Nearly one in two industry pros scaled back open source use over security fears
- Reference: 1663183748
- News link: https://www.theregister.co.uk/2022/09/14/snakes_on_a_plan_anaconda/
- Source link:
The company's [1]2022 State of Data Science report solicited opinions in April and May from 3,493 individuals from 133 countries and regions, targeting academics, industry professionals, and students. About 16 percent of respondents identified as data scientists.
About 33 percent of surveyed industry professionals said they had not scaled back on open source, 7 percent said they had increased usage, and 20 percent said they weren't sure. The remaining 40 percent said they had.
[2]
By industry professionals, or commercial respondents as Anaconda puts it, the biz means a data-science-leaning mix of business analysts, product managers, data and machine-learning scientists and engineers, standard IT folks such as systems administrators, and others in technology, finance, consulting, healthcare, and so on.
[3]
[4]
And by scale back, that doesn't mean stop: 87 percent of commercial respondents said their organization still allowed the use of open source. It appears a good number of them, though, are seeking to reducing the risk from relying on too many open source dependencies.
Anaconda's report found that incidents like [5]Log4j and reports of " [6]protestware " prompted users of open source software to take security concerns more seriously. Of the 40 percent who scaled back usage of open source, more than half did so after the Log4j fiasco.
[7]
Some 31 percent of respondents said security vulnerabilities represent the biggest challenge in the open source community today.
Most organizations use open source software, according to Anaconda. But among the 8 percent of respondents indicating that they don't, more than half (54 percent, up 13 percent since last year) cited security risks as the reason.
Other reasons for not using open source software include: lack of understanding (38 percent); lack of confidence in organizational IT governance (29 percent); "open-source software is deemed insecure, so it's not allowed" (28 percent); and not wanting to disrupt current projects (26 percent).
[8]Open source body quits GitHub, urges you to do the same
[9]Google urges open source community to fuzz test code
[10]CP/M's open-source status clarified after 21 years
[11]Draft EU AI Act regulations could have a chilling effect on open source software
Anaconda's survey also registered worries about lack of technical skills, with 90 percent of professional respondents fretting about a talent shortage. Some 64 percent said their biggest concern was being able to recruit and retain talent and 56 percent opined that lack of data science talent represented one of the major obstacles in enterprise data science efforts.
"Organizations should bolster the tools and resources available for continued learning, and academic institutions should fill in the skills gaps for students and turn them into strengths as they prepare to enter the workforce," said Jessica Reeves, SVP of Operations at Anaconda, in [12]a statement .
[13]
Reeves argues that training existing workers in data science and permitting more appealing remote work options can help with talent acquisition and retention.
Python continues to be the preferred language for data science types. Among survey respondents, 31 percent said they use it "always" and 27 percent said they use it "frequently." Julia, as a point of comparison, scored 3 percent "always" and 12 percent "frequently."
Attention to ethics in data science continues to be underwhelming. The survey found 24 percent of respondents said their organizations don't have standards, policies, or measurement tools to address algorithmic fairness and bias. An additional 15 percent aren't sure how their organizations confront such challenges.
Academic institutions come out even worse in the survey. Among academic-track respondents, just 19 percent said their institutions teach ethics in data science and machine learning and 20 percent said that ethics is covered in the coursework for their respective fields.
Just 23 percent of academic respondents and 21 percent of students said bias in AI/ML/data science is taught regularly. About 39 percent said it's rarely taught and 36 percent said it's never taught – which Anaconda notes is at least a 9 percent year-on-year decrease from the company's 2021 survey.
About a third (32 percent) of respondents said that the social effects of bias in data and models is the biggest problem in AI/ML/data science today.
"[T]here is certainly room for a greater emphasis on ethics and bias in the educational sphere," the survey says. ®
Get our [14]Tech Resources
[1] https://www.anaconda.com/state-of-data-science-report-2022
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YyJO-RDWbHgW5Czd9wC@fgAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YyJO-RDWbHgW5Czd9wC@fgAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YyJO-RDWbHgW5Czd9wC@fgAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/12/13/log4j_rce_latest/
[6] https://www.theregister.com/2022/01/10/npm_fakerjs_colorsjs/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YyJO-RDWbHgW5Czd9wC@fgAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/06/30/software_freedom_conservancy_quits_github/
[9] https://www.theregister.com/2022/09/08/google_fuzz_rewards/
[10] https://www.theregister.com/2022/07/15/cpm_open_source/
[11] https://www.theregister.com/2022/09/11/in_brief_ai/
[12] https://www.anaconda.com/press/anaconda-research-finds-majority-of-organizations-scaled-back-their-open-source-software-usage-due-to-security-fears
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YyJO-RDWbHgW5Czd9wC@fgAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
"open-source software is deemed insecure, so it's not allowed" (28 percent)
Presumably that 28% are quite happy to run Windows, the most insecure enterprise OS of all time. As well as, of course ,myriad cloud services and web technologies, all built on open source software.
As for "data science", the definition of what this actually is appears to have expanded to mean "IT" - I have fortunately not yet encountered an "enterprise data scientist", but I'd be willing to bet 50p that they can't even tell me what a tuple is, or judge whether my schema is in Third Normal Form.
All this survey has done has asked whether this open source thing that was discovered to have errors in it might have put some people off other open source things, because they might have errors too. Obviously people get worried when they hear of problems and would like to avoid them. But the idea that the solution is to only use proprietary software instead, implying that it never has problems, is laughable.
Sounds odd to me
We use open source and had no issues with the log4j, but I know of several instances of log4j issues all with proprietary paid for software using log4j and obsolete versions of other projects embedded in their apparently close source software.
Clickbait title
I must say that I think the article title is clickbait - but then that's becoming more and more common these days. Sigh.
And I think the biggest security problem facing IT departments, well in Australia at least, is a shortage of people with IT skills. Doesn't really matter if it's open or closed source software - some clown will screw up the configuration and leave security holes. A friend supporting some software at a large semi-government organisation was gob-smacked when their outsourced Linux support person didn't know what logrotate was, and asked him how to install and use it. With that level of (lack of) knowledge how can you expect any thought to be given to security - they don't know what they don't know.
Open-source or not, this is surely an obvious choice.
Seeing projects (typically web) pulling in hundreds, if not thousands of dependencies from PIP, CPAN, crates.io, NPM, etc always makes me cringe.
Did anyone ever think this was not going to result in a security issue (and other technical debts). Especially in network related software it seems particularly mad.
Maybe open-source is getting a bit of flack because this kind of development style is less common with proprietary software. No language based package managers just for close-source for example.