James Bond secrets: The bizarre way Sean Connery prepared himself for 007 love scenes | Films | Entertainment

    James Bond secrets: The bizarre way Sean Connery prepared himself for 007 love scenes | Films | Entertainment

    Guns N’ Roses review: Pain and glory at Tottenham stadium | Music | Entertainment

    Guns N’ Roses review: Pain and glory at Tottenham stadium | Music | Entertainment

    Roger Moore named his favourite Bond girl who then helped another star try and replace him | Films | Entertainment

    Roger Moore named his favourite Bond girl who then helped another star try and replace him | Films | Entertainment

    Trending Tags

      • Bollywood
      • Hollywood
      • Music
    • Lifestyle
      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      How often to water hydrangeas – why healthy growth means watering LESS

      How often to water hydrangeas – why healthy growth means watering LESS

      Gardeners urged to ‘know the plants’ before cross-pollinating – expert explains why

      Gardeners urged to ‘know the plants’ before cross-pollinating – expert explains why

      Key times you should NOT cut your grass – prevent ‘serious’ lawn harm

      Key times you should NOT cut your grass – prevent ‘serious’ lawn harm

      ‘Essential’ tip for a ‘booster harvest’ from pear trees – ‘no tree will thrive without’ it

      ‘Essential’ tip for a ‘booster harvest’ from pear trees – ‘no tree will thrive without’ it

      Lawn care: ‘Effective’ methods for removing weeds to achieve a ‘weed-free’ lawn for good

      Lawn care: ‘Effective’ methods for removing weeds to achieve a ‘weed-free’ lawn for good

      Trending Tags

      • Golden Globes
      • Game of Thrones
      • MotoGP 2017
      • eSports
      • Fashion Week
    • Nature
    • Business
    • Health
      • Food
    • Fashion
    • Science
    • Sports
    • Travel
    • World News
    No Result
    View All Result
    • Home
    • Technology
      Microsoft previews Edge Developer Tools for Visual Studio

      How to deploy with Vercel and MongoDB Atlas without even trying

      Uno Platform advances WebAssembly support

      Uno Platform advances WebAssembly support

      Traditional architecture still has a place in the cloud

      Traditional architecture still has a place in the cloud

      What is Flutter? Mobile app development for Android, iOS, and more

      What is Flutter? Mobile app development for Android, iOS, and more

      Choosing your Java IDE | InfoWorld

      Choosing your Java IDE | InfoWorld

      8 great new JavaScript language features in ES12

      The best new features in .NET 6

      Trending Tags

      • Nintendo Switch
      • CES 2017
      • Playstation 4 Pro
      • Mark Zuckerberg
    • Entertainment
      Wordle 380 July 4 daily hints: Can’t solve today’s Wordle? Three clues to help with answer | Gaming | Entertainment

      Wordle 380 July 4 daily hints: Can’t solve today’s Wordle? Three clues to help with answer | Gaming | Entertainment

      Jenny Agutter returns for Railway Children sequel 52 years later | Films | Entertainment

      Jenny Agutter returns for Railway Children sequel 52 years later | Films | Entertainment

      Chainsaw Man anime release date reveal and trailer 2 TOMORROW? | Gaming | Entertainment

      Chainsaw Man anime release date reveal and trailer 2 TOMORROW? | Gaming | Entertainment

      James Bond secrets: The bizarre way Sean Connery prepared himself for 007 love scenes | Films | Entertainment

      James Bond secrets: The bizarre way Sean Connery prepared himself for 007 love scenes | Films | Entertainment

      Guns N’ Roses review: Pain and glory at Tottenham stadium | Music | Entertainment

      Guns N’ Roses review: Pain and glory at Tottenham stadium | Music | Entertainment

      Roger Moore named his favourite Bond girl who then helped another star try and replace him | Films | Entertainment

      Roger Moore named his favourite Bond girl who then helped another star try and replace him | Films | Entertainment

      Trending Tags

        • Bollywood
        • Hollywood
        • Music
      • Lifestyle
        Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

        Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

        How often to water hydrangeas – why healthy growth means watering LESS

        How often to water hydrangeas – why healthy growth means watering LESS

        Gardeners urged to ‘know the plants’ before cross-pollinating – expert explains why

        Gardeners urged to ‘know the plants’ before cross-pollinating – expert explains why

        Key times you should NOT cut your grass – prevent ‘serious’ lawn harm

        Key times you should NOT cut your grass – prevent ‘serious’ lawn harm

        ‘Essential’ tip for a ‘booster harvest’ from pear trees – ‘no tree will thrive without’ it

        ‘Essential’ tip for a ‘booster harvest’ from pear trees – ‘no tree will thrive without’ it

        Lawn care: ‘Effective’ methods for removing weeds to achieve a ‘weed-free’ lawn for good

        Lawn care: ‘Effective’ methods for removing weeds to achieve a ‘weed-free’ lawn for good

        Trending Tags

        • Golden Globes
        • Game of Thrones
        • MotoGP 2017
        • eSports
        • Fashion Week
      • Nature
      • Business
      • Health
        • Food
      • Fashion
      • Science
      • Sports
      • Travel
      • World News
      No Result
      View All Result
      Updates News
      No Result
      View All Result
      Home Technology

      More money for open source security won’t work

      admin by admin
      May 16, 2022
      in Technology
      0
      More money for open source security won’t work
      0
      SHARES
      4
      VIEWS
      Share on FacebookShare on Twitter


      Here’s the good news. According to the Open Source Security Foundation (OpenSSF), it will cost less than $150 million to secure open source software. More good news, industry giants Amazon, Intel, Google, and Microsoft have already pledged $30 million. Just $120 million to go toward a secure open source future, right?

      Well, no, because the bad news is that no generalized approach to open source security is going to work. OpenSSF has a fantastic 10-point plan to foster a multifaceted approach to security. This approach has a better chance of succeeding than the more piecemeal approaches of the past, argued Brian Behlendorf, general manager of the OpenSSF, on a recent press call, because “there’s not one root cause or one root approach that’s going to address them all.”

      He’s right, and it’s precisely why I worry that we may still be approaching open source security wrong.

      But first, the plan

      I don’t want to come across as disparaging these efforts. As I’ve written before, I’m optimistic. The OpenSSF’s attempts to rally the industry are an important upgrade on past approaches. The open source process by which we find and fix bugs is also the right way to tackle software security. The OpenSSF offers us a chance to coordinate our efforts.

      I’m heartened by OpenSSF’s 10-point plan:

      1. Offer security education for everyone working in the community
      2. Establish a risk assessment dashboard for the top open-source components
      3. Accelerate adoption of digital signatures
      4. Replace non-memory-safe languages to eliminate the root cause of many bugs
      5. Establish an open source incident response team
      6. Improve scanning of code by maintainers and experts to find bugs more quickly
      7. Conduct third-party code reviews of up to 200 of the most critical components
      8. Coordinate industrywide research data sharing
      9. Improve software bill of materials (SBOM) tools and training to drive adoption
      10. Enhance the 10 most critical build systems, package managers, and distribution systems with better security tools and best practices

      This is a smart, holistic approach to security and is yet another reason for developers to love open source. In fact, when I managed AWS’ Open Source Strategy and Marketing team, we commissioned a survey in 2020 to ask why developers like open source. Top of the list was security:

      AWS open source survey Chart courtesy of AWS

      The developers responding to this survey knew about Heartbleed and other vulnerabilities in critical open source projects. They still picked open source. Thanks to the OpenSSF’s efforts, many more developers may be able to choose open source with added comfort.

      Don’t assume this or any other funding will solve open source security problems, just as no amount of cash has made AWS, Google, or Microsoft impervious to software vulnerabilities. All software is buggy, now and forever.

      Process is better than plan

      The best guarantor of open source security has always been the open source development process. Even with OpenSSF’s excellent plan, this remains true. The plan, for example, promises to “conduct third-party code reviews of up to 200 of the most critical components.” That’s great! But guess what makes something a “critical component”? That’s right—a security breach that roils the industry. Ditto “establishing a risk assessment dashboard for the top open source components.” If we were good at deciding in advance which open source components are the top ones, we’d have fewer security vulnerabilities because we’d find ways to fund them so that the developers involved could better care for their own security.

      Of course, often the developers responsible for “top open source components” don’t want a full-time job securing their software. It varies greatly between projects, but the developers involved tend to have very different motivations for their involvement. No one-size-fits-all approach to funding open source development works (though I continue to feel that the most sustainable open source has significant corporate involvement, whether from a community (Kubernetes) or a single company (MySQL/Oracle).

      It’s also the case that hackers tend to be incredibly innovative in how they expose gaps in proprietary and open source software. It’s a virtual guarantee that they’re currently burrowing into components no one thinks are “critical” or “top” today but will become so when the software is compromised.

      This is why I prefer the “meta” approaches in the 10-point plan, like replacing non-memory-safe languages (with things like Rust) or adopting digital signatures. These help build security into a project while deferring to the development process to fix bugs when discovered.

      Let’s remember: As open source has grown in popularity, bugs have proliferated as WhiteSource and other firms have detailed. Think about that: The universe of open source code is expanding at a dramatic rate, and vulnerabilities have expanded in parallel. Identifying all those critical components in advance is a monumental and perhaps impossible task.

      So, is the 10-point plan a waste? No. Not at all. But I worry that we’ll dupe ourselves into believing that $150 million is going to buy us open source security once and for all. It won’t. Even if it secured today’s components, we’d still need to have the industry upgrade old systems running older, less secure “critical open source components.” Hence, the only way for open source security to become real is for each individual project to take up the burden of security and take it very seriously, with each user of that project also taking it very seriously. The OpenSSF won’t deliver this for everyone, but if it helps, it’s $150 million well spent.

      Copyright © 2022 IDG Communications, Inc.



      Source link

      admin

      admin

      • Trending
      • Comments
      • Latest
      UK’s most dangerous plant: Father’s warning — ‘Never seen a child so badly burned’ | Science | News

      UK’s most dangerous plant: Father’s warning — ‘Never seen a child so badly burned’ | Science | News

      June 6, 2022
      Plant warning as bamboo causes £100,000 of damage to Hampshire property

      Plant warning as bamboo causes £100,000 of damage to Hampshire property

      January 31, 2022
      Social workers warned weeks before baby Mitchell died in 2019 | TV & Radio | Showbiz & TV

      Social workers warned weeks before baby Mitchell died in 2019 | TV & Radio | Showbiz & TV

      January 2, 2022
      Yorkshire nan on how to make Yorkshire puddings with no ingredients weighed

      Yorkshire nan on how to make Yorkshire puddings with no ingredients weighed

      February 15, 2022
      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      0
      Boris Johnson slammed by Indie band for using their song ‘Blue Bunch Of Corrupt W****rs’ | Music | Entertainment

      Boris Johnson slammed by Indie band for using their song ‘Blue Bunch Of Corrupt W****rs’ | Music | Entertainment

      0
      Call Your Mom, Because Sue Grafton’s Alphabet Murder Mystery Books Are Becoming A Show

      Call Your Mom, Because Sue Grafton’s Alphabet Murder Mystery Books Are Becoming A Show

      0
      Release Date, Cast, And More

      Release Date, Cast, And More

      0
      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      July 4, 2022
      Iain Duncan Smith backs £15bn global masterplan to ditch EU project: ‘Will be better!’ | Science | News

      Iain Duncan Smith backs £15bn global masterplan to ditch EU project: ‘Will be better!’ | Science | News

      July 4, 2022
      Wordle 380 July 4 daily hints: Can’t solve today’s Wordle? Three clues to help with answer | Gaming | Entertainment

      Wordle 380 July 4 daily hints: Can’t solve today’s Wordle? Three clues to help with answer | Gaming | Entertainment

      July 4, 2022
      31 Swimsuits for Every Style Aesthetic

      31 Swimsuits for Every Style Aesthetic

      July 4, 2022

      Recent News

      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      July 4, 2022
      Iain Duncan Smith backs £15bn global masterplan to ditch EU project: ‘Will be better!’ | Science | News

      Iain Duncan Smith backs £15bn global masterplan to ditch EU project: ‘Will be better!’ | Science | News

      July 4, 2022
      Wordle 380 July 4 daily hints: Can’t solve today’s Wordle? Three clues to help with answer | Gaming | Entertainment

      Wordle 380 July 4 daily hints: Can’t solve today’s Wordle? Three clues to help with answer | Gaming | Entertainment

      July 4, 2022
      31 Swimsuits for Every Style Aesthetic

      31 Swimsuits for Every Style Aesthetic

      July 4, 2022
      Breaking News, US News, World News and Bollywood News

      Follow Us

      Browse by Category

      • Bollywood
      • Business
      • Entertainment
      • Fashion
      • Food
      • Health
      • Hollywood
      • Lifestyle
      • Music
      • Nature
      • Science
      • Sports
      • Technology
      • Travel
      • World News

      Recent News

      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      Garden: How to paint your decking ‘to guarantee the best finish possible’ – ‘saves time’

      July 4, 2022
      Iain Duncan Smith backs £15bn global masterplan to ditch EU project: ‘Will be better!’ | Science | News

      Iain Duncan Smith backs £15bn global masterplan to ditch EU project: ‘Will be better!’ | Science | News

      July 4, 2022
      • Home
      • Privacy Policy

      © 2021 Updates News

      No Result
      View All Result

      © 2021 Updates News