Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Senators Introduce Open Source Software Security Act
Homeland Security Today ^ | 9/24/2022

Posted on 09/24/2022 7:16:22 AM PDT by Right Wing Vegan

U.S. Senators Gary Peters (D-MI) and Rob Portman (R-OH), Chairman and Ranking Member of the Homeland Security and Governmental Affairs Committee, have introduced bipartisan legislation to help protect federal and critical infrastructure systems by strengthening the security of open source software. The legislation comes after a hearing convened by Peters and Portman on the Log4j incident earlier this year, and would direct the Cybersecurity and Infrastructure Security Agency (CISA) to help ensure that open source software is used safely and securely by the federal government, critical infrastructure, and others. A vulnerability discovered in Log4j – which is widely used open source code – affected millions of computers worldwide, including critical infrastructure and federal systems. This led top cybersecurity experts to call it one of the most severe and widespread cybersecurity vulnerabilities ever seen.

“Open source software is the bedrock of the digital world and the Log4j vulnerability demonstrated just how much we rely on it. This incident presented a serious threat to federal systems and critical infrastructure companies – including banks, hospitals, and utilities – that Americans rely on each and every day for essential services,” said Senator Peters. “This commonsense, bipartisan legislation will help secure open source software and further fortify our cybersecurity defenses against cybercriminals and foreign adversaries who launch incessant attacks on networks across the nation.”

“As we saw with the log4shell vulnerability, the computers, phones, and websites we all use every day contain open source software that is vulnerable to cyberattack,” said Senator Portman. “The bipartisan Securing Open Source Software Act will ensure that the U.S. government anticipates and mitigates security vulnerabilities in open source software to protect Americans’ most sensitive data.”

“This important legislation will, for the first time ever, codify open source software as public infrastructure,” said Trey Herr, Director, Cyber Statecraft Initiative, Scowcroft Center for Strategy and Security, the Atlantic Council. “If signed into law, it would serve as a historic step for wider federal support for the health and security of open source software. I am encouraged by the leadership of Senators Peters and Portman on this issue.”

The overwhelming majority of computers in the world rely on open source code – freely available code that anyone can contribute to, develop, and use to create websites, applications, and more. It is maintained by a community of individuals and organizations. The federal government, one of the largest users of open source software in the world, must be able to manage its own risk and also help support the security of open source software in the private sector and the rest of the public sector.

The Securing Open Source Software Act would direct CISA to develop a risk framework to evaluate how open source code is used by the federal government. CISA would also evaluate how the same framework could be voluntarily used by critical infrastructure owners and operators. This could identify ways to mitigate risks in systems that use open source software. The legislation also requires CISA to hire professionals with experience developing open source software to ensure that government and the community work hand-in-hand and are prepared to address incidents like the Log4j vulnerability. Additionally, the legislation requires the Office of Management and Budget (OMB) to issue guidance to federal agencies on the secure usage of open source software and establishes a software security subcommittee on the CISA Cybersecurity Advisory Committee.

Read more at the Senate Committee on Homeland Security and Governmental Affairs


TOPICS: Government; News/Current Events
KEYWORDS: ccp; china; chrome; debian; linux; raspbian; ubuntu; unix
Navigation: use the links below to view more comments.
first 1-2021-27 next last

1 posted on 09/24/2022 7:16:22 AM PDT by Right Wing Vegan
[ Post Reply | Private Reply | View Replies]

To: Right Wing Vegan
Securing Open Source Software Act

Following the basic rule that all legislation is named the opposite of its actual result, I bet that the real effect of this is to make Linux and other open source software too expensive to use and thus come back to Windows.

2 posted on 09/24/2022 7:24:52 AM PDT by KarlInOhio (The government sees you as either livestock or pet. If things get bad they will eat their pets too.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: KarlInOhio

Government only gets involved these days to Screw Thing Up


3 posted on 09/24/2022 7:28:23 AM PDT by butlerweave
[ Post Reply | Private Reply | To 2 | View Replies]

To: KarlInOhio

That’s a good a good bet. The idea that government is interested in people being secure in their person, papers, and effects is laughable.


4 posted on 09/24/2022 7:30:14 AM PDT by ecomcon
[ Post Reply | Private Reply | To 2 | View Replies]

To: KarlInOhio

Following the basic rule that all legislation is named the opposite of its actual result...

This!


5 posted on 09/24/2022 7:38:21 AM PDT by Flick Lives (FJB and the corrupt FBI)
[ Post Reply | Private Reply | To 2 | View Replies]

To: butlerweave

Indeed.

But when has it really been different?


6 posted on 09/24/2022 7:38:25 AM PDT by Rurudyne (Standup Philosopher)
[ Post Reply | Private Reply | To 3 | View Replies]

To: KarlInOhio

“to make Linux and other open source software too expensive to use and thus come back to Windows”

Bingo

Gotta keep India employed with US taxpayer $$$


7 posted on 09/24/2022 7:39:12 AM PDT by Regulator (It's fraud, Jim)
[ Post Reply | Private Reply | To 2 | View Replies]

To: KarlInOhio

This has all the wording for tyranny. “secure, safety, ect.”

No details on what it actually does.


8 posted on 09/24/2022 7:42:54 AM PDT by Bayard
[ Post Reply | Private Reply | To 2 | View Replies]

To: Right Wing Vegan

but it’s OK to hire as many Chinese Spies at Los Alamos as they can find


9 posted on 09/24/2022 7:50:57 AM PDT by butlerweave
[ Post Reply | Private Reply | To 1 | View Replies]

To: Right Wing Vegan

As if proprietary software never has security holes!


10 posted on 09/24/2022 7:50:58 AM PDT by Dr. Sivana (What was 35% of the Rep. Party is now 85%. And it’s too late to turn back—Mac Stipanovich )
[ Post Reply | Private Reply | To 1 | View Replies]

To: butlerweave

That’s a fact.


11 posted on 09/24/2022 7:57:17 AM PDT by Howie66 (Let's Go Brandon!!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Right Wing Vegan

“This important legislation will, for the first time ever, codify open source software as public infrastructure”

...ok, that doesn’t sound good at all.


12 posted on 09/24/2022 7:58:20 AM PDT by fuzzylogic (welfare state = sharing of poor moral choices among everybody)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Right Wing Vegan

Bkmk


13 posted on 09/24/2022 8:00:49 AM PDT by sauropod (Unbelief has nothing to say. Chance favors the prepared mind.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Right Wing Vegan

Open Source Software is free so they can’t charge money it’s part of the licensing and saves Government Billions and that can’t happen ,LOL


14 posted on 09/24/2022 8:01:07 AM PDT by butlerweave
[ Post Reply | Private Reply | To 1 | View Replies]

To: KarlInOhio; Openurmind
"Following the basic rule that all legislation is named the opposite of its actual result, I bet that the real effect of this is to make Linux and other open source software too expensive to use and thus come back to Windows."

That was my thought as well.

Microsoft and Apple are both hardcore woke companies, as well as Adobe, Google, and many others. It benefits left wing government to keep people paying money into these - what are essentially - laundering machines for left wing corporate goals. It is in the left's best interests to keep these companies funded.

I spent some time trying to convince most of the conservatives within my reach that switching was a benefit for us.

Of course, nobody listened. Well, now, here's the legislation to lock us out.

We simply don't have a lot of activists in our midst. Nobody was going to switch, and it doesn't matter how woke these companies are. Apple could've come out plain as day and said "kill whitey" and nobody was going to move.

Woke was not motivating enough, in and of itself.

15 posted on 09/24/2022 8:19:13 AM PDT by ProgressingAmerica (A man's rights rest in 3 boxes. The ballot box, jury box and the cartridge box.- Frederick Douglass)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Right Wing Vegan

I wonder which megatech company wrote this bill? Do you think the politicians sit around thinking up stuff like this? No.


16 posted on 09/24/2022 8:21:09 AM PDT by jdt1138 (Where ever you go, there you are.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: KarlInOhio

Probably,a good idea to make install disks of,the most recent Linux flavors that one would want, just incase they do muck up Linux or make it too expensive to get. Only problem though would be no updates if that happens, but still.


17 posted on 09/24/2022 8:28:19 AM PDT by Bob434 (question)
[ Post Reply | Private Reply | To 2 | View Replies]

To: fuzzylogic
“This important legislation will, for the first time ever, codify open source software as public infrastructure”

THAT'S RIGHT. We're the Government and we're here to help you. Run for your lives!

18 posted on 09/24/2022 9:13:32 AM PDT by Desron13 (You may choose to ignore reality but you can't force reality to ignore you.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Right Wing Vegan

There is already a process in place to mitigate exploits in open source software ... because ... it's open source. See a bug? Report it! And if you are clever, submit a patch as well. There is no need for any legislation. Just tell your CISA people to submit bug reports and patches.


19 posted on 09/24/2022 10:03:54 AM PDT by so_real ( "The Congress of the United States recommends and approves the Holy Bible for use in all schools.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: fuzzylogic
“This important legislation will, for the first time ever, codify open source software as public infrastructure” And this... "The federal government, one of the largest users of open source software in the world, must be able to manage its own risk and also help support the security of open source software in the private sector and the rest of the public sector." This stinks to high heaven of CONFISCATION BY EMINENT DOMAIN FOR NATIONAL SECURITY. They are going to steal/claim ownership and nationalize it as property of the U.S. Government... THIS IS MORE THAN JUST PROTECTING THEMSELVES. Why? Because of one bug. Did they do this to MS after thousands of bugs? They do this and it will attract all the virus/hacker moths that can come towards the light. They are INVITING hackers to come destroy Linux as we know it! How much you want to bet that Microsoft is right behind this bill pushing it. Every computer user needs to raise hell about this, because it is Linux now and you might not care, but you can bet once they open that door of government confiscation for national security your loved MS will be NEXT! Give them an inch on this concept and they will take a mile. No... No... And No... Don't even think about even going there. Shut this concept down right now!
20 posted on 09/24/2022 11:50:59 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 12 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-27 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson