{"id":12216,"date":"2023-05-30T07:00:00","date_gmt":"2023-05-30T15:00:00","guid":{"rendered":"https:\/\/formtek.com\/blog\/?p=12216"},"modified":"2022-08-20T16:29:23","modified_gmt":"2022-08-21T00:29:23","slug":"open-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/open-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard\/","title":{"rendered":"Open Source: No Longer a Fringe Movement, But Security is a Worry"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">It&#8217;s taken decades, but Open Source software has moved from a fringe weird idea into mainstream software development and is routinely used in both small and large businesses. [<a href=\"https:\/\/www.wsj.com\/articles\/SB10001424052748704415104576065641376054226\" data-type=\"URL\" data-id=\"https:\/\/www.wsj.com\/articles\/SB10001424052748704415104576065641376054226\">In 2010, the Wall Street Journal<\/a> wrote of an &#8220;open-source software movement, whose activists tend to be fringe academics and ponytailed computer geeks.&#8221;]<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/donaldfischer\/\" data-type=\"URL\" data-id=\"https:\/\/www.linkedin.com\/in\/donaldfischer\/\">Donald Fischer<\/a>, chief executive officer at Tidelift, <a href=\"https:\/\/tidelift.com\/about\/press-releases\/tidelift-study-finds-the-majority-of-organizations-struggle-with-open-source-software-supply-chain-security-and-maintenance\" data-type=\"URL\" data-id=\"https:\/\/tidelift.com\/about\/press-releases\/tidelift-study-finds-the-majority-of-organizations-struggle-with-open-source-software-supply-chain-security-and-maintenance\">said that<\/a> &#8220;open source is now the de facto standard application development platform and is a proven driver of business success and innovation. Yet as its popularity grows, the challenge of helping development teams manage open source health and security becomes exponentially more difficult.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.idc.com\/getdoc.jsp?containerId=PRF005085\" data-type=\"URL\" data-id=\"https:\/\/www.idc.com\/getdoc.jsp?containerId=PRF005085\">Jim Mercer<\/a>, IDC analyst, pinpointed a major problem with open source, <a href=\"https:\/\/solutionsreview.com\/endpoint-security\/the-hidden-challenges-of-securing-the-open-source-software-supply-chain\/\" data-type=\"URL\" data-id=\"https:\/\/solutionsreview.com\/endpoint-security\/the-hidden-challenges-of-securing-the-open-source-software-supply-chain\/\">saying that<\/a> &#8220;despite the litany of different projects used for building applications, there are no established standards for building, maintaining, and securing OSS. Unfortunately, because many OSS projects are underfunded or rely solely on volunteer contributors, there is a lot of variation in how the projects are maintained.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The lack of oversight and the need for continued and guaranteed maintenance on many open source projects is a reason for concern.  <a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/organizations-intensify-software-supply-chain-security-efforts-against-risks-posed-by-open-source-prevalence\/\" data-type=\"URL\" data-id=\"https:\/\/www.cpomagazine.com\/cyber-security\/organizations-intensify-software-supply-chain-security-efforts-against-risks-posed-by-open-source-prevalence\/\">A survey by Synopsys<\/a> found deep worry about Open-Source usage among IT.  The Synopsys survey found that while 99 percent of companies either use or plan to use Open Source soon, 41 percent worry about being hacked because of their open source choice.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.synopsys.com\/content\/dam\/synopsys\/company\/about\/bio-pdfs\/jason-schmitt-bio-2021.pdf\" data-type=\"URL\" data-id=\"https:\/\/www.synopsys.com\/content\/dam\/synopsys\/company\/about\/bio-pdfs\/jason-schmitt-bio-2021.pdf\">Jason Schmitt<\/a>, general manager at Synopsys, <a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/organizations-intensify-software-supply-chain-security-efforts-against-risks-posed-by-open-source-prevalence\/\" data-type=\"URL\" data-id=\"https:\/\/www.cpomagazine.com\/cyber-security\/organizations-intensify-software-supply-chain-security-efforts-against-risks-posed-by-open-source-prevalence\/\">said that<\/a> &#8220;as organizations are witnessing the level of the potential impact that a software supply chain security vulnerability or breach can have on their business through high-profile headlines, the prioritization of a proactive security strategy is now a foundational business imperative.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One solution proposed by analyst firms like Gartner and IDC is to use a centrally managed repository of open-source components that are available for use by developers in an organization. <a href=\"https:\/\/www.linkedin.com\/in\/chrisgrams\/\" data-type=\"URL\" data-id=\"https:\/\/www.linkedin.com\/in\/chrisgrams\/\">Chris Grams<\/a>, head of marketing at Tidelift, <a href=\"https:\/\/thenewstack.io\/organizations-only-somewhat-confident-in-open-source-components\/\" data-type=\"URL\" data-id=\"https:\/\/thenewstack.io\/organizations-only-somewhat-confident-in-open-source-components\/\">said that<\/a> &#8220;I would view this as an emerging trend. It\u2019s interesting to see that we\u2019re still [in the] early days, but some organizations are starting to do this.&#8221;  But it is unlikely that this model would work for most companies &#8212; it would require a dedicated team to select, validate, and maintain a curated set of open-source components, and even then, if vulnerabilities are ultimately found within those components, the skillset needed to fix the problem is likely outside the realm of the organization.<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fopen-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>It&#8217;s taken decades, but Open Source software has moved from a fringe weird idea into mainstream software development and is routinely used in both small and large businesses. [In 2010, the Wall Street Journal wrote of an &#8220;open-source software movement,<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/open-source-no-longer-a-fringe-movement-but-ensuring-security-is-hard\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24],"tags":[],"class_list":["post-12216","post","type-post","status-publish","format-standard","hentry","category-open-source"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/12216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=12216"}],"version-history":[{"count":2,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/12216\/revisions"}],"predecessor-version":[{"id":12218,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/12216\/revisions\/12218"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=12216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=12216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=12216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}