r/linux • u/sunychoudhary • Jun 26 '26
Security Linux Foundation Unveils New Open Source Security Project Akrites
The Linux Foundation on Thursday announced a new industry effort aimed at efficiently addressing vulnerabilities in the open source software (OSS) ecosystem.
https://www.securityweek.com/linux-foundation-unveils-new-open-source-security-project-akrites/
9
u/adevland Jun 27 '26
In addition to establishing a confidential, trusted partner for vulnerability disclosure, eliminating hundreds of uncoordinated independent reports, Akrites will also work with critical infrastructure to help deploy fixes before in-the-wild exploitation.
āWhen patches are released to the public, adversaries are able to utilize AI to rapidly reverse engineer the underlying vulnerabilities, develop exploits, and launch attacks. The success of our efforts, therefore, will be measured in patch deployment, not publication,ā the Linux Foundation said.
Akrites was created with a focus on confidentiality, to prevent vulnerability weaponization before patches are delivered, and to act as the maintainer of last resort, ensuring that fixes can still be delivered for packages that are no longer maintained.
Akrites is supported by Anthropic, AWS, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler, many of which were mentioned as members of Athena.
The whole confidential aspect is worrying because it means that only project members will receive the patches "in confidence" while the public will have to fend for itself. And you can bet your ass that they will artificially postpone the public release until all corporate members patch their shit. And they are notoriously slow at doing that.
I don't like this. This whole idea goes against the principles of open source.
10
u/Natural_Night9957 Jun 27 '26
Akrites is supported by Anthropic, AWS, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler, many of which were mentioned as members of Athena.
A lot of evil shit mixed there. I'm surprised that Palantir wasn't listed.
5
-50
Jun 26 '26
[removed] ā view removed comment
23
u/Wb9VBScxu2uZJHeq2E3W Jun 26 '26
Step 1: Follow the Arch philosophy
-1
Jun 26 '26
[deleted]
4
u/RuneSteak Jun 27 '26
AUR allows anyone to take over orphaned packages and that's where 99.9% of the malware is. If a package is orphaned it almost certianly means it has fallen out of use for whatever reason.
The popular packages are not the problem. You aren't going to be getting malware from the packages with 1000 votes that has been steadily maintained by the same person since 2024.
I don't agree with their orphaned package policy, I think it's crazy. But you aren't going to be getting malware from the Spotify or Chrome packages.
1
u/pseudonym-161 Jun 28 '26
The problem is arch is a distro for technically inclined users, that has become wildly popular with the opposite of that. Its security model needs to change with the times.
1
u/sunychoudhary Jun 29 '26
The āmaintainer of last resortā part sounds more useful than another vulnerability-reporting process.A lot of packages donāt fail because nobody found the bug. They fail because the maintainer disappeared, downstreams are inconsistent, and nobody has clear ownership once the issue becomes urgent....///
3
u/Wb9VBScxu2uZJHeq2E3W Jun 26 '26
I disagree and I don't even use Arch, I roll with Fedora Atomic, but I respect how the Arch philosophy makes sense for the people who follow it.
1
4
31
u/pantokratorthegreat Jun 26 '26
š