


Pentagon Targets Open Source Security Risks in Software Procurement Overhaul (theregister.com) 39
The Department of Defense is revamping its "outdated" software procurement systems through a new Software Fast Track initiative. The SWFT program aims to reform how software is acquired, tested, and authorized with security as the primary focus. "Widespread use of open source software, with contributions from developers worldwide, presents a significant and ongoing challenge," DoD CIO Katie Arrington wrote in the initiative memo.
The DoD currently "lacks visibility into the origins and security of software code," hampering security assurance efforts. The initiative will establish verification procedures for software products and expedite authorization processes. Multiple requests for information are running until late May seeking industry input, including how to leverage AI for software authorization and define effective supply chain risk management requirements.
The push comes amid recent DoD security incidents, from malware campaigns targeting procurement systems to sensitive information leaks.
The DoD currently "lacks visibility into the origins and security of software code," hampering security assurance efforts. The initiative will establish verification procedures for software products and expedite authorization processes. Multiple requests for information are running until late May seeking industry input, including how to leverage AI for software authorization and define effective supply chain risk management requirements.
The push comes amid recent DoD security incidents, from malware campaigns targeting procurement systems to sensitive information leaks.
Paying back the bribes (Score:4, Insightful)
Ermahgerd! Erhpin Serhss! (Score:5, Insightful)
The DoD currently "lacks visibility into the origins and security of software code," hampering security assurance efforts.
Or they could... Perhaps... Read the code?! After all, it's Open Source. It's kinda the point.
Sensible vs reality (Score:5, Insightful)
Or they could... Perhaps... Read the code?! After all, it's Open Source. It's kinda the point.
Yup.
The sensible things to do:
Contribute -- both financially and by having coders on your own payroll -- to LTS versions of opensource projects, that you audit for security and contribute back to the development.
The whole planet would benefit from these improvements.
What they are actually going to do:
Microsoft is going pay some bribes to make sure that their latest crap -- huh, sorry, Microsoft Copilot 365 Crap ME (Military Edition) -- is the official "tested and authorized" software.
A few rich guys will get richer.
Re: (Score:2)
The whole planet would benefit from these improvements.
That's exactly why they won't do it. Anything that benefits others is bad in their opinion, even if it benefits them too and ultimately leads to others doing things that benefit them even more. A rising tide lifts all ships, and that's a terrible thing to a corporatist.
Re: (Score:2)
Re: (Score:2)
And MS is going to package up the open source software in libraries to embed in their code.
Re: (Score:3, Interesting)
Or they could... Perhaps... Read the code?!
That's exactly what TFS says they are doing:
he initiative will establish verification procedures for software products and expedite authorization processes.
Between clearly malicious things like the xzutils back door and apparently unintended faults like Apple's "goto fail", there are legitimate security concerns. Contracts for software development or purchase/licensing can include terms that reduce the risk of those mistakes, but using open source code directly doesn't have a contractor who can accept those terms.
Re: Ermahgerd! Erhpin Serhss! (Score:1)
Re: (Score:2)
unless they maintain a verified and continually updated code repository for development... maybe thats what SWFT is?
i am just wondering if there is a budget for that initiative.
Re: (Score:2)
It is pure government bureaucrat speak, at least. They are extremely risk-averse, so they want coverage -- either in terms of contract terms (that probably don't do much except make them feel better) or in terms of paperwork for "assurance" and "authorization".
This does push companies to provide service level agreements for support (typically 8x5 or 24x7, depending on exposure of the software) but a lot of the other security assurance/authorization checkbox items can be provided by a reasonably clueful use
Re: (Score:2)
Or they could... Perhaps... Read the code?! After all, it's Open Source. It's kinda the point.
Let's not get cocky. Yes, being able to read the code is good. But the threat is still real, and we need a systematic way to make sure every update is adequately "read".
Supply chain attacks can bite you when you least expect it. https://en.wikipedia.org/wiki/... [wikipedia.org]
Re: (Score:2)
The thing is, FOSS is not free. It needs to be paid fro by society. It works the same as infrastructure. Well, come tot hink of it, no surprise the US has trouble with the idea.
Re: (Score:2)
The thing is, FOSS is not free.
[sigh] "Free as in speech, not free as in beer" is the common saying.
Re: (Score:2)
Actually that one would be non-F "OSS". But FOSS is not free either. It just needs to be treated as a common good an many people do not understand ho that works. Also so "Tragedy of the Commons" ...
Re: (Score:1)
Back to security by obscurity (Score:5, Interesting)
Re: (Score:2)
as long as the boundary is closed.
Re: (Score:2)
Yep. Only problem is that has stopped working about half a century ago.
including how to leverage AI for software authoriz (Score:5, Insightful)
"including how to leverage AI for software authorization"
So, they're not actually serious about software security. You'd never let an "AI" system anywhere near your evaluation chain. They're just looking for cash.
Re: (Score:2)
the memo does not mention AI, but yeah probably a sales job
Re: (Score:2)
Incompetence or greed? Well, you argue greed and you have a point. But it could be greed and incompetence, after all it is the military. One of the most prolific confirmation organizations for the Dunning-Kruger effect.
the robot dog has already left the stable (Score:2)
Look for improvements where there are problems.
aka Fish where there are fish.
Re: (Score:2)
There ARE problems with several open source projects.
The right way to approach this is to fix them. The wrong way is to depend on something you can't verify.
But don't pretend that FOSS software is perfect. Some of it may be (or close), but much of it isn't. The difference is IT CAN BE FIXED.
Re: (Score:2)
I'm just whatabouting, because I think it's valid to say the vast majority of any problems they are experiencing are over in the microsoft domain.
Why a military force would intentionally create a dependency on clearly bloated and bug ridden software for critical functions is a dereliction of duty.
No need to blame open source when you're balls deep with Microsoft.
Here we go again (Score:4, Insightful)
The DoD currently "lacks visibility into the origins and security of software code," hampering security assurance efforts.
This is the very first step in destroying FOSS. First you cast aspersions on its quality as if closed source software were somehow better.
Re: (Score:1)
Re: (Score:2)
If you read the article, there are four separate quotes that may only be linked by how the author ordered them.
If you could read, you would have noted that the article links the memo [defense.gov] which contains... hold on, wait for it... no more than four paragraphs, of which the quotes in the article encompass the first two of them and are presented in order.
You could then also go on to read the part about where he is "directing the development of a Software Fast-Track (SWFT) Initiative" which will "lead the Department's adoption in* best practices" and (among other things) "expedite the cybersecurity authorizations for rapid
Re: (Score:2)
Naa, others have tried. FOSS is not going to be destroyed. But this will reduce the benefits overall. Obviously a good thing! Cannot have the unwashed masses think they do not need to pay the Microsoft (or Apple) Tax!
Visibility... (Score:4, Insightful)
Re: (Score:1)
Though I'm pretty sure that they do have a code review process for their vendors. And I've seen suggestions that the problem with open-source software is that there is often
Re: (Score:2)
The problem is that the code review processes for COTS software do not really work. I know several people that are or were involved in those and there is so much work they can only do partial inspection of the most critical parts.
Re: (Score:1)
Isolationism (Score:5, Insightful)
Isolationism says is better to buy overpriced proprietary software from your cronies than use open solutions from the evil globalists.
Re: (Score:1)
It's not a simple matter.
Re: (Score:2)
Actually, it is much easier to get that FOSS support. Also much cheaper. The way you do it is you provide one or several paid maintainer positions or finance existing maintainers. Well, known, even if only to experts.
Their biggest security issue (Score:4, Informative)