Open source does not mean open to vulnerabilities

6 months ago 3
ARTICLE AD BOX

On October 13, The Hindu published a report, headlined “Email accounts of 12 lakh Central authorities employees present tally connected Zoho’s platform”, connected the migration of 12 lakh email addresses of Union authorities employees from a National Informatics Centre (NIC)-based strategy to a level developed by Zoho. The views expressed by a elder authoritative successful the study received a monolithic backlash from the Indian Free & Open Source Software (FOSS) community, with galore taking to societal media.

Strongly condemning the official’s statement, Anvar Sadath, Chief Executive Officer, Kerala Infrastructure and Technology for Education (KITE), said it was a “deeply misinformed and unsafe narrative”. KITE is the nodal e-governance bureau of Kerala’s General Education Department.

The comments by the elder authoritative connected FOSS are disparaging and troubling. The “Policy connected Adoption of Open Source Software for Government of India” of 2014 aims “to guarantee strategical power successful e-Governance applications and systems from a semipermanent perspective” and “to trim the Total Cost of Ownership (TCO) of projects” by adopting FOSS. In different words, “to physique a self-reliant ecosystem successful technology”. Given this, I americium incapable to comprehend the connection by the elder authoritative that “many authorities employees were utilizing unfastened root tools, which could compromise information of files”.

What FOSS tools were the elder authoritative referring to, and however could these tools compromise the information of files? Unfortunately, it is simply a persistent story that FOSS is not unafraid oregon due to the fact that the bundle is “open”, the information besides go “open” oregon “public”. This is acold from the truth. FOSS, similar each software, tin person information vulnerabilities, but arsenic the saying goes, “Given capable eyeballs, each bugs are shallow.”

Unlike closed-source, proprietary software, FOSS empowers users with freedoms — for instance, the state to forestall the bundle from accessing the Internet oregon the state to tally the bundle successful an isolated intra-network, preventing imaginable information compromises erstwhile accessing the nationalist Internet. Unlike closed-source and proprietary software, FOSS tin beryllium independently audited by individuals oregon 3rd parties to discover, disclose, and adjacent hole information vulnerabilities. The 2014 argumentation explicitly states that authorities organisations volition measure the information of FOSS erstwhile adopting a bundle solution.

On October 6, the German authorities of Schleswig-Holstein announced the migration of the email strategy for its full authorities medication of astir 30,000 employees from proprietary bundle to FOSS alternatives, specifically to Open-eXchange and Thunderbird. From 2015, lakhs of Indian authorities users had been utilizing an email strategy developed by the NIC, based connected the open-source Zimbra software.

Defence Secretary Ajay Kumar, and Abhishek Singh, CEO, MyGov, NeGD, and DIC, praised the email work successful the January 2022 contented of the Informatics magazine, published by the NIC. It is incredibly disappointing to spot the Government of India going backmost connected existing well-informed authorities policies conscionable erstwhile the remainder of the satellite is catching up. A nationalist involvement technologist pointed retired that it was of paramount value for the Government of India to tally its ain unafraid mail, 1 built utilizing FOSS, to fortify integer sovereignty.

I applaud the government’s efforts to “build a self-reliant ecosystem successful technology, hardware, and bundle solutions” due to the fact that the FOSS assemblage successful India has been pursuing this imagination for much than 2 decades. A cursory hunt connected DuckDuckGo oregon your hunt motor of prime should uncover pages upon pages of FOSS projects being used, built, and maintained successful India. Tens, if not hundreds, of start-ups person created FOSS from India for the satellite implicit the past 2 decades, and galore established work providers person been solving mission-critical problems for ample Indian enterprises utilizing FOSS. I don’t recognize wherefore the DIC and MeitY decided to determination distant from a FOSS-powered email service, but disparaging the start-ups creating FOSS applications and tools successful the process is profoundly counter-productive to the stated ngo of “building a self-reliant bundle ecosystem”. The elder authoritative is misinformed astir FOSS tools and applications, and is contradicting existing Union authorities policies regarding the adoption of FOSS.

In the “Rise of FOSS successful India” study from the National Law School of India University, Bengaluru, researchers noted that FOSS comprises 70-90% of bundle successful each modern-day bundle solutions. The researchers item FOSS usage astatine much than 15 Indian companies crossed finance, bundle and IT services, healthcare, education, and government. FOSS powers much than 500 cardinal UPI transactions each time via the National Payments Corporation of India. We anticipation that the elder authoritative realises that FOSS powers regular life.

To rephrase Mr. Sadath, India cannot execute existent integer sovereignty by sidelining the precise instauration of an open, transparent, and unafraid exertion stack built utilizing FOSS.

Sai Rahul Poruri is CEO, FOSS United; views expressed are personal

Read Entire Article