Loading…
This event has ended. Visit the official site or create your own event on Sched.
September 11-14, 2017 - Los Angeles, CA
Click Here For Information & Registration
Wednesday, September 13 • 11:50am - 12:30pm
Collaborative Security: Securing Open Source Software - Nicko van Someren, The Linux Foundation

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
There is no set of practices that can guarantee that software will never have defects or vulnerabilities, whether that software is open source or proprietary. Even formal methods can fail if the specifications or assumptions are wrong. Nor is there any set of practices that can guarantee that a project will sustain a healthy and well-functioning development community.

But with open source software, it is possible to reduce security issues in the same way it’s built -- with collaboration and transparency. In this talk, The Linux Foundation CTO Nicko van Someren, will present the Core Infrastructure Initiative, a multi-million dollar project to fund and support critical elements of the global information infrastructure. He will discuss the latest research and an update on creative self-serve tools and best practices that help improve the security and quality of open source projects.

The Best Practices Badges Program, for example, is a free open source secure development maturity model designed with and for the open source community. The Linux kernel, Curl, GitLab, OpenBlox, OpenStack, OpenSSL, Node.js, and Zephyr among the first projects to have a new Best Practices badge. Available on GitHub, the badges program continues to evolve. New badge levels were introduced this year to provide even more sophisticated criteria.

Citing both good and bad examples, he’ll dive into what progress is or isn’t being made with security vis a vis the software development lifecycle. OpenSSL is in the habit of making major quality improvements and consciously works to bring the number of defects down. As of June 2016, the current number of defects was 407, its lowest since June 2006. This proves OpenSSL developers are making a concentrated effort to both find new bugs and close existing ones instead of just closing old ones.

He will also explore how, and if, there are differences between open source and commercial software through multiple industry examples.

Whether a producer and consumer of open source, attendees will gain an understanding of how to quickly assess which open source projects care about security-conscious development and how to apply secure development methodologies to the software that they create and use.

Speakers
avatar for Nicko van Someren

Nicko van Someren

CTO, Linux Foundation
Nicko is The Linux Foundation’s chief technology officer focused on the Core Infrastructure Initiative and other security-focused efforts at the organization. He has extensive experience across the security and networking industries. Most recently, he was the chief technology officer... Read More →



Wednesday September 13, 2017 11:50am - 12:30pm PDT
Atrium III