Thursday, May 28, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | Entertainment | Google Calls For Govt Help To Secure Critical Open Source Software

Google calls for govt help to secure critical open-source software

Following a summit on open-source security hosted at the White House on Thursday, Google said the collaboration between government and the private sector was needed for open-source funding and management.

By IANS
Updated On - 14 January 2022, 01:38 PM
Google calls for govt help to secure critical open-source software
whatsapp facebook twitter telegram

Washington: Google has called for a public-private partnership to identify a list of critical open source projects and find new ways of identifying software that might pose a systemic risk, as the world grapples with the recent log4j open source software vulnerability that has put millions of devices at hacking risk.

Following a summit on open-source security hosted at the White House on Thursday, Google said the collaboration between government and the private sector was needed for open-source funding and management.


“We need a public-private partnership to identify a list of critical open source projects — with criticality determined based on the influence and importance of a project — to help prioritise and allocate resources for the most essential security assessments and improvements,” said Kent Walker, president for global affairs and chief legal officer at Google and Alphabet.

Open source software code is available to the public, free for anyone to use, modify, or inspect.

Since it is freely available, open source facilitates collaborative innovation and the development of new technologies to help solve shared problems.

“That’s why many aspects of critical infrastructure and national security systems incorporate it. But there’s no official resource allocation and few formal requirements or standards for maintaining the security of that critical code,” said Google.

In fact, most of the work to maintain and enhance the security of open source, including fixing known vulnerabilities, is done on an ad hoc, volunteer basis.

“Longer term, we need new ways of identifying software that might pose a systemic risk — based on how it will be integrated into critical projects — so that we can anticipate the level of security required and provide appropriate resourcing,” Google noted.

The ‘Log4j’ vulnerabilities represent a complex and high-risk situation for companies across the globe.

This open-source component is widely used across many suppliers’ software and services.

“Sophisticated adversaries (like nation-state actors) and commodity attackers alike have been observed taking advantage of these vulnerabilities. There is high potential for the expanded use of the vulnerabilities,” according to Microsoft.

Cyber criminals are making thousands of attempts to exploit a second vulnerability involving a Java logging system called ‘Apache log4j2’.

Google recently said that more than 35,000 Java packages, amounting to over 8 per cent of the Maven Central repository (the most significant Java package repository), have been impacted by the recently disclosed vulnerabilities with widespread fallout across the software industry.

The Apache Software Foundation has released several updates in the wake of the widespread ‘Log4Shell’ vulnerability in Log4j version 2 branch.

  • Follow Us :
  • Tags
  • Google

Related News

  • Pradhan reviews NEET-UG re-exam security, orders crackdown on fake Telegram channels

    Pradhan reviews NEET-UG re-exam security, orders crackdown on fake Telegram channels

  • Google down for over 3 hours on Tuesday

    Google down for over 3 hours on Tuesday

  • North Korean hackers using AI to find cybersecurity blind spots: Google

    North Korean hackers using AI to find cybersecurity blind spots: Google

  • Google launches Fitbit Air, a lightweight AI-powered fitness tracker priced at 99 USD

    Google launches Fitbit Air, a lightweight AI-powered fitness tracker priced at 99 USD

Latest News

  • WMO warns global temperatures likely to stay near record highs through 2026–2030

    1 min ago
  • Twenty years later, Abdul Rahim comes home from Saudi prison to his mother’s embrace

    11 mins ago
  • Bengal govt arranges food, lodging, treatment facilities at holding centres for illegal immigrants

    19 mins ago
  • HPS Society felicitates Padma Shri awardee Dr G Venkat Rao

    20 mins ago
  • SC pauses sealing directions around Delhi Golf Club heritage zone, grants interim relief

    22 mins ago
  • EBG Group inaugurates Vajram Electric manufacturing hub in Hyderabad

    30 mins ago
  • WFI moves SC against HC order allowing Vinesh Phogat to participate in Asian Games selection trials

    35 mins ago
  • Odisha police officer suspended over alleged assault on woman and son inside police station

    37 mins ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam