News

Microsoft, Google and IBM Among First Members of Open Source Security Group

Microsoft has joined a high-powered group of tech giants in a new industry foundation aimed at improving the security of open source software.

The Open Source Security Foundation counts Microsoft as a founding member, along with "GitHub, Google, IBM, JPMC, NCC Group, OWASP Foundation and Red Hat," according to a Monday announcement. The JPMorgan Chase banking chain is also listed as a founding member, per the Open Source Security Foundation's FAQ.

The Open Source Security Foundation is "hosted at the Linux Foundation" and brings together various Linux Foundation-initiated efforts. Those efforts include the "Core Infrastructure Initiative (CII)" and the "GitHub-initiated Open Source Security Coalition (OSSC)," among others. The OSSC members are joining the Open Source Security Foundation and the efforts of CII likely will get dissolved into the new foundation, the FAQ explained.

The aim of the new foundation is to "improve the security of open source software by building a broader community, targeted initiatives and best practices," Microsoft indicated. A list of current technical initiative being overseen by the foundation can be found at this GitHub page.

The open source software community has tended to critique proprietary software companies, such as Microsoft, because its code can't be independently checked. However, Microsoft's announcement by Mark Russinovich, Microsoft's chief technology officer, offered an alternative view, namely:

  • Open source software is ubiquitous, and thereby potentially more subject to frequent attack.
  • Open source software has no central authority checking software quality.
  • Open source software can have attackers masquerading as project maintainers.

"Given the complexity and communal nature of open source software, building better security must also be a community-driven process," Russinovich argued in explaining Microsoft's support for the new foundation.

Microsoft had already been working with the OSSC to identify security threats in open source software. It's also worked to speed the software fixing process. Additionally, Microsoft has developed security tools for open source developers, and it currently offers best-practices advice, Russinovich noted.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

Featured

  • Microsoft Appoints Althoff as New CEO for Commercial Business

    Microsoft CEO and chairman Satya Nadella on Wednesday announced the promotion of Judson Althoff to CEO of the company's commercial business, presenting the move as a response to the dramatic industrywide shifts caused by AI.

  • Broadcom Revamps VMware Partner Program Again

    Broadcom recently announced a significant update regarding its VMware Cloud Service Provider (VCSP) program, coinciding with the release of VMware Cloud Foundation (VCF) 9.0, a key component in Broadcom’s private cloud strategy.

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.