{"id":90638,"date":"2020-08-04T01:42:20","date_gmt":"2020-08-03T23:42:20","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po"},"modified":"2020-08-04T01:42:20","modified_gmt":"2020-08-03T23:42:20","slug":"uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po","title":{"rendered":"\u00c8 stato istituito il progetto OpenSSF, focalizzato sul miglioramento della sicurezza del software open source","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Fondazione Linux <noindex><a rel=\"nofollow\" href=\"https:\/\/www.linuxfoundation.org\/press-release\/2020\/08\/technology-and-enterprise-leaders-combine-efforts-to-improve-open-source-security\/\">ha annunciato<\/a><\/noindex> sulla formazione di un nuovo progetto congiunto <noindex><a rel=\"nofollow\" href=\"https:\/\/openssf.org\/\">OpenSSF<\/a><\/noindex> (Open Source Security Foundation), volto a riunire il lavoro dei principali attori del settore per migliorare la sicurezza del software open source. OpenSSF continuer\u00e0 a sviluppare iniziative quali  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=39635Core\">Infrastructure Initiative<\/a><\/noindex> e <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51867\">Open Source Security Coalition<\/a><\/noindex>, oltre a unire altre attivit\u00e0 correlate alla sicurezza realizzate dai partecipanti al progetto.<\/p>\n<p>Tra i fondatori di OpenSSF figurano aziende come <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/2020-08-03-github-joins-the-open-source-security-foundation\/\">GitHub<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/opensource.googleblog.com\/2020\/08\/google-joins-open-source-security.html\">Google<\/a><\/noindex>, IBM, JPMorgan Chase, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/08\/03\/microsoft-open-source-security-foundation-founding-member-securing-open-source-software\/\">Microsoft<\/a><\/noindex>, NCC Group, OWASP Foundation e Red Hat. Hanno aderito come partecipanti aziende come GitLab, HackerOne, Intel, Uber, VMware, ElevenPaths, Okta, Purdue, SAFECode, StackHawk e Trail of Bits.<\/p>\n<p>Si sottolinea che nel mondo attuale il software open source \u00e8 molto richiesto in diversi settori, ma la sua sicurezza \u00e8 influenzata dalle catene di dipendenza e dai partecipanti allo sviluppo. Pertanto, per confermare la sicurezza dei progetti open source \u00e8 fondamentale la verifica non solo del codice principale, ma anche delle dipendenze, cos\u00ec come l'identificazione degli sviluppatori il cui codice viene incluso nel progetto e una solida autenticazione durante la revisione e i commit. Inoltre, per garantire la sicurezza \u00e8 necessario l'uso di sistemi di build protetti e la verifica delle build. <\/p>\n<p>Il lavoro di OpenSSF sar\u00e0 concentrato in ambiti come il coordinamento <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-vulnerability-disclosures\">dei risultati di audit di vari SDK per lo sviluppo di applicazioni che interagiscono con il codice eseguito negli ambienti isolati. Con l'obiettivo di identificare funzioni problematiche che potrebbero essere utilizzate per condurre attacchi, sono stati esaminati otto SDK:<\/a><\/noindex> delle informazioni sulle vulnerabilit\u00e0 e la diffusione di patch, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-security-tooling\">sviluppo<\/a><\/noindex> strumenti per garantire la sicurezza, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-best-practices-os-developers\">una pubblicazione<\/a><\/noindex> migliori pratiche per organizzare lo sviluppo in modo sicuro, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-identifying-security-threats\">di quattro vulnerabilit\u00e0 (CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901) nel driver per chip wireless Marvell, che possono portare a un overflow di buffer. L'attacco pu\u00f2 essere effettuato da remoto inviando pacchetti formattati in un certo modo quando ci si connette a un punto di accesso wireless dell'attaccante. La minaccia pi\u00f9 probabile \u00e8 il denial of service remoto (crash del kernel), ma non si esclude la possibilit\u00e0 di eseguire codice nel sistema.<\/a><\/noindex> minacce legate alla sicurezza nel software open source,  <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-securing-critical-projects\">conducendo<\/a><\/noindex> auditing e rafforzamento della sicurezza di progetti open source critici, creazione di strumenti per la verifica <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-developer-identity\">dell'identit\u00e0 degli sviluppatori<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53482\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f Linux Foundation \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 OpenSSF (Open Source Security Foundation), \u043f\u0440\u0438\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0438\u0442\u044c \u0440\u0430\u0431\u043e\u0442\u0443 \u0432\u0435\u0434\u0443\u0449\u0438\u0445 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u0435\u0439 \u0438\u043d\u0434\u0443\u0441\u0442\u0440\u0438\u0438 \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e. OpenSSF \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442 \u0440\u0430\u0437\u0432\u0438\u0442\u0438\u0435 \u0442\u0430\u043a\u0438\u0445 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432, \u043a\u0430\u043a Infrastructure Initiative \u0438 Open Source Security Coalition, \u0430 \u0442\u0430\u043a\u0436\u0435 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0438\u0442 \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e \u0440\u0430\u0431\u043e\u0442\u044b, \u043f\u0440\u0435\u0434\u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u043c\u044b\u0435 \u0443\u0447\u0430\u0441\u0442\u043d\u0438\u043a\u0430\u043c\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430. \u0412 \u0447\u0438\u0441\u043b\u043e \u0443\u0447\u0440\u0435\u0434\u0438\u0442\u0435\u043b\u0435\u0439 OpenSSF [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-90638","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f Linux Foundation\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0447\u0440\u0435\u0436\u0434\u0451\u043d \u043f\u0440\u043e\u0435\u043a\u0442 OpenSSF, \u0441\u0444\u043e\u043a\u0443\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f Linux Foundation\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-03T23:42:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-03T23:42:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00c8 stato istituito il progetto OpenSSF, focalizzato sul miglioramento della sicurezza del software open source | ProHoster","description":"Fondazione Linux","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0447\u0440\u0435\u0436\u0434\u0451\u043d \u043f\u0440\u043e\u0435\u043a\u0442 OpenSSF, \u0441\u0444\u043e\u043a\u0443\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e | ProHoster","og:description":"\u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f Linux Foundation","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-03T23:42:20+00:00","article:modified_time":"2020-08-03T23:42:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"90638","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:45:33","updated":"2022-09-30 11:51:44","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/90638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=90638"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/90638\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=90638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=90638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=90638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}