8
3 Comments

The US Military should red-team open source code

https://www.defenseone.com/ideas/2022/08/military-should-red-team-open-source-code/375635/
submitted this linkon August 29, 2022
  1. 1

    The Open Source Security Foundation recently proposed red-teaming 200 major open-source projects a year at a cost of roughly $40 million a year. For the military, that’s budget dust.

    Seems like a no brainer. I wonder how easy it will be for US enemies such as North Korea, Iran, Russia, and China to tamper with the US military's software given that the US isn't actively maintaining the software it benefits from.

    I hear a lot of arguments that OS is more secure then proprietary software because it the community vets the software and patches issues themselves...but is that really true when organizations like the US military utilize OS and don't contribute?

  2. 1

    I find it incredibly concerning that the US military is using Open Source software and they aren't contributing to the security of it. They are instead letting companies and enthusiasts handle security on their own.

    This doesn't make any sense. Google and Facebook each contribute to open source security and also pay for bug bounties....why isn't the the US military - one of the largest employers in the world - doing the same?

    1. 1

      Can you name countries whose intelligence force / army actively contributes for open source software they use?