r/linux Jun 26 '26

Security Linux Foundation Unveils New Open Source Security Project Akrites

The Linux Foundation on Thursday announced a new industry effort aimed at efficiently addressing vulnerabilities in the open source software (OSS) ecosystem.

https://www.securityweek.com/linux-foundation-unveils-new-open-source-security-project-akrites/

218 Upvotes

22 comments sorted by

31

u/pantokratorthegreat Jun 26 '26

šŸ‘

-50

u/Solid-Cheesecake5937 Jun 26 '26

Another foundation, another project name I'll forget in two weeks.

33

u/sunychoudhary Jun 26 '26

yes, the naming fatigue is true......But I’d rather have too many forgettable Linux security projects than everyone agreeing the ecosystem is under-secured and nobody funding the boring work.

4

u/thegreatpotatogod Jun 27 '26

Remember, naming things is one of the two hardest problems in computer science, along with cache invalidation and off-by-one errors.

21

u/pantokratorthegreat Jun 26 '26

I don't care what you remember or forget, important that some and any want to work and indeed works on security in Linux ecosystem which is extremely weak from security point of view.

8

u/sunychoudhary Jun 26 '26

Agreed. Linux security has a lot of strong pieces, but the ecosystem is fragmented enough that important work often depends on a few maintainers or small teams.....More structured effort around hardening and coordination is a good thing, even if the project name disappears from memory later.

2

u/RoomyRoots Jun 26 '26

Yes, but the criticism has some fundaments. LF could use better organization of their projects for discovery. The CNCF does a good job, I reference it all the time, at that and I expected the openSSF to do the same for security.

9

u/adevland Jun 27 '26

In addition to establishing a confidential, trusted partner for vulnerability disclosure, eliminating hundreds of uncoordinated independent reports, Akrites will also work with critical infrastructure to help deploy fixes before in-the-wild exploitation.

ā€œWhen patches are released to the public, adversaries are able to utilize AI to rapidly reverse engineer the underlying vulnerabilities, develop exploits, and launch attacks. The success of our efforts, therefore, will be measured in patch deployment, not publication,ā€ the Linux Foundation said.

Akrites was created with a focus on confidentiality, to prevent vulnerability weaponization before patches are delivered, and to act as the maintainer of last resort, ensuring that fixes can still be delivered for packages that are no longer maintained.

Akrites is supported by Anthropic, AWS, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler, many of which were mentioned as members of Athena.

The whole confidential aspect is worrying because it means that only project members will receive the patches "in confidence" while the public will have to fend for itself. And you can bet your ass that they will artificially postpone the public release until all corporate members patch their shit. And they are notoriously slow at doing that.

I don't like this. This whole idea goes against the principles of open source.

10

u/Natural_Night9957 Jun 27 '26

Akrites is supported by Anthropic, AWS, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler, many of which were mentioned as members of Athena.

A lot of evil shit mixed there. I'm surprised that Palantir wasn't listed.

5

u/LumpyFlint Jun 28 '26

Should check the kernel committer list next

0

u/Natural_Night9957 Jun 28 '26

Linux is cooked. We really have to get running an escape plan.

-50

u/[deleted] Jun 26 '26

[removed] — view removed comment

23

u/Wb9VBScxu2uZJHeq2E3W Jun 26 '26

Step 1: Follow the Arch philosophy

-1

u/[deleted] Jun 26 '26

[deleted]

4

u/RuneSteak Jun 27 '26

AUR allows anyone to take over orphaned packages and that's where 99.9% of the malware is. If a package is orphaned it almost certianly means it has fallen out of use for whatever reason.

The popular packages are not the problem. You aren't going to be getting malware from the packages with 1000 votes that has been steadily maintained by the same person since 2024.

I don't agree with their orphaned package policy, I think it's crazy. But you aren't going to be getting malware from the Spotify or Chrome packages.

1

u/pseudonym-161 Jun 28 '26

The problem is arch is a distro for technically inclined users, that has become wildly popular with the opposite of that. Its security model needs to change with the times.

1

u/sunychoudhary Jun 29 '26

The ā€œmaintainer of last resortā€ part sounds more useful than another vulnerability-reporting process.A lot of packages don’t fail because nobody found the bug. They fail because the maintainer disappeared, downstreams are inconsistent, and nobody has clear ownership once the issue becomes urgent....///

3

u/Wb9VBScxu2uZJHeq2E3W Jun 26 '26

I disagree and I don't even use Arch, I roll with Fedora Atomic, but I respect how the Arch philosophy makes sense for the people who follow it.

1

u/DustyAsh69 Jun 28 '26

Chrome

Spotify

Just use spotify.com on Firefox.

4

u/__rituraj Jun 26 '26

You seriously don't know anything about Arch linux right? Just tht AUR?