August 20, 2015 By Shane Schick 2 min read

Open source projects have gotten a bad rap in security circles thanks to Heartbleed, Shellshock and other flaws, but an industry consortium may change that by offering a badge to recognize stability and quality.

Amid this week’s LinuxCon in Seattle, SecurityWeek reported that the Core Infrastructure Initiative (CII), which funds open source projects, will give the badge to those that meet a set of standard criteria. This includes an established bug reporting process, an automated test suite, vulnerability response processes and patching processes. A self-assessment will determine whether the project owners merit the badge.

Of course, a badge program won’t change much if it doesn’t have credibility. That’s why, according to SiliconANGLE, the CII has requested the open source community weigh in on what should be included in the standards of excellence that the badge will represent. It’s also a healthy sign that prominent experts in cryptography and other areas of the security industry have recently joined the CII.

To some extent, there will be a lot riding on the success or failure of the badge program. As eWEEK pointed out, the CII only came into existence through the Linux Foundation following Heartbleed, the flaw in OpenSSL that threatened countless organizations around the world. But its current efforts could provide wayS for those involved in this community to effectively police themselves and perhaps restore the credibility of open source projects as being fit for use in the enterprise.

Naturally, the security badge program isn’t guaranteed to prevent the next Heartbleed or Bash bug. Instead, experts told ZDNet the CII’s efforts are more about educating developers of open source projects to aim higher in terms of their security practices. At the very least, they should demonstrate that when the worst happens, there will be some way of addressing flaws quickly.

Enterprise Tech said that the security badge program isn’t the only way the CII is hoping to make open source projects more proactive about security. The group is considering the introduction of a fellowship program focused on modeling security threats, as well as bringing on someone to oversee audits of coding practices that could put users at risk.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

2024 trends: Were they accurate?

4 min read - The new year always kicks off with a flood of prediction articles; then, 12 months later, our newsfeed is filled with wrap-up articles. But we are often left to wonder if experts got it right in January about how the year would unfold. As we close out 2024, let’s take a moment to go back and see if the crystal balls were working about how the year would play out in cybersecurity.Here are five trends that were often predicted for…

Ransomware attack on Rhode Island health system exposes data of hundreds of thousands

3 min read - Rhode Island is grappling with the fallout of a significant ransomware attack that has compromised the personal information of hundreds of thousands of residents enrolled in the state’s health and social services programs. Officials confirmed the attack on the RIBridges system—the state’s central platform for benefits like Medicaid and SNAP—after hackers infiltrated the system on December 5, planting malicious software and threatening to release sensitive data unless a ransom is paid. Governor Dan McKee, addressing the media, called the attack…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today