5 ms·
If they were really trying to secure the code, shouldn't the bill be called the "Securing Software Act"? It's not like closed source software is magically immu
by ZainRiz 4y ago
If they were really trying to secure the code, shouldn't the bill be called the "Securing Software Act"?
It's not like closed source software is magically immune to vulnerabilities
- yesbut 4y agoThey'll change the name as soon as FOSS developers spend millions to hire lobbyists.
- kube-system 4y agoThis isn't about fixing anyone's code, it's about securing the software stack that the government is running. They already have well developed processes for addressing closed source software.
- yakak 4y agoCan you provide a reference to the processes you are referring to? I'm only familiar with EAL and FIPS which require theories that there is maintenance where they apply in the lower part of the stack. They are applied to open source like OpenSSL and SeLinux, probably with better quality than a lot of niche closed source government procures.
- Xelynega 4y agoWhy can't those same processes be used for open source code then? If we assume those processes can't(or don't) apply to open source software then am I to believe that OpenSSL has been running the internet without any scrutiny for the last decade?
- kube-system 4y agoThis is about risk management process, not computer science process. The businesses processes are different. For example, if your proprietary software has a bug, you call the developer and demand they come into your office and fix it under warranty. Doesn’t work that way for some dependency downloaded from GitHub.
- yencabulator 4y agoPractically all software is licensed/sold without any warranty. I challenge you to find even a single counterexample.
- kube-system 4y agoChallenge accepted, here’s one that’s publicly posted. Most are not on public websites: https://www.vmware.com/solutions/industry/government/warranty.html https://www.vmware.com/solutions/industry/government/warrant... Warranties aren’t common in B2C or cheap boxed software. A few hundred or a few thousand dollars is not worth anyone’s time to negotiate special terms. In big dollar B2B or B2G, software isn’t usually as-is. Contracts are negotiated that specify what will be delivered, and what remediations exist if those deliveries fall short. If you spend 7 or 8 digits on software, you can easily get a warranty.
- yencabulator 4y agoGreat example. Key quotes: > your sole remedy will be that VMware shall, at its option, > make a U.S. Person on U.S. soil available to provide technical support (in the case of non-conformity to the aforementioned Section (b)) or refund the license or service fees you paid > VMware receives prompt written notice of the non-conformity following delivery (in the case of Software So, If the product isn't accessible: they'll write down the way it isn't. Period. If the product doesn't do what it says it does, and you notice it quickly after purchase: Either 1. they provide technical support, OR 2. they refund your purchase price. And it's VMware who decides. If the product doesn't do what it says it does, but you don't know until later: You're still screwed. There is no guarantee of performance or suitability for purpose here. There is no guarantee of fixing anything. At worst, "you weren't prompt". At best, yes you get your money back. On the average, maybe you're given a phone number to call, and that person will ask if you've rebooted your computer. This is actually still really bad for risk management; you have no guarantees that anything will keep working, just that after several months of running your platform on this stack, you might get refunded the purchase price. (Which leaves open the question, does that invalidate your software license, and do you now have to emergency migrate to a different stack?) So, what you said earlier really isn't true: > For example, if your proprietary software has a bug, you call the developer and demand they come into your office and fix it under warranty. Also, your earlier > Doesn’t work that way for some dependency downloaded from GitHub. The above is true for every single open source dependency you download from Github! You'll be refunded your $0 purchase price, immediately!
- stubish 4y agoWhat they are really after is having someone to assume risk and take blame.