The Case for Global Open Source Security
24m
Global open source security is the debate of the summer. Mike Milinkovich, Executive Director of the Eclipse Foundation, joins Alan Shimel to unpack the European Cyber Resilience Act, the Mythos vulnerability wave and why the next chapter has to be a federated global effort, not another US-only initiative.
About Mike Milinkovich
Mike has led the Eclipse Foundation since 2004 and moved it to a European base five years ago. Consequently, he now runs 440 projects across the Eclipse IDE, Theia AI, Adoptium Java, IoT, edge and the software defined vehicle working group.
Inside the case for global open source security
Open source used to be assumed secure because so many eyes looked at the code. As a result, everyone learned the hard way that upstream fixes are only half the job. Meanwhile, downstream applications in banks, utilities and OT can take months to patch after a critical CVE ships.
In addition, the Eclipse Foundation scanned its projects through Project Glasswing and Alpha Omega and found 1,200 vulnerabilities, 30 percent of them high or critical. Therefore, Mike argues that real global open source security requires public private partnerships and federated repositories across nations.
Why this matters now
Meanwhile, White House Gold Eagle, Linux Foundation, IBM and Red Hat Lightwell, GateChain and the Open Secure AI Alliance are all US based. Consequently, Mike says these initiatives are necessary but not sufficient without a truly worldwide framework.
Explore more cybersecurity coverage and the latest TechStrong TV interviews. Furthermore, Mike previews Eclipse Foundation contributions to a federated global program and his upcoming appearance on The Open Current with Alan Shimel and Margaret Dawson of SUSE.
For more information please visit eclipse.org