The Answer Was Already on the Shelf

Together with Linux Magazine NLnet will publish a five-part article series on how public funding of open source contributes to digital autonomy. The equipment designed to be a data center’s last line of defense was the least defended thing in the rack. That’s roughly what happened with Mirai: malware that, without obvious disruption, used hundreds of thousands of Internet protocol (IP) cameras and similar devices to launch attacks. Philippe Ombredanne, who leads the open source project ScanCode, points to log4j to show “the inertia is huge.” A small, ubiquitous piece of Java software, log4j was found in December 2021 to be dangerously vulnerable — and present in a vast number of Internet-facing systems, including banks. More than four years later, a contact at one of the largest cloud providers told Ombredanne that more than 20 percent of its Java customers were still running a flaw that was already years old at discovery. NGI Zero is made possible with financial support from the European Commission's Next Generation Internet programme, under the aegis of DG Communications Networks, Content and Technology.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source