VOOZH about

URL: https://thenewstack.io/solarwinds-the-worlds-biggest-security-failure-and-open-sources-better-answer/

⇱ SolarWinds, the World's Biggest Security Failure and Open Source's Better Answer - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2020-12-18 14:01:55
SolarWinds, the World's Biggest Security Failure and Open Source's Better Answer
op-ed,tutorial,
Open Source / Security / Tech Culture

SolarWinds, the World’s Biggest Security Failure and Open Source’s Better Answer

Every day that goes by SolarWinds proprietary software Orion network monitoring product supply chain security failure gets bigger and bigger.
Dec 18th, 2020 2:01pm by Steven J. Vaughan-Nichols
👁 Featued image for: SolarWinds, the World’s Biggest Security Failure and Open Source’s Better Answer
Feature image by Ryan McGuire via Pixabay.

Every day that goes by SolarWinds proprietary software Orion network monitoring product supply chain security failure gets bigger and bigger. Microsoft, itself a victim, reports that 40 of its customers installed trojanized versions of Orion. Victims include the U.S. Department of Energy and the National Nuclear Security Administration, at least a number of state governments, and many others.

How bad is it? The Cybersecurity Infrastructure and Security Agency said the hacks posed a “grave risk” to US governments at all levels. That’s how bad.

What really caught my attention though is that SolarWinds has been anti-open source for years. Cloud native computing, from Docker and Kubernetes to the last little program on the Cloud Native Computing Foundation’s (CNCF) Cloud Native Interactive Landscape is open source.

Ironically, SolarWinds claimed open source software as being untrustworthy because anyone can infect it with malicious code. A SolarWinds writer claimed: security “risk is far less when it comes to proprietary software. Due to the nature of open source software allowing anyone to update the code, the risk of downloading malicious code is much higher. One member in the SolarWinds community referred to using open-source software as “eating from a dirty fork.” He wrote that, “When you reach in the drawer for a clean fork, you could be pulling out a dirty utensil. That analogy is right on the money.”

Right. Sure.

SolarWinds followed this up by remarking in another blog that the whole foundation of cloud native computing — containers and container orchestration aren’t trustworthy either. Omar Rafik, SolarWinds Senior Manager of Federal Sales Engineering, wrote, “containers are designed in a way that hampers visibility” and “Visibility becomes particularly problematic when using an orchestration tool like Docker Swarm or Kubernetes to manage connections between different containers because it can be difficult to tell what is happening.”

Trust us, we already know security is a challenge in cloud native computing. We work on locking down cloud native computing every day.

But, open source is not the one that’s inherently insecure here. Proprietary software — a black box where you can never know what’s really going on — is now, always has been, and always will be more of a security problem.

I would no more trust anything mission critical to proprietary software than I would drive a car at night without lights or a fastened seat belt. That’s why I’m writing this on Linux Mint with LibreOffice rather than Windows and Microsoft Word. That’s why the internet, cloud native computing, and the cloud — yes even Microsoft Azure — use Linux and open source.

Now, there’s nothing magical about open source software. People who assume that a miracle happens when you use open source and you’re somehow perfectly safe — I’m looking at you Equifax — deserve what they get when they don’t keep their software up to date. In that case, it was Apache Struts.

And, in still another infamous case, missing a simple error in validating a variable containing a length in OpenSSL led to the Heartbleed security breach. I called it open source’s greatest failure to date. I wasn’t wrong.

So, why with all that history am I saying open source software is inherently more secure? Because it is.

A fundamental open source principle is that by bringing many eyeballs to programs more errors will be caught. That doesn’t mean all errors are caught, just a lot more than those by a single proprietary company.

A corollary to this, is Eric S. Raymond, one of open source’s founders, who famously said, “Given enough eyeballs, all bugs are shallow.” He called it “Linus’s Law.” It worked well. Just consider the sheer number of serious Windows bugs — does a month go by without one? — compared to those of Linux.

There are many ways to find those open source mistakes. You can, of course, do it yourself. The code, after all, is open. Not sure what’s new in your software supply chain’s programs? You can use the Red Hat‘s Release Monitoring or Replogy. The nvchecker program is also useful.  Or, you can look to Synopsys’s Black Duck or Sonatype Nexus Lifecycle for a third-party code analysis tool.

The Linux Foundation has also been working on armoring the open source software chain with the Open Source Security Foundation (OpenSSF). This cross-industry group brings together open source leaders by building a broader security community. It combines efforts from the Core Infrastructure Initiative (CII), GitHub’s Open Source Security Coalition, and other open source security-savvy companies such as GitHub, GitLab, Google, IBM,  Microsoft, NCC Group, OWASP Foundation, Red Hat, and VMware.

The goal of OpenSSF, according to Mark Russinovich, Microsoft Azure’s CTO is to help developers better understand the security threats that exist in the open source software ecosystem and how those threats impact specific open source projects.

To help harden open source software, the Foundation has four goals. 1) Help developers to spot security problems, 2) Provide the best security tools for open source developers, 3) Give them best practice recommendations; and 4) Create an open source software ecosystem where the time to fix a vulnerability and deploy that fix across the ecosystem is measured in minutes, not months.

In short, proprietary software companies, like SolarWinds, are still making huge security blunders, which are hidden from users until the damage is done. At the time, open source programmers and their allies are continuing to make their programs ever more secure and in the open so that everyone benefits.

TRENDING STORIES
Steven J. Vaughan-Nichols, aka sjvn, has been writing about technology and the business of technology since CP/M-80 was the cutting-edge PC operating system, 300bps was a fast internet connection, WordStar was the state-of-the-art word processor, and we liked it.
Read more from Steven J. Vaughan-Nichols
SHARE THIS STORY
TRENDING STORIES
The Linux Foundation, CNCF, GitLab, Red Hat, Sonatype, Synopsys and VMware are sponsors of The New Stack.
TNS owner Insight Partners is an investor in: Docker, SolarWinds.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.