'Set it and forget it' attitude to open-source software has become a major security problem, says Veracode
- Reference: 1624397407
- News link: https://www.theregister.co.uk/2021/06/22/third_party_libraries_veracode/
- Source link:
"The vast majority of today's applications use open source code. The security of a library can change quickly, so keeping a current inventory of what's in your application is crucial," Chris Eng, Vercode's chief research officer, said. "We found that once developers pick a library, they rarely update it.
"With vendors facing increasing scrutiny around the security of their supply chain, there is simply no way to justify a 'set it and forget it' mentality. It's vital that developers keep those components up-to-date and respond quickly to new vulnerabilities as they’re discovered."
[1]
In its latest report, "State of Software Secuity v11: Open Source Edition", application testing specialist Veracode revealed that a claimed 80 per cent of included third-party libraries are never updated – and that almost all of the code repositories analysed included libraries with at least one vulnerability.
[2]
[3]
That's no small number: the company used data from 13 million scans covering 86,000 repositories, in turn containing over 301,000 unique libraries. The report also cites responses from almost 2,000 developers.
Elsewhere in the report Veracode claimed that a whopping 92 per cent of the laws discovered in third-party libraries could be fixed by simply updating to the latest version, with two-thirds of fixes being "minor and non-disruptive to the functionality of even the most complex software applications."
[4]
The report also highlighted that a slim majority, 52 per cent, of developers claimed to have a formal process for the selection of third-party libraries, with a quarter saying they are either unsure or unaware of the existence of such a process, and that "security" is the third biggest concern when selecting a library – with "functionality" and "licensing" topping the leader board.
[5]Intel to put SiFive's latest CPU cores into 7nm dev system to woo customers to RISC-V
[6]Do you want speed or security as expected? Spectre CPU defenses can cripple performance on Linux in tests
[7]Open standard but not open access: Schematron author complains about ISO paywall
[8]Open-source projects glibc and gnulib look to sever copyright ties with Free Software Foundation
"Although alarming, these results are not entirely surprising," application security expert Sean Wright told The Register . "We see time and time again that libraries are often not updated. Often this comes down to libraries not being effectively tracked.
"There's a reason why this type of vulnerability has a special place in the current OWASP [Open Web Application Security Project] Top 10 list. Organisations have to start tracking the libraries which they use in their software, and ensure that any identified vulnerabilities are appropriately prioritised."
"If you want to see what happens when you don't update libraries," Wright added, "just look to [9]the 2017 Equifax breach . That cost the organisation around $1.4bn. The fix for the underlying vulnerability could have potentially involved a single line of code."
Veracode, of course, pointed to the code-scanning technology it just so happens to provide as the solution. "The growing popularity of open-source software, combined with increasingly demanding development cycles, results in a higher propensity to software vulnerabilities," claimed Chris Wysopal, co-founder and chief technology officer.
[10]
"Scanning earlier in the process significantly reduces the risk profile, and most fixes are minor so will not impact the functionality of even the most complex software."
The full report is available to download [11]here .
OpenUK chief executive Amanda Brock said of the report: "We are pleased to see this detailed focus emerging, as the open-source software communities working on legal and governance have evolved over the last decade to produce a number of important tools including the Open Chain, ISO approved, standard for supply chain and the SPDX Software Bill of Material (SBOM) standard, currently seeking ISO approval.
"Open source is indeed like gravity today and all around us, in a way that is inescapable, particularly in our infrastructure, due to inherent transparency and the wisdom of Linus's law – that many eyes make bugs shallow.
"In many ways I suspect the open-source code is likely better positioned to managing security risks than our friends in the proprietary world. This is not an open-source issue, but a consequence of digitalisation and a general software issue. It will be solved through open collaboration to find the best resolutions." ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YNJdfz3jrpBObp1s-z7NZQAAAEc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNJdfz3jrpBObp1s-z7NZQAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNJdfz3jrpBObp1s-z7NZQAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNJdfz3jrpBObp1s-z7NZQAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/06/22/sifive_performance_p550_intel/
[6] https://www.theregister.com/2021/06/22/spectre_linux_performance_test_analysis/
[7] https://www.theregister.com/2021/06/18/schematron_standard_paywall/
[8] https://www.theregister.com/2021/06/16/glibc_gnulib_fsf_copyright/
[9] https://www.theregister.com/2017/09/07/143m_american_equifax_customers_exposed/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNJdfz3jrpBObp1s-z7NZQAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://info.veracode.com/fy22-state-of-software-security-v11-open-source-edition.html
[12] https://whitepapers.theregister.com/
With Windows you have a centrally managed OS, but many people install the odd utillity or find stuff packaged in by the main software and hidden in theapplications main program folder (Java, Tomcat, python, WinRar, 7-zip, a Chrome add on from the store because it synched your profile....) then completely forget about it and never update it or don't update the application. So when you have this mentatility applied to an OS you are so going land the brown smelly stuff at some point.
With out mechanisism to maintain all these odd bits of stuff and libraries etc and some decent reporting tools you have not got a hope.
Companies don't understand that just because Linux is free to install no OS is free to manage and maintain. Linux is probably more complex in this regard than Windows or other Unix type OSes as it so customisable and the installable applications often have many open source components that you need to keep on top of.