Only about half of firms have an open source software security policy in place to guide developers in the use of components and frameworks, but those that do exhibit better security. . Companies that have an open source software (OSS) security policy in place tend to perform much better in self-assessed measures of readiness. They also tend to have dedicated teams in charge of driving software security, according to a survey published on June 21. The survey — published by software-security firm Snyk and the Linux Foundation on Tuesday — found that seven out of 10 companies that have an OSS security policy in place consider their application development to be highly or somewhat secure . Comparatively, just 45% of companies that failed to institute such a policy consider themselves at least somewhat secure. The link for this article located at Dark Reading is no longer available. . Organizations utilizing an open-source software security framework tend to excel in protecting their development methodologies and systems.. Open Source Software, Security Policies, Application Development, Risk Management, Software Safety. . Brittany Day
If your open-source software project is deemed "critical", you could be facing a lot more work and responsibility in the future. Some of Google's top engineers have proposed new 'norms' that they feel could help secure "critical" open-source projects. . Open-source software should be more secure than closed source, but only if people are inspecting it and that's not an easy job, Google argues. But to ensure future software supply chain attacks don't involve key open-source software projects, some of Google's top engineers have proposed new 'norms' that might cause problems with open-source contributors – if their project is considered "critical". . Microsoft unveils new guidelines to enhance the protection of vital open-source projects, emphasizing safety improvements and minimizing supply chain risks. Open Source Security, Developer Guidelines, Critical Projects, Software Safety, Supply Chain Standards. . LinuxSecurity.com Team
The use of Linux is becoming increasingly common in the development of modern embedded medical devices for various reasons - including the high level of security it offers. Discover how embedded developers can ease development of advanced Linux-based medical devices for reliability and safety. . Electronics and software going into medical devices has become increasingly more sophisticated. Platforms utilizing embedded Linux are also common these days. Likewise, safety and security remain paramount for medical devices. Electronic Design's Bill Wong talked with Scot Morrison, Platform Business Unit G.M. of Mentor’s Embedded Systems Division, a Siemens Business, about medical device development using Linux, managing security and safety, to ensure product performance success. . Linux is essential for modern embedded medical devices, offering reliability and security. Its open-source nature allows customization for optimal performance and compliance.. Embedded Medical Devices, Linux Development, Medical Technology. . Brittany Day
Mozilla is moving forward on a number of initiatives to ensure that Internet security improves. Among the efforts is a new approach for determining and measuring security metrics. The security metrics effort, announced earlier this year, is designed to figure out what matters in security and then measure and track those metrics. Snyder explained that the first step of the process, now wrapping up, is about determining what the company needs to look at in terms of security metrics. The next step is figuring how to get that information out of bugzilla and capture it on an ongoing basis. After that the challenge is to get information out and generating raw numbers. At the end the company will do analysis on that information to identify trends, correlate factors and draw conclusions. Mozilla is working on steps to improve the security of it's software by creating a security metrics. What do you think about this security metrics that they are developing? Will it help the security for Firefox? . The link for this article located at InternetNews is no longer available. . Google's commitment to privacy standards seeks to elevate data integrity, bolstering user confidence in Chrome.. Mozilla Security, Software Development, Internet Protection. . Bill Locke
A group of hackers has delayed introducing its planned Web software that is meant to allow users to evade government censorship of the Internet. The delayed project, code-named "Peekabooty," was originally scheduled for launch next month at the hackers' convention Def Con, the group Cult of the Dead Cow (CDC) said in an e-mail message to journalists.. . .. A group of hackers has delayed introducing its planned Web software that is meant to allow users to evade government censorship of the Internet. The delayed project, code-named "Peekabooty," was originally scheduled for launch next month at the hackers' convention Def Con, the group Cult of the Dead Cow (CDC) said in an e-mail message to journalists. Peekabooty still needs to be fine-tuned in order to ensure user safety, wrote the hacker known as Oxblood Ruffian, who is identified as CDC's "Foreign Minister." It would be irresponsible to release the program in its current state, he continued. "My main concern is that Peekabooty needs to function with a higher degree of stealth and mitigate client risk as much as possible. In plain English, we don't want our users to attract the thought police because Peekabooty is operating promiscuously," Oxblood Ruffian wrote. The link for this article located at CNN is no longer available. . A group of hackers has delayed introducing its planned Web software that is meant to allow users to . group, hackers, delayed, introducing, planned, software, meant, allow, users. . LinuxSecurity.com Team
Demonized by the media as "cyber juvenile delinquents"wreaking havoc on the Internet, hackers view themselves as neither young nor intent on havoc. They are crusading to bring public attention to two areas of needed law reform: the quality and safety of software.. . .. Demonized by the media as "cyber juvenile delinquents"wreaking havoc on the Internet, hackers view themselves as neither young nor intent on havoc. They are crusading to bring public attention to two areas of needed law reform: the quality and safety of software. They recognize that there are no training or licensing requirements for software developers, nor are there any product certification standards for this product. Due to the omnipresent disclaimer, there is effectively no legal responsibility for software quality. The main target for hacker attacks has been Microsoft because its Windows software is the operating system for 90 per cent of desktop computers. At the hackers' Second Millennium Conference (H2K) in Pittsburgh last summer, Robert Steele, an ex-CIA agent, and keynote speaker, dramatized the situation as follows: "A car manufacturer has quality control to ensure that the bolts are tightened on the wheels of its cars. Bill Gates puts out cars without wheels." The link for this article located at Lexis-Nexis is no longer available. . Demonized by the media as 'cyber juvenile delinquents'wreaking havoc on the Internet, hackers view t. demonized, media, 'cyber, juvenile, delinquents'wreaking, havoc, internet, hackers. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.