On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

May 6th, 2008

Google launches CERT for open source

Posted by Larry Dignan @ 8:09 am

Categories: Exploit code, Google, Linux, Open source, Viruses and Worms

Tags: Google Inc., CERT, oCERT, Open Source, Security, Larry Dignan

Google on Tuesday detailed plans for oCERT, a volunteer workforce that will remediate security issues in open source applications.

ocert.pngThe move makes a ton of sense. Community driven software can have bugs and plenty of folks to find these vulnerabilities. The problem: There’s no central group to actually fix these flaws.

In Google’s security blog, Will Drewry said:

I’m proud to announce that Google has sponsored participation in oCERT, the open source computer emergency response team. oCERT is a volunteer workforce of security professionals from the open source community with the goal of providing security vulnerability mediation and incident response services to open source projects. It will strive to contact software authors with all security reports and aid in debugging and patching, especially in cases where the author, or the reporter, doesn’t have a background in security. Reliable contacts for projects, publishers, and vendors will be maintained where possible and used for notification when issues arise and fixes are available for mediated issues. Additionally, oCERT will aid projects of any size with responses to security incidents, such as server compromises.

What oCERT does is give corporations a one-stop open source security repository. That’ll come in handy when navigating the patch cycle. Dana Blankenhorn notes that “Google’s backing of oCERT is a major milestone in the history of open source.”

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 4 Talkback(s)
RE: Google launches CERT for open source
Google didn't actually launch anything. oCERT was founded by Inverse Path, Google are a sponsor. (Read the rest)
Posted by: robholland Posted on: 05/08/08 You are currently: a Guest | | Terms of Use
Google and FOSS  fr0thy2 | 05/06/08
...wonder what the AGPL folk are saying...  storm14k | 05/06/08
RE: Google launches CERT for open source  Gabriel Kent | 05/06/08
RE: Google launches CERT for open source  robholland | 05/08/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads