healthcarereimagined

Envisioning healthcare for the 21st century

  • About
  • Economics

Washington summit grapples with securing open source software – Cyberscoop

Posted by timmreardon on 09/24/2023
Posted in: Uncategorized.

The second open source security summit saw a number of the biggest names in tech gather to discuss how to protect open source software.

BYCHRISTIAN VASQUEZ

SEPTEMBER 13, 2023

who’s-who of technology industry representatives and national security agencies are convening this week in Washington to explore ways to improve the security of open source software — a bedrock of the software ecosystem that government officials and researchers are grappling with how to better secure. 

Hosted by the Linux Foundation’s Open Source Security Foundation, the Secure Open Source Software Summit brings together a medley of federal agencies, non-profits and tech giants.

“This week’s convening is a check in with government and the private sector partners to ensure we are holding ourselves accountable toward the aggressive goals set last year and to continue to spark momentum,” Anne Neuberger, the deputy national security advisor for cyber and emerging technologies, said in a statement to CyberScoop. “But we have more work to do – like tools to generate software bills of materials automatically and approaches to use AI for more secure open source software.”

Open source software is a core building block of virtually all computer systems, but its reliance on volunteers and the fact that anyone can contribute to its repositories can lead to major security concerns. Indeed, the initial drive for the January 2022 open source security summit was an easily exploitable vulnerability found in the Apache Log4J software, which continues to be exploited nearly three years after its discovery.

The attendees of this week’s summit include government representatives from the Cybersecurity and Infrastructure Security Agency, the Office of the National Cyber Director, the Departments of Energy and Treasury, the National Science Foundation, the National Security Council, the Office of Management and Budget, the Advanced Research Projects Agency for Health and the Defense Advanced Research Projects Agency.

Industry representatives include Amazon, Apple, Google, Github, IBM, JFrog, Lockheed Martin and Microsoft, among many others.

Non-profits include the Alperovitch Institute for Cybersecurity Studies, FS-ISAC, ISC2 and the Fintech Open Source Foundation.

The Biden administration has embraced improving the security of open source software as a key priority. At the cybersecurity conference Black Hat in August, the administration released a request for information on how best to secure open source technology, whether that’s through promoting memory safe languages like Rust that can help protect a particular subset of vulnerabilities by default or more broadly, such as where should the federal government focus its resources.

On Tuesday, CISA published its open source software security roadmap. The agency outlined two major concerns: cascading risks of vulnerabilities in open source projects and the potential supply chain impacts of a compromised repository where a malicious update can lead to widespread backdoors or scripts.

“Open source software has fostered tremendous innovation and economic gain, including serving as the foundation for technologies used across our federal government and every critical sector,” Eric Goldstein, the executive assistant director for cybersecurity, said in a statement. “In part due to this prevalence, we know that vulnerable or malicious open source software can introduce systemic risks to our economy and essential functions.”

The roadmap calls for several overarching goals: establishing CISA’s role in supporting open source software, drive visibility over usage and risks, reducing risks for the federal government and hardening the open source software ecosystem.

While that roadmap is encouraging, it lack sufficient focus on funding the work to secure open source software, said Dan Lorenc, the CEO of Chainguard and a member of OpenSSF. “They talked about help, they talked about support, but the word ‘funding’ doesn’t show up in here once, so I’m not quite sure what that support means,” Lorenc said. 

Delivering that funding is not an easy task, Lorenc acknowledged. Some developers or maintainers of open source projects work day jobs that prohibit payment on outside projects. And the open nature of open source programs — meaning anyone can clone or try to contribute — means that the broader open source community is far more diverse and fragmented than the interest groups and larger organizations that can more easily receive federal funding.

“It’s really hard for anybody, not just CISA and not just the U.S. government to engage in a constructive way with the broader open source community,” Lorenc said.

Asked about the lack of funding in the roadmap, a CISA spokesperson said that the agency “appreciates all feedback from the open source community.” The spokesperson said that the roadmap is a “starting point” and pointed the open source community to the request for information “to inform the government’s next steps.”

One key topic of conversation at this year’s summit will be how artificial intelligence fits into securing open source software, said Omkhar Arasaratnam, OpenSSF’s general manager. 

“OpenSSF believes AI can be used to address entire classes of open source security problems. We expect to see significant progress in this area from programs like the AI Cyber Challenge by DARPA,” Arasaratnam said. 

Arasaratnam said the summit will be focused on four areas of work related to AI security: supply chain security in open source packages, such as the PyTorch deep learning framework; the security of open sourced AI packages like Falcon LLM; augmenting cybersecurity with AI and applied security of open source inputs and outputs in AI.

Going forward, OpenSSF aims to expand education for open source developers through security guides and classes, improve security evaluations, strengthen open source tools and increase funding for vulnerability discovery tools.

Moran Ashkenazi, a summit attendee and the chief security officer and vice president of engineering at JFrog, said that firms in attendance were encouraged to “contribute, not just consume.” While open source projects are the bedrock of the digital economy, many large companies use the free software while doing little to give back. Encouraging companies to contribute to open source repositories could improve the quality of the code for everyone. 

Correction, Sept. 15, 2023: An earlier version of this article included an incorrect title for Moran Ashkenazi, who is the chief security officer and vice president of engineering at JFrog.

Article link: https://cyberscoop.com/openssf-open-source-security-summit/

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on LinkedIn (Opens in new window) LinkedIn
Like Loading...

Related

Posts navigation

← The 15 Diseases of Leadership, According to Pope Francis – HBR
DeepMind’s cofounder: Generative AI is just a phase. What’s next is interactive AI. – MIT Technology Review →
  • Search site

  • Follow healthcarereimagined on WordPress.com
  • Recent Posts

    • Hype Correction – MIT Technology Review 12/15/2025
    • Semantic Collapse – NeurIPS 2025 12/12/2025
    • The arrhythmia of our current age – MIT Technology Review 12/11/2025
    • AI: The Metabolic Mirage 12/09/2025
    • When it all comes crashing down: The aftermath of the AI boom – Bulletin of the Atomic Scientists 12/05/2025
    • Why Digital Transformation—And AI—Demands Systems Thinking – Forbes 12/02/2025
    • How artificial intelligence impacts the US labor market – MIT Sloan 12/01/2025
    • Will quantum computing be chemistry’s next AI? 12/01/2025
    • Ontology is having its moment. 11/28/2025
    • Disconnected Systems Lead to Disconnected Care 11/26/2025
  • Categories

    • Accountable Care Organizations
    • ACOs
    • AHRQ
    • American Board of Internal Medicine
    • Big Data
    • Blue Button
    • Board Certification
    • Cancer Treatment
    • Data Science
    • Digital Services Playbook
    • DoD
    • EHR Interoperability
    • EHR Usability
    • Emergency Medicine
    • FDA
    • FDASIA
    • GAO Reports
    • Genetic Data
    • Genetic Research
    • Genomic Data
    • Global Standards
    • Health Care Costs
    • Health Care Economics
    • Health IT adoption
    • Health Outcomes
    • Healthcare Delivery
    • Healthcare Informatics
    • Healthcare Outcomes
    • Healthcare Security
    • Helathcare Delivery
    • HHS
    • HIPAA
    • ICD-10
    • Innovation
    • Integrated Electronic Health Records
    • IT Acquisition
    • JASONS
    • Lab Report Access
    • Military Health System Reform
    • Mobile Health
    • Mobile Healthcare
    • National Health IT System
    • NSF
    • ONC Reports to Congress
    • Oncology
    • Open Data
    • Patient Centered Medical Home
    • Patient Portals
    • PCMH
    • Precision Medicine
    • Primary Care
    • Public Health
    • Quadruple Aim
    • Quality Measures
    • Rehab Medicine
    • TechFAR Handbook
    • Triple Aim
    • U.S. Air Force Medicine
    • U.S. Army
    • U.S. Army Medicine
    • U.S. Navy Medicine
    • U.S. Surgeon General
    • Uncategorized
    • Value-based Care
    • Veterans Affairs
    • Warrior Transistion Units
    • XPRIZE
  • Archives

    • December 2025 (8)
    • November 2025 (9)
    • October 2025 (10)
    • September 2025 (4)
    • August 2025 (7)
    • July 2025 (2)
    • June 2025 (9)
    • May 2025 (4)
    • April 2025 (11)
    • March 2025 (11)
    • February 2025 (10)
    • January 2025 (12)
    • December 2024 (12)
    • November 2024 (7)
    • October 2024 (5)
    • September 2024 (9)
    • August 2024 (10)
    • July 2024 (13)
    • June 2024 (18)
    • May 2024 (10)
    • April 2024 (19)
    • March 2024 (35)
    • February 2024 (23)
    • January 2024 (16)
    • December 2023 (22)
    • November 2023 (38)
    • October 2023 (24)
    • September 2023 (24)
    • August 2023 (34)
    • July 2023 (33)
    • June 2023 (30)
    • May 2023 (35)
    • April 2023 (30)
    • March 2023 (30)
    • February 2023 (15)
    • January 2023 (17)
    • December 2022 (10)
    • November 2022 (7)
    • October 2022 (22)
    • September 2022 (16)
    • August 2022 (33)
    • July 2022 (28)
    • June 2022 (42)
    • May 2022 (53)
    • April 2022 (35)
    • March 2022 (37)
    • February 2022 (21)
    • January 2022 (28)
    • December 2021 (23)
    • November 2021 (12)
    • October 2021 (10)
    • September 2021 (4)
    • August 2021 (4)
    • July 2021 (4)
    • May 2021 (3)
    • April 2021 (1)
    • March 2021 (2)
    • February 2021 (1)
    • January 2021 (4)
    • December 2020 (7)
    • November 2020 (2)
    • October 2020 (4)
    • September 2020 (7)
    • August 2020 (11)
    • July 2020 (3)
    • June 2020 (5)
    • April 2020 (3)
    • March 2020 (1)
    • February 2020 (1)
    • January 2020 (2)
    • December 2019 (2)
    • November 2019 (1)
    • September 2019 (4)
    • August 2019 (3)
    • July 2019 (5)
    • June 2019 (10)
    • May 2019 (8)
    • April 2019 (6)
    • March 2019 (7)
    • February 2019 (17)
    • January 2019 (14)
    • December 2018 (10)
    • November 2018 (20)
    • October 2018 (14)
    • September 2018 (27)
    • August 2018 (19)
    • July 2018 (16)
    • June 2018 (18)
    • May 2018 (28)
    • April 2018 (3)
    • March 2018 (11)
    • February 2018 (5)
    • January 2018 (10)
    • December 2017 (20)
    • November 2017 (30)
    • October 2017 (33)
    • September 2017 (11)
    • August 2017 (13)
    • July 2017 (9)
    • June 2017 (8)
    • May 2017 (9)
    • April 2017 (4)
    • March 2017 (12)
    • December 2016 (3)
    • September 2016 (4)
    • August 2016 (1)
    • July 2016 (7)
    • June 2016 (7)
    • April 2016 (4)
    • March 2016 (7)
    • February 2016 (1)
    • January 2016 (3)
    • November 2015 (3)
    • October 2015 (2)
    • September 2015 (9)
    • August 2015 (6)
    • June 2015 (5)
    • May 2015 (6)
    • April 2015 (3)
    • March 2015 (16)
    • February 2015 (10)
    • January 2015 (16)
    • December 2014 (9)
    • November 2014 (7)
    • October 2014 (21)
    • September 2014 (8)
    • August 2014 (9)
    • July 2014 (7)
    • June 2014 (5)
    • May 2014 (8)
    • April 2014 (19)
    • March 2014 (8)
    • February 2014 (9)
    • January 2014 (31)
    • December 2013 (23)
    • November 2013 (48)
    • October 2013 (25)
  • Tags

    Business Defense Department Department of Veterans Affairs EHealth EHR Electronic health record Food and Drug Administration Health Health informatics Health Information Exchange Health information technology Health system HIE Hospital IBM Mayo Clinic Medicare Medicine Military Health System Patient Patient portal Patient Protection and Affordable Care Act United States United States Department of Defense United States Department of Veterans Affairs
  • Upcoming Events

Blog at WordPress.com.
  • Reblog
  • Subscribe Subscribed
    • healthcarereimagined
    • Join 154 other subscribers
    • Already have a WordPress.com account? Log in now.
    • healthcarereimagined
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • View post in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...
 

    %d