Send in your ideas for NGI Taler/Fediversity. Deadline August 1, 2026

The Answer Was Already on the Shelf

How public money built defenses for open source software (way) before the law required them.

The second installment of our article series on digital autonomy looks into open source software supply chain management. Author Jeffrey A. McGuire talks to Armijn Hemel of o.a. DeviceCode and Philippe Ombredanne of o.a. the Free Software Vulnerability Database. They both have a long track record of building tools to improve FOSS supply chain management and are part of the CodeSupply project. Read The Answer Was Already on the Shelf on the Linux Magazine website, or start with the excerpt below.

Together with Linux Magazine NLnet will publish a five-part article series on how public funding of open source contributes to digital autonomy. Each article, written by Jeffrey A. McGuire, focuses on a specific ecosystem supported by the NGI Zero programs that is of strategic importance to increase digital autonomy. The first in the series is about Open Electronic Design Automation: Changing the Chip Industry.

When the Last Line of Defense is the Weakest

Around 2016, Armijn Hemel took apart a KVM-over-IP switch. The box a sysadmin reaches for when a server stops answering, it opens a path into the machine over the network. This one ran a version of Linux that, by Hemel’s estimate, was about 16 years old. The equipment designed to be a data center’s last line of defense was the least defended thing in the rack.

Hemel dismantles firmware for a living, so this pattern is familiar. The devices most people never think about (the home router, the cheap camera) tend to ship with already-old software that then runs for years. The owner rarely notices when one gets exploited, because the camera still films and the router still routes. “Would you be okay if a team of burglars set up shop in your home?” he asks. That’s roughly what happened with Mirai: malware that, without obvious disruption, used hundreds of thousands of Internet protocol (IP) cameras and similar devices to launch attacks.

Old flaws linger for the same reason: No one is forced to fix them. Philippe Ombredanne, who leads the open source project ScanCode, points to log4j to show “the inertia is huge.” A small, ubiquitous piece of Java software, log4j was found in December 2021 to be dangerously vulnerable — and present in a vast number of Internet-facing systems, including banks. More than four years later, a contact at one of the largest cloud providers told Ombredanne that more than 20 percent of its Java customers were still running a flaw that was already years old at discovery.

The scale of this gap is almost invisible to the people relying on the software. Ombredanne likes a thought experiment: Subtract all the open source software from the world and see what stops. The phones, the computer, the networks that connect them. Most cars built in the last few decades and the pumps that would refuel them. Cash registers and the banks behind them. “It would be total chaos,” he says.

For years, a small number of people have been building the defenses for this hidden layer of dependency. They did it quietly, on public money, before any law required it. Now a law has arrived.

Continue reading the article on the Linux Magazine website

Acknowledgements

NGI Zero is made possible with financial support from the European Commission's Next Generation Internet programme, under the aegis of DG Communications Networks, Content and Technology.