SyncAI.news, a Varaisys broadcasting
​Open Source In The Age Of AI: Why Transparency Is Your Best Security Control
FD

Francis Dinha, Forbes Councils Member

· 1 min read

World NewsForbes: Innovation

​Open Source In The Age Of AI: Why Transparency Is Your Best Security Control

Francis Dinha is CEO and cofounder of OpenVPN Inc., a leading enterprise network security company.

​A recent TechRadar audit of Windows VPN applications turned up some unsettling findings. More than half the apps examined were running open source code that had not been updated in over a year. Some providers, including Turbo VPN and VyprVPN, which are built on the OpenVPN open source protocol, were found running a version dating back to 2019. As the CEO of OpenVPN, I know that OpenVPN itself has continued to patch, harden and improve its codebase in the years since, which means the vulnerability was never really inside the open source project itself but rather in what individual vendors chose to do or not do with it downstream.​​

The Old Argument Against Transparency Was Already Incomplete​

There is a version of the security world that treats open source as a liability rather than an asset on the theory that publishing your code is equivalent to publishing a blueprint of your own vulnerabilities. It is an old argument and has never aged particularly well. One technology CEO recently told a reporter for ZDNet that “open-source code is basically like handing out the blueprint to a bank vault,” with every additional reader assumed to be a potential thief rather than a potential ally. I understand the intuition behind it, though I think it gets the underlying dynamic backward.​

Closed source does not eliminate the existence of vulnerabilities; it only narrows the population of people capable of finding them before an attacker does. Of course, serious vendors run internal audits, penetration testing and bug bounty programs, and some do this exceptionally well. The trouble is that a customer has no way to confirm any of it directly and is left evaluating a vendor’s account of its own security rather than the security itself. ​

Original source

This story was published by Forbes: Innovation and written by Francis Dinha, Forbes Councils Member. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on forbes.com

Similar News