White House Unveils $11M Strategy to Enhance Open Source Security

At the Def Con conference in Las Vegas, National Cyber Director Harry Coker Jr. emphasized the need for greater community engagement alongside federal support to enhance cybersecurity.

Coker highlighted that the Department of Homeland Security (DHS) is set to invest $11 million into bolstering the security of open source software. This investment is a key component of the Biden administration’s national cybersecurity strategy. The funding will support the Open Source Software Prevalence Initiative, which aims to evaluate the extent of open source software used in critical infrastructure sectors.

“Open source is fundamental to our digital infrastructure. It’s crucial for the government to give back to the community as part of our comprehensive infrastructure efforts,” Coker stated, based on a summary of his speech.

The funding will be allocated through the Bipartisan Infrastructure Law.

Coker’s announcement followed a recent report from the Office of the National Cyber Director, which outlined new recommendations after gathering input on open source software security in 2023. The report suggested utilizing key federal agencies to speed up open source security improvements, such as developing software bills of materials and establishing a U.S. Government Open Source Program Office.

Additionally, the report proposed several actions for the federal government to enhance open source security, including:

  • Offering incentives to promote the use of memory-safe programming languages.
  • Funding the creation of open source tools and libraries to secure the ecosystem.
  • Exploring artificial intelligence applications, such as large language models and machine learning.
  • Fostering public-private partnerships within the open source community.
  • Investing in the development of new and existing talent to strengthen open source security.

During his speech at Def Con, Coker stressed that while government support is important, it cannot replace the need for the broader community to improve coding practices and address security issues. He pointed out that despite longstanding knowledge of vulnerabilities in border gateway protocols, U.S. internet traffic remains at risk of hijacking.

“Memory-safe programming languages have been available for years, yet critical software often relies on C due to convenience,” Coker observed.

He also discussed the “tragedy of the commons” in open source development, noting that while the issues are well-known, crucial software packages are often maintained by volunteers operating with minimal resources.

More Articles & Posts