Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Senators Introduce Open Source Software Security Act
Homeland Security Today ^ | 9/24/2022

Posted on 09/24/2022 7:16:22 AM PDT by Right Wing Vegan

U.S. Senators Gary Peters (D-MI) and Rob Portman (R-OH), Chairman and Ranking Member of the Homeland Security and Governmental Affairs Committee, have introduced bipartisan legislation to help protect federal and critical infrastructure systems by strengthening the security of open source software. The legislation comes after a hearing convened by Peters and Portman on the Log4j incident earlier this year, and would direct the Cybersecurity and Infrastructure Security Agency (CISA) to help ensure that open source software is used safely and securely by the federal government, critical infrastructure, and others. A vulnerability discovered in Log4j – which is widely used open source code – affected millions of computers worldwide, including critical infrastructure and federal systems. This led top cybersecurity experts to call it one of the most severe and widespread cybersecurity vulnerabilities ever seen.

“Open source software is the bedrock of the digital world and the Log4j vulnerability demonstrated just how much we rely on it. This incident presented a serious threat to federal systems and critical infrastructure companies – including banks, hospitals, and utilities – that Americans rely on each and every day for essential services,” said Senator Peters. “This commonsense, bipartisan legislation will help secure open source software and further fortify our cybersecurity defenses against cybercriminals and foreign adversaries who launch incessant attacks on networks across the nation.”

“As we saw with the log4shell vulnerability, the computers, phones, and websites we all use every day contain open source software that is vulnerable to cyberattack,” said Senator Portman. “The bipartisan Securing Open Source Software Act will ensure that the U.S. government anticipates and mitigates security vulnerabilities in open source software to protect Americans’ most sensitive data.”

“This important legislation will, for the first time ever, codify open source software as public infrastructure,” said Trey Herr, Director, Cyber Statecraft Initiative, Scowcroft Center for Strategy and Security, the Atlantic Council. “If signed into law, it would serve as a historic step for wider federal support for the health and security of open source software. I am encouraged by the leadership of Senators Peters and Portman on this issue.”

The overwhelming majority of computers in the world rely on open source code – freely available code that anyone can contribute to, develop, and use to create websites, applications, and more. It is maintained by a community of individuals and organizations. The federal government, one of the largest users of open source software in the world, must be able to manage its own risk and also help support the security of open source software in the private sector and the rest of the public sector.

The Securing Open Source Software Act would direct CISA to develop a risk framework to evaluate how open source code is used by the federal government. CISA would also evaluate how the same framework could be voluntarily used by critical infrastructure owners and operators. This could identify ways to mitigate risks in systems that use open source software. The legislation also requires CISA to hire professionals with experience developing open source software to ensure that government and the community work hand-in-hand and are prepared to address incidents like the Log4j vulnerability. Additionally, the legislation requires the Office of Management and Budget (OMB) to issue guidance to federal agencies on the secure usage of open source software and establishes a software security subcommittee on the CISA Cybersecurity Advisory Committee.

Read more at the Senate Committee on Homeland Security and Governmental Affairs


TOPICS: Government; News/Current Events
KEYWORDS: ccp; china; chrome; debian; linux; raspbian; ubuntu; unix
Navigation: use the links below to view more comments.
first previous 1-2021-27 last
To: ProgressingAmerica

Thank you for the ping! Please see 20...

This is BAD for all private computing not just Linux!

MS is next!


21 posted on 09/24/2022 11:53:24 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Right Wing Vegan

Portman. It’s not going to be good for us.


22 posted on 09/24/2022 1:15:26 PM PDT by Lazamataz (The firearms I own today, are the firearms I will die with. How I die will be up to them.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Right Wing Vegan

This will not end well...


23 posted on 09/24/2022 1:18:22 PM PDT by kosciusko51
[ Post Reply | Private Reply | To 1 | View Replies]

To: fuzzylogic

“This important legislation will, for the first time ever, codify open source software as public infrastructure”
= = =

So, if I write a Poem or an Essay, or an Opinion . . .

Is that ‘Public Infrastructure’?

If I say: ‘ x.LT.y=print#value’ is that Public Infrastructure?

If I have thoughts about all this, is that Public Infrastructure?


24 posted on 09/24/2022 2:00:58 PM PDT by Scrambler Bob (My /s is more true than your /science (or you might mean /seance))
[ Post Reply | Private Reply | To 12 | View Replies]

To: Openurmind

Bugs?

These are undocumented features.


25 posted on 09/24/2022 2:03:06 PM PDT by Scrambler Bob (My /s is more true than your /science (or you might mean /seance))
[ Post Reply | Private Reply | To 20 | View Replies]

To: Scrambler Bob

“Bugs?

These are undocumented features.”

Unfortunately you are right. And if they now own your OS then they own your box and there will be even more.

This is scary serious bad... This is Communist Chinese “the government now owns your computer to keep you safe” stuff right here...

Who the hell would be dumb enough to even think this is Ok?


26 posted on 09/24/2022 2:16:36 PM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 25 | View Replies]

To: Right Wing Vegan

Anything coming from these 2 traitorous pieces of trash can’t be good or beneficial for the country. Who’s paying them off to do this?


27 posted on 09/24/2022 7:03:41 PM PDT by EinNYC
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-27 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson