Much of the invisible backbone of websites from Google to Amazon to the Federal Bureau of Investigation was built by volunteer programmers in what is known as the open-source community.
The Heartbleed bug that made news last week drew attention to one of the least understood elements of the Internet: Much of the invisible backbone of websites from Google to Amazon to the Federal Bureau of Investigation was built by volunteer programmers in what is known as the open-source community.
Heartbleed originated in this community, in which these volunteers, connected over the Internet, work together to build free software, to maintain and improve it and to look for bugs. Ideally, they check one another’s work in a peer review system similar to that found in science, or at least on the nonprofit Wikipedia, where motivated volunteers regularly add new information and fix others’ mistakes.
This process, advocates say, ensures trustworthy computer code.
But since the Heartbleed flaw got through, causing fears — as yet unproved — of widespread damage, members of that world are questioning whether the system is working the way it should.
“This bug was introduced two years ago, and yet nobody took the time to notice it,” said Steven M. Bellovin, a computer science professor at Columbia University. “Everybody’s job is not anybody’s job.”
Once Heartbleed was revealed, nearly two weeks ago, companies raced to put patches in place to fix it. But security researchers say more than one million web servers could still be vulnerable to attack. Mandiant, a cyberattack response firm, said on Friday that it had found evidence that attackers used Heartbleed to breach a major corporation’s computer system, although it was still assessing whether damage was done.
What makes Heartbleed so dangerous, security experts say, is the so-called OpenSSL code it compromised. That code is just one of many maintained by the open-source community. But it plays a critical role in making our computers and mobile devices safe to use.
OpenSSL code was developed by the OpenSSL Project, which has its roots in efforts in the 1990s to make the Internet safe from eavesdropping. “SSL” refers to “secure sockets layer,” a kind of encryption. Those who use this code do not have to pay for it as long as they credit the OpenSSL Project.
Over time, OpenSSL code has been picked up by companies like Amazon, Facebook, Netflix and Yahoo and used to secure the websites of government agencies like the F.B.I. and Canada’s tax agency. It is baked into Pentagon weapons systems, devices like Android smartphones, Cisco desktop phones and home Wi-Fi routers.
Companies and government agencies could have used proprietary schemes to secure their systems, but OpenSSL gave them a free and, at least in theory, more secure option.
Unlike proprietary software, which is built and maintained by only a few employees, open-source code like OpenSSL can be vetted by programmers the world over, advocates say.
“Given enough eyeballs, all bugs are shallow” is how Eric S. Raymond, one of the elders of the open-source movement, put it in his 1997 book, “The Cathedral & the Bazaar,” a kind of manifesto for open-source philosophy.
In the case of Heartbleed, though, “there weren’t any eyeballs,” Mr. Raymond said in an interview this week.
Although any programmer may work on OpenSSL code, only a few regularly do, said Ben Laurie, a Google engineer based in Britain who donates time to OpenSSL on nights and weekends. This is a problem, he said, adding that the companies and government agencies that use OpenSSL code have benefited from it but give back little in return.
The Latest on: Open-source community
[google_news title=”” keyword=”Open-source community” num_posts=”10″ blurb_length=”0″ show_thumb=”left”]
via Google News
The Latest on: Open-source community
- Open source Kubeflow 1.7 set to ‘transform’ MLopson March 29, 2023 at 1:00 pm
Kubeflow 1.7 became generally available today (March 29), providing the first update to the widely used open source MLops platform since the debut of Kubeflow 1.6 in Sept. 2022. At its core, Kubeflow ...
- Aptera Solar EV Will Work With Openpilot, An Open-Source Driver Assistance Systemon March 29, 2023 at 4:54 am
The open-source system is already commercially available for over 200 vehicles on the market today, essentially turning them into Level 2 semi-autonomous cars just by plugging in some connectors. Now, ...
- Robust Intelligence Releases the AI Risk Database to Evaluate Supply Chain Risk in Open Source Modelson March 28, 2023 at 5:00 pm
Robust Intelligence, the end-to-end AI integrity company that proactively mitigates model failure, has released the AI Risk Database, a free and community-supported resource to evaluate AI supply ...
- FOSDEM 2023: An Open-Source Conference, Literallyon March 28, 2023 at 5:00 pm
Of course, part of open-source software is the mobile OSes, and you’d expect the postmarketOS and the Linux on Mobile community around a desk absolutely full of smartphones of all kinds.
- SOOS Creates Public SBOM Database for 54M Open Source Packages (and Counting)on March 28, 2023 at 8:50 am
SOOS Creates Public SBOM Database for 54M Open Source Packages (and Counting) Mar 28, 2023 (PRNewswire via COMTEX) -- PR Newswire WINOOSKI, Vt., March ...
- Cerebras launch open-source GPT-models that don’t need ‘thousands of GPUs’ to runon March 28, 2023 at 6:56 am
An open source AI model has just been released that doesn't require thousands of Nvidia GPUs to run. Find out more about it here.
- AI computing startup Cerebras releases open source ChatGPT-like modelson March 28, 2023 at 6:02 am
Artificial intelligence chip startup Cerebras Systems on Tuesday said it released open source ChatGPT-like models for the research and business community to use for free in an effort to foster more ...
- Cerebras Publishes 7 Trained Generative AI Models To Open Sourceon March 28, 2023 at 6:00 am
The AI company Cerebras Systems, announced it has trained and is releasing a series of seven GPT-based large language models (LLMs) for open use by the research community.
- Making Open Source Truly Openon March 26, 2023 at 5:33 am
Semut's technologies will enable open source applications to be available as a service. Instead of merely uploading code to Github, developers can now enable applications to be available as an easy to ...
- Best Open Source CRM Of 2023on March 22, 2023 at 5:02 am
It is best to research and find the best type of open source CRM that matches your specific needs and then look at how widely used it is. The larger the community of developers who are working ...
via Bing News