Open Source Security Foundation
openssf.org
openssf.org
Here's a non-exhaustive list: Security Scorecards (https://github.com/ossf/scorecard): auto-generated security checks for OSS, Criticality Score (https://github.com/ossf/criticality_score): auto-generated criticality score for OSS, Package Feeds (https://github.com/ossf/package-feeds): watches package registries for updates, malware analysis tools, SLSA (https://github.com/slsa-framework/slsa): proposal for a supply chain integrity framework, Sigstore/Cosign (https://sigstore.dev/): code signing made easy!
We are also investing and exploring different efforts for improving security of critical OSS projects, and making it sustainable! If any of these projects sound interesting, come join us in the OpenSSF Working Groups!
*edited formatting
And then there's https://security.googleblog.com/2021/02/know-prevent-fix-fra... which effectively calls for the end of open-source contributors staying pseudonymous.
Google does a lot of good for open-source security, but these recent things are a terrible look.
I think that will do more harm than good. First of all a lot of critical software is security related and encryption related and I would guess a higher proportion of contributors in that area are more sensitive to protecting their identity than the general developer population. So you would lose out on some contributions that you would otherwise have gotten.
Second, a major threat in this area arises from nation states. However, due to experience with physical espionage, nation states are already pretty good at establishing fake identities for people (for example it would be no problem for them to supply a fake (or even real) passport/ birth certificate/etc or turning people who are already working in critical areas. Thus getting rid of anonymity would not even be a speed bump for Five Eyes, Russia, China, North Korea, etc.
So I don’t thing there would be much benefit, but there would be a lot of cost.
The point I was trying to make was that stable identity, whether real or pseudonymous, has value in a security context.
> It is conceivable that contributors, unlike owners and maintainers, could be anonymous, but only if their code has passed multiple reviews by trusted parties. It is also conceivable that we could have “verified” identities, in which a trusted entity knows the real identity, but for privacy reasons the public does not. This would enable decisions about independence as well as prosecution for illegal behavior.
For example, I don't want anyone to know my real name. I'm not up to any mischief (criminal or otherwise), I just want the separation of identities. There isn't a single entity on Earth that I'd feel safe delegating this knowledge with if I could avoid it.
Disclaimer: opinions are my own, not my employer's (Google)
I'd argue that "thinking twice" should be the standard bar for all open source dependencies, not a discrimination levied towards anonymous or pseudonymous developers.
(Though, to be fair, I doubt Google would ever use any of my code. I know your cryptographers; they don't need me to contribute lol.)
Among other things, attacking pseudonymity is an effective means for ensuring the exclusion of trans people, wherein they're forced to identify as their legal name (a.k.a. dead name).
Google needs to correct course on this if they're to be trusted at all.
Like you said, trans people are far from the only ones affected. Here is a more extensive list:
https://geekfeminism.wikia.org/wiki/Who_is_harmed_by_a_%22Re...
I see tons of opportunity for guidance to OSS devs that, when implemented, would have massive positive impact for detection and response.
I don't have the experience with such foundations, or the time, to really form a working group, but I'd certainly be interested in discussing this with others.
We finally found out who runs GooseInfosec!
I'm also looking to hire a software/security engineer to join our team at Microsoft, to improve security tooling and analysis around open source. This work will align/contribute to OpenSSF projects. If you like having one foot in software development and the other in security, please take a look: https://careers.microsoft.com/us/en/job/1009857
So, Microsoft x 2, Google, IBM x 2, a for-profit Security company, and non-profit security group, and a bank. I don't see any of the BSDs listed or any other big open source projects.
I'm starting to get a bit worried that this is and some of the goals going to be more for future legislation than helping open source projects with security.
Edit: it should also go without saying that Google et al. are already responsible for a significant portion of the open source ecosystem. For better or worse.
FD: My employer is a (much, much smaller) member of the OpenSSF.
The name makes it sound like a US gov organisation, in reality it is a lobbying group to curb consumer rights.
To be honest it feels like vested interests are keeping it that way: professionals want to keep the tools manual so they can charge by the hour; and tool vendors obviously have no interest in open source tools
And the community of practitioners are giving back to the community in all dimensions, code, knowledge, talks, support, heck even governments and institutions five free insights; mitre, nist, cis for instance.
With a few exceptions such as Nessus and Qualys.
CIS audit, https://www.auditscripts.com
Mitre Attack, https://attack.mitre.org/
NIST, https://www.nist.gov/cyberframework
CISA, https://www.cisa.gov/cybersecurity
OWASP top 10, https://owasp.org/www-project-top-ten/
Cloud security alliance, https://cloudsecurityalliance.org/
Higher level standards: Iso27001
IEC62443
Tools:
AD: Bloodhound / Sharphound
PingCastle
Web:
Owasp ZAP
Burpsuite
Basically download the Kali linux distro
+++++++++++++++
Conferences:
Blackhat
Defcon
Hope
I gave up on trying to do an authenticated scan. Docs/ Forum answers always say "First get it to work in the GUI, then try running on command line." Well that's not helping me very much, because "getting it to work in the GUI" is not reproducible and shareable in the same way as a code/script showing clear steps. Secondly, getting authenticated scans to work when your login form is protected by a CSRF token is very much not trivial (don't think I got this to work in any tools). But if your forms are not protected, you have a vulnerability.
My feeling is that the right kind of tool is really a library, so that one can script the login process which may be quite complex with 2FA.
For CSRF you'll want browser automation, like Chrome Headless. Alternatively, you can load a page and extract a token from the DOM in a normal scraper.
>To be honest it feels like vested interests are keeping it that way: professionals want to keep the tools manual so they can charge by the hour;
As a security professional, get out of here with that non-sense. You've run into a challenging problem and still think there is some conspiracy. What we do is highly technical and often customer specific (e.g. automate 2fa due to some weird requirement rather than the customer disabling it for the test account). There is no market in automating a lot of this work, packaging it in a nodejs library for you to use, and writing docs.
Zap is pretty scriptable as well, so there are likely solutions for it also. What have you tried?
Oh, and it also crashes with null pointer errors.
That piece of software is some of the worst, verbose, bug-ridden garbage I've been required to work with.
That’s the only way to break the consultancy chain - stop paying the wolves to guard the henhouse.
"Open" source is being drowned in bureaucracy by talkers.
Seriously, our biggest challenge is that we need more folks like you, who will roll up your sleeves and help us get something tangible done "right now". Attend a working group and tell us that we're not moving fast enough, or that we're not working on the most important things, or that your idea is better than ours and we should do your thing instead.
Give it a shot, you might be surprised. Or we might be. Either way, one of us is getting better.
The perspective of working for free in initiative where all good outcomes will be used to promote Google and other corporate entities, is not something that encourages people to become involved.
Especially hard working people who produce something useful.
<self interest> Maybe fund some grant program accessible without tons of paperwork? And fund people who would be happy to create/continue creating/improve something useful and security related but are unable to justify doing this as a hobby? </self interest>
If you're willing to try again, I'd be happy to have a chat with you about where you could contribute/collaborate with us. You're also welcome to join any of the working groups (mine meets next on Wednesday, 3/31); calendar: https://calendar.google.com/calendar?cid=czYzdm9lZmhwNWk5cGZ...
Attending meetings with workgroups and advisory committees filled with people from Microsoft/Google/Redhat/JPMorgan is not the sort of thing that fills most oss devs I’ve ever met with joy...
All Linux Foundation projects separate business/funding governance (you pay to get a vote on how the money is spent) from technical governance (you do the work you get a seat at the table). If you show up and do the work, you should be fine.
1. If it requires a GUI, at any stage at all, it's broken.
2. Unless it's controllable through scripting, it's unfit for purpose.
3. If it doesn't support real-time observability and control via an API, it's useless.
This space doesn't need any more "products". We need a good suite of composable tools, not more C-suite bingo sheets.
If that's not the goal, you need to invest into a) ensuring that you actually do provide a useful environment for outside participants and b) communicating this, i.e. by having a public presence that clearly explains this and doesn't look like it's targeted at impressing middle management. Transparency into what is going on right now is key to this.
"Linux Foundation" doesn't scream "community". See also other comments here specifically about Google's input, which reads a lot like "we've thought up some things we're now going to impose on everyone, just open-washed a bit". (Again, this is totally outside image, and not intended as an attack on any individual involved as having done anthing wrong, just trying to communicate what outside impression you are likely dealing with)
Open Source now is in every single walk of life and is only going to become more critical to everyone online, their banking, their healthcare and so on.
As such most people would want that software to be governed. Preferably with transparency, right to reply / be heard and have their needs taken into account.
It might not have to be bereaucratic, long winded or inefficient, but it will have to be government.
And it's going to need to be a government of international needs and concerns.
The only good point is we might get to shape it for the next decade while it all starts up
www.oss4gov.org/manifesto
Looks way too much like a bunch of suits and the occasional skunkworks greybeard deciding they want to tell open source project maintainers and contributors what to do.
Maybe they’ll do some good, it doesn’t sound like a thing I’d ever want to be involved in (you know, unless IBM or Microsoft or whoever offer me a Distinguished Engineer role where I can choose to dabble here at my leisure on their great big firehouse of dimes...)
Will this foundation focus on reducing patch times and offering services like integrated bugtrackers and direct contacts and open policies about what happens to submitted critical bugs and exploit PoCs?
I'm asking because when thinking of "enterprise open-source", the WebKit bugtracker comes to mind ... where literally nobody knows what's going on. All bugs are private once submitted and not any external contributor can see what's going on until literally years later somebody starts to actually read it; and yes that's also the case for critical remote exploit bug reports.
Personal Opinion:
I personally cannot vouch for Microsoft's policies, as they cease-and-desisted me and threatened to sue me in the past for disclosing a RCE/priv escalation report that was NT related. They also caused an illegal police raid (in a legal case where they didn't even charged me with anything and therefore my lawyer couldn't find out anything except about the illegal police raid reports). Well, and I still haven't gotten back my hardware after waiting more than 5 years.
So yeah, I guess every company that's part of this initiative should look on their own shitty policies and previous legal actions before claiming they actually want to get contributions. Almost always reverse engineers get threatened by lawyers once they report critical remote exploit-level bugs. Quite literally, I'm not making this up, and it's known around the netsec/infosec scenes.
As long as "hackers" are painted as the bad guys for reverse engineering and trying to submit patches and fixes, and even have to be anxious about not getting sued by the company they're trying to help - nothing will change.
There are a few ways that OpenSSF and member organizations are already funding direct security work for open source projects, and I'm hoping this expands significantly in the near term.
That said, there is no way to directly help every one of the millions of Open Source projects, so there is a big interest in doing things that help many projects at the same time.
It will not come through commercial software, where profit pressures ensure that there will always be business decision makers who innovate by spending ever less on security until finally it blows up in their face.
The security of proprietary software will improve on average only insofar as it is constrained to improve by open source dependencies.
What I don’t get is why everyone rolls their own infrastructure scripts still?
Where is a mono repo for Terraform or SDK based code that is openly vetted? The same goes for Kubernetes, Helm, Ansible...
Very few web tech problems are so Byzantine they need humans to write bespoke config
Terraform modules were a nice start, but I've pretty much never seen a module I would trust using. It may just be my own bad luck, but the vast majority of the TF Modules I've looked at are A.) A single maintainer, B.) 10 stars or less, C.) Haven't been updated in 6 months. The combination of the above 3 do not leave me feeling confident in including a library. I wish that there was an easier way to tread the paths of those that have done the work.
[1]: https://debops.org/