Peters and Hawley Introduce Bipartisan Bill to Help Secure Open Source Software
hsgac.senate.gov
hsgac.senate.gov
Does this mean I can get paid hundreds of millions of dollars to ship upgrades to open source code several years late and with twice as much technical debt as before? Because if so, I'm on board
/s
Or neither. Just make a fund to hire talent to work all day hardening OSS projects. Rather than all the new mandatory meetings and oversight.
text: https://www.congress.gov/bill/117th-congress/senate-bill/491...
pdf: https://www.congress.gov/117/bills/s4913/BILLS-117s4913rs.pd...
[I did eventually figure it out.]
Whereas bugs in computer software are problematic because they allow a new type of analyst to gain an outsized advantage, which upsets the status quo. Although the sharp contrast is slowly vanishing as full compromise bugs get rarer and the incumbent power structure employs more and more computer code analysts. For example, look at all of the security vulns in modern browsers and web protocols themselves that leak information to surveillance companies, but get downplayed as mere "privacy" problems that would be nice to fix some day perhaps.
I remember seeing the apache logs on my home desktop on my cable modem back in 2001, the default.ida GETS would race through with multiple attempts per hour.
Conversely I saw barely any attempts on my public facing apache servers 20+ years later with log4shell. Was it just me?
https://www.bleepingcomputer.com/news/security/us-govt-irani...