{"id":62237,"date":"2016-06-09T00:00:00","date_gmt":"2016-06-09T00:00:00","guid":{"rendered":"http:\/\/blog.mozilla.org\/foxtail\/2016\/06\/09\/help-make-open-source-secure\/"},"modified":"2021-02-08T20:33:51","modified_gmt":"2021-02-08T20:33:51","slug":"help-make-open-source-secure","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/","title":{"rendered":"Help Make Open Source Secure"},"content":{"rendered":"<p>Major security bugs <img decoding=\"async\" loading=\"lazy\" class=\"alignright wp-image-9359 size-medium\" src=\"https:\/\/blog.mozilla.org\/wp-content\/uploads\/2016\/06\/hearbleed-bandage-300x309.png\" width=\"300\" height=\"309\" \/>in core pieces of open source software &#8211; such as Heartbleed and Shellshock &#8211; have elevated highly technical security vulnerabilities into national news headlines. Despite these sobering incidents, adequate support for securing open source software remains an unsolved problem, as a panel of 32 security professionals <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2015\/07\/28\/experts-develop-cybersecurity-recommendations\/\" target=\"_blank\" rel=\"noopener noreferrer\">confirmed<\/a> in 2015. We want to change that, starting today with the creation of the Secure Open Source (\u201cSOS\u201d) Fund aimed at precisely this need.<\/p>\n<p>Open source software is used by millions of businesses and thousands of educational and government institutions for critical applications and services. From Google and Microsoft to the United Nations, open source code is now tightly woven into the fabric of the software that powers the world. Indeed, much of the Internet &#8211; including the network infrastructure that supports it &#8211; runs using open source technologies. As the Internet moves from connecting browsers to connecting devices (cars and medical equipment), software security becomes a life and death consideration.<\/p>\n<p>The SOS Fund will provide security auditing, remediation, and verification for key open source software projects. The Fund is part of the <a href=\"https:\/\/blog.mozilla.org\/blog\/2015\/10\/23\/mozilla-launches-open-source-support-program\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mozilla Open Source Support program<\/a> (MOSS) and has been allocated $500,000 in initial funding, which will cover audits of some widely-used open source libraries and programs. But we hope this is only the beginning. We want to see the numerous companies and governments that use open source join us and provide additional financial support. We challenge these beneficiaries of open source to pay it forward and help secure the Internet.<\/p>\n<p>Security is a process. To have substantial and lasting benefit, we need to invest in education, best practices, and a host of other areas. Yet we hope that this fund will provide needed short-term benefits and industry momentum to help strengthen open source projects.<\/p>\n<p>Mozilla is committed to tackling the need for more security in the open source ecosystem through three steps:<\/p>\n<ul>\n<li>Mozilla will contract with and pay professional security firms to audit other projects\u2019 code;<\/li>\n<li>Mozilla will work with the project maintainer(s) to support and implement fixes, and to manage disclosure; and<\/li>\n<li>Mozilla will pay for the remediation work to be verified, to ensure any identified bugs have been fixed.<\/li>\n<\/ul>\n<p>We have already tested this process with audits of <a href=\"https:\/\/wiki.mozilla.org\/MOSS\/Secure_Open_Source\/Completed\" target=\"_blank\" rel=\"noopener noreferrer\">three pieces of open source software<\/a>. In those audits we uncovered and addressed a total of 43 bugs, including one critical vulnerability and two issues with a widely-used image file format. These initial results confirm our investment hypothesis, and we\u2019re excited to learn more as we open for applications.<\/p>\n<p>We all rely on open source software. We invite other companies and funders to join us in securing the open source ecosystem. If you\u2019re a developer, <a href=\"https:\/\/docs.google.com\/forms\/d\/1f0xSg9XM8v7YGdZ_FzeE67ggckbAsg6sH1mpQ4buTQE\/viewform\" target=\"_blank\" rel=\"noopener noreferrer\">apply for support<\/a>! And if you\u2019re a funder, <a href=\"mailto:sosfund@mozilla.com\" target=\"_blank\" rel=\"noopener noreferrer\">join us<\/a>. Together, we can have a greater impact for the security of open source systems and the Internet as a whole.<\/p>\n<p><strong>More information:<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/blog.mozilla.org\/statements-of-support-from-the-security-community\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Statements of Support from the Security Community<\/strong><\/a><\/li>\n<li><strong><a href=\"https:\/\/docs.google.com\/a\/mozilla.com\/forms\/d\/1f0xSg9XM8v7YGdZ_FzeE67ggckbAsg6sH1mpQ4buTQE\/viewform\" target=\"_blank\" rel=\"noopener noreferrer\">SOS Fund Application<\/a><\/strong><\/li>\n<li><strong><a href=\"https:\/\/wiki.mozilla.org\/MOSS\" target=\"_blank\" rel=\"noopener noreferrer\">MOSS Program Page<\/a><\/strong><\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Major security bugs in core pieces of open source software &#8211; such as Heartbleed and Shellshock &#8211; have elevated highly technical security vulnerabilities into national news headlines. Despite these sobering incidents, adequate support for securing open source software remains an unsolved problem, as a panel of 32 security professionals confirmed in 2015. We want to [&hellip;]<\/p>\n","protected":false},"author":665,"featured_media":9359,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"coauthors":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Help Make Open Source Secure<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/\",\"url\":\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/\",\"name\":\"Help Make Open Source Secure\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2016\/06\/hearbleed-bandage.png\",\"datePublished\":\"2016-06-09T00:00:00+00:00\",\"dateModified\":\"2021-02-08T20:33:51+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/92c467284d1b178dea38bea5386a5263\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#primaryimage\",\"url\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2016\/06\/hearbleed-bandage.png\",\"contentUrl\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2016\/06\/hearbleed-bandage.png\",\"width\":489,\"height\":504},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Help Make Open Source Secure\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/en\/\",\"name\":\"The Mozilla Blog\",\"description\":\"News and Updates about Mozilla\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/92c467284d1b178dea38bea5386a5263\",\"name\":\"Chris Riley\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/image\/559fa836e2ec3814f8e5ac20d5b8cae6\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4778f215cde88b189620cafd0476b440?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4778f215cde88b189620cafd0476b440?s=96&d=mm&r=g\",\"caption\":\"Chris Riley\"},\"description\":\"Head of Public Policy, Mozilla\",\"sameAs\":[\"https:\/\/blog.mozilla.org\/netpolicy\/\"],\"url\":\"https:\/\/blog.mozilla.org\/en\/author\/crileymozilla-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Help Make Open Source Secure","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/","url":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/","name":"Help Make Open Source Secure","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#primaryimage"},"image":{"@id":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2016\/06\/hearbleed-bandage.png","datePublished":"2016-06-09T00:00:00+00:00","dateModified":"2021-02-08T20:33:51+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/92c467284d1b178dea38bea5386a5263"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#primaryimage","url":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2016\/06\/hearbleed-bandage.png","contentUrl":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2016\/06\/hearbleed-bandage.png","width":489,"height":504},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/en\/mozilla\/help-make-open-source-secure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/en\/"},{"@type":"ListItem","position":2,"name":"Help Make Open Source Secure"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/en\/#website","url":"https:\/\/blog.mozilla.org\/en\/","name":"The Mozilla Blog","description":"News and Updates about Mozilla","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/92c467284d1b178dea38bea5386a5263","name":"Chris Riley","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/image\/559fa836e2ec3814f8e5ac20d5b8cae6","url":"https:\/\/secure.gravatar.com\/avatar\/4778f215cde88b189620cafd0476b440?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4778f215cde88b189620cafd0476b440?s=96&d=mm&r=g","caption":"Chris Riley"},"description":"Head of Public Policy, Mozilla","sameAs":["https:\/\/blog.mozilla.org\/netpolicy\/"],"url":"https:\/\/blog.mozilla.org\/en\/author\/crileymozilla-com\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts\/62237"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/users\/665"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/comments?post=62237"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts\/62237\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/media\/9359"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/media?parent=62237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/categories?post=62237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/tags?post=62237"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/coauthors?post=62237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}