The Case for Global Open Source Security
Global open source security is the debate of the summer. Mike Milinkovich, Executive Director of the Eclipse Foundation, joins Alan Shimel to unpack the European Cyber Resilience Act, the Mythos vulnerability wave and why the next chapter has to be a federated global effort, not another US-only initiative.
About Mike Milinkovich
Mike has led the Eclipse Foundation since 2004 and moved it to a European base five years ago. Consequently, he now runs 440 projects across the Eclipse IDE, Theia AI, Adoptium Java, IoT, edge and the software defined vehicle working group.
Inside the case for global open source security
Open source used to be assumed secure because so many eyes looked at the code. As a result, everyone learned the hard way that upstream fixes are only half the job. Meanwhile, downstream applications in banks, utilities and OT can take months to patch after a critical CVE ships.
In addition, the Eclipse Foundation scanned its projects through Project Glasswing and Alpha Omega and found 1,200 vulnerabilities, 30 percent of them high or critical. Therefore, Mike argues that real global open source security needs public private partnerships and federated repositories across nations.
Why this matters now
Meanwhile, White House Gold Eagle, Linux Foundation, IBM and Red Hat Lightwell, GateChain and the Open Secure AI Alliance are all US based. Consequently, Mike says these initiatives are necessary but not sufficient without a truly worldwide framework.
Explore more cybersecurity coverage and the latest Techstrong TV interviews. Furthermore, Mike previews Eclipse Foundation contributions to a federated global program and his upcoming appearance on The Open Current with Alan Shimel and Margaret Dawson of SUSE.
For more information please visit eclipse.org
Transcript
Hey, everyone. " My next guest is Mike Milinkovich, and I could tell you a quick idiom that will help you with his last name, but we're not going to go into it, I promised him. But Mike is the executive director of the Eclipse Foundation, and that's a great foundation.
It's been around a while. He's going to tell us about it. But first, let's welcome Mike.
" It's great to have you on here. It's great to be here, Alan. Thank you so much for having me.
My pleasure. Mike, before we talk about Eclipse and what's going on in the world, I wanted to talk a little bit about you. Give people a sense of who they're watching.
Sure. How did you come to be the ED over here? Well, that's a long story.
But yeah, by way of background, and this is part of the origin story of the Eclipse Foundation itself, but the Eclipse Foundation was originally started by a group of four companies, IBM, Intel, SAP, and HP at the time that was really focusing on the IBM-led Eclipse project. The core team that built the original Eclipse platform and IDE went into IBM through an acquisition of a company called Object Technology International. Just so happens I was employee number 10, and I was one of the executives that sold OTI to IBM and had since left at that time when they were searching for a new executive or their first executive director of the Eclipse Foundation.
I was a VP at Oracle. And so I'm based in- Oh, okay ... Ottawa, Canada, which is actually where the original core development team for Eclipse was.
And I'd like to say sort of jokingly, I pattern matched my way into the job, because if you think of what they were looking for, and this is all the way back in 2004 when open source was a completely different thing. What were they looking for? They were looking for ideally somebody who knew how to run a business, and I'd done three startups and had been an executive in a bunch of different places.
Somebody who knew the tools industry because the original Eclipse platform was very much a tooling platform, and I'd basically been a software developer, started my career building tools for Smalltalk and Java developers way back when. They wanted somebody who ideally knew the people on the core development team. And I'd been, like I said, employee number 10.
I knew all the folks that had been working on the Eclipse IDE. And the fourth thing was, and somewhat tongue in cheek, is they really didn't want somebody from IBM because they really- Yeah ... the whole story of the Eclipse Foundation was- No, it had to be independent Had to be independent and- Yep ...
at the time I was a VP at Oracle, and so like I jokingly say, I pattern matched my way into the job. Good for you. I got to be honest, I'm old enough to remember when the Eclipse Foundation spun up.
And yeah, I was already into open source and all of that. I never heard it explained from the other side, from the inside like this, though. I appreciate you sharing that.
I don't know, I assume other people out here in the audience will too, but I got to tell you from my personal point of view, thank you. That explains a lot. Now, from 2004 to now, it's 22 going on 23 years, a lot of open source has gone under that bridge.
Right? And the Eclipse Foundation, it's probably best known with Java and some of the other things, but it's a living, breathing, dynamic, changing foundation. Yeah.
It's evolved- Tell us ... so much since. So, in some ways, think of it as sort of a similar story to the Apache Software Foundation, which started off with one project, right?
Yeah. And has eventually over time has evolved into a community that has a lot of different projects. Sort of a similar story, the Eclipse Foundation started with the Eclipse IDE and the Eclipse platform.
We still have them. Millions of developers around the world still use the Eclipse IDE for Java, the Eclipse IDE for C and C++. These are still widely used.
But we've grown now to the point where we have 440 different projects- Wow ... in the Eclipse Foundation. Wow.
And so the whole tooling area is maybe a fifth of what we do now. The other areas that we're really big in are places like IoT and edge computing. We have a lot of projects that are in that space.
We're very strong in automotive. The Eclipse software-defined vehicle working group is- Yes ... is really changing the industry in really dynamic and interesting ways.
We're actually the second largest Java vendor after Oracle. So the Eclipse- Huh ... open Java runtime, which comes from the Adoptium group is-- It just actually passed the one billion download mark the other day.
And of course, we still have a core franchise in tools, but in addition to the developer, the original Eclipse IDE platform, we also have Eclipse Theia and Theia AI, and we have an emerging portfolio of AI-related projects for agentic platforms, for AI development with Eclipse Theia, where you can use any language model you want. You're not tied to any particular one. And so, a really great portfolio of developer tools, which is, like I said, that's our original franchise and we're still very strong there.
Wow. I had no idea it was 400 at this point. Oh, yeah.
And actually, and we're growing at a- And growing ... and growing, and actually we've had already more project proposals halfway through this year than we did all of last year. So- Well, I think part of that, Mike, is Again, I've been following a part of the open source software movement for decades now, and I always describe it this way to people.
When I first got involved with open source, I call it the cathedral and bazaar era. Dr. Stallman and down with the pigs and free as in beer, free as in freedom, the whole kind of genesis of open source software.
Then it went through what I call a Big Brother era, right? And that was very much IBM was the king of this. IBM did a whole bunch of good open source projects, but let's be fair, they did it for their own benefit as much as anyone else's, and they did what was good for them.
And if it was good for the community, that's great, too. Not so much for other vendors, quite frankly. As long as it was good for IBM, they were benevolent about it.
But it prevented an Oracle from working closely with IBM or an HP from working cl- the foundation era begins with the Eclipse and the Apache Foundation and, of course, Linux Foundation. And it allows all these companies now to start working together. With the premise that the rising tide lifts all boats, we're going to have a common floor, and what you build on top of that's up to you.
But it made possible what open source is today. Absolutely. We're trying.
I see a lot of people throwing their hats in the ring trying to do this with AI today, too. There's the AI Foundation. A lot of the existing foundations are taking in a lot of AI projects.
But just this week, we've had, this week and last week, this whole flare up around, it's not open source AI, it's open weights AI. Oh, yeah. And all these people signing letters that that has to be the future.
We can't have closed source. It's just not- Well, I think they're pointing out to the fact that the long-term success of AI is going to involve a more democratic approach, where- Yeah ... AI is not controlled by a small group of companies, but is made available in ways that we are able to use them on premises, with our own data staying in behind our firewall.
I think the CEO of Palantir had a rant on CNBC, what, a couple- Yes, I covered it ... it was very much along those lines. And I think honestly, he has a point.
I think that having AI controlled by just a small group of vendors, I think would be a terrible outcome. I think that there's a lot of opportunity for AI to be democratized, and actually we're very interested in being part of that solution. I should mention, one of the things I didn't talk about in the history of the Eclipse Foundation, I think is important to touch on, because I think it gives us a bit of a unique viewpoint, is five years ago, we moved the Eclipse Foundation from being a US-based foundation to a European-based foundation.
Now, this- Really? Good for you ... and it- This is before the whole sovereignty thing.
Yeah, this was actually not based at all on any kind of politicking of any type. We actually did an analysis, and we realized that two-thirds of our projects and two-thirds of our paying members were based in Europe. And so we decided to basically pick up lock, stock, and barrel and move to Europe.
And it- That's fascinating ... it's given us an interesting differentiator. Yeah.
All of the other open source foundations, the big ones, I'm thinking like the umbrella ones like the Linux Foundation, Apache, are based in not only in the US, but based in Silicon Valley. They're based- In the Valley ... in the Bay Area.
As is Mozilla, although Mozilla is very focused on- Not what it was ... Thunderbird and the like. So it's given us an interesting differentiator, but it also gives us an interestingly- Point of view ...
viewpoint. I'm a Canadian who runs Europe's largest open source foundation. So we just have a- Good ...
subtly different worldview in terms of what's right for the community and what makes sense- And I applaud you for it ... yeah. Look, let's face it, Canada has more of a European-based view than I think they did prior to our current administration.
Let's not even go there. But Mike, you know what I find ironic, though, is that the Chinese Communist Party is now the champion of open weight AI and open source distribution, and there's something to be said for that. Well, their position is not based on altruism.
You were commenting a little bit o- No, nothing they do is based... Look. Yeah.
There's no angels in this game. Let's be really clear. Yeah.
I don't care whether it's the Chinese, the US, or quite frankly, the Europeans. There are no angels. Everyone just wants to make sure that their position is solidified, that their position is protected.
Right. And it means different things for each of these players. It does.
But I think to a large- It's the world we live in. Let's not be naive. Yeah.
But I think to a large degree, let's just leave AI aside for the moment. What a lot of both companies and institutions, and for that matter, countries, are really interested in, you can talk about this sovereignty notion, but basically what everybody is trying to do is have access to a technology stack that gives them freedom of action. And you can call that sovereignty, you can call that autonomy, you can call it whatever you want, but it really is what that- It's control of your own Destiny, control of your own technology.
" It's me and Margaret Dawson, who's the CMO of SUSE. And that was our very first episode is, why do you need to control your own technology stack? Not necessarily own it, but at least control your own technology stack.
It's your destiny. As a matter of fact, Mike, we're going to do this one every other week. I'd love to have you on one time with Margaret and I, and we could dive into this.
Yeah, I'd love to. Because I think when it comes particularly to European digital sovereignty, which is a catchphrase, the Eclipse Foundation is definitely part of the solution. If somebody would've told me when I started this job 20 years ago, that public policy and geopolitics was going to be part of the job description of being the executive director of an open source foundation, I would've laughed my butt off.
But it's- But it is ... and when you look at the work that we did at the Eclipse Foundation in regards to the European Cyber Resilience Act, we actually were able to have a positive influence on the European Union's, the first horizontal regulation of the IT industry as it relates to cybersecurity. Because the original draft of that was quite a bit off the mark, and we were able to have a really positive impact on the final document.
And we're still having a positive impact because there's a lot of FAQs and enabling acts and interpretations that need to be written. And we're still working very hard to make sure all of that reflects the requirements of the open source community. I applaud the EU, first of all, for having the will to tackle these problems, because we don't seem to have the will here in the US to tackle some of them.
But secondly, I applaud their approach because it is a, we may not get it right the first time, but we'll keep working at it till we do, sort of approach to these things. And I think that's the right thing to do, especially in a quickly changing world. But Mike, that kind of brings me to pivot or segue into what I wanted to talk a little bit more about today, which is securing open source software.
Yeah. It's a problem, right? So I grew up in a time where we used to say open source software is more secure by definition because all of these extra eyes are on it, and the code's available for everyone to see.
And then we found out, yeah, not everyone looks at the code, not everyone's testing it. Open source software is not perfect, neither is commercial software. But our quest to make open source software more secure, without getting locked in, without having to abandon open source and so forth, doing it on a global scale, it's not easy.
It could be a bit of a maze, a bit of a rat's nest for people. I actually think of the problem a little bit differently, because as bad as it is, and as challenging as it is in terms of securing open source software, securing the open source upstream projects in many ways is the easy part. Because let's say there's a vulnerability that's discovered in a project and it gets fixed upstream.
That fix can be made available and published pretty quickly. And the open source project has done its work. It does responsible disclosure.
It tells the world that this bug is now fixed, and it's time to update your systems. The problem is a single open source project could be used in tens of thousands, hundreds, millions of different applications running, in some cases banks, insurance companies, utilities, critical infrastructure. Right?
The hard part is actually making sure that everybody that's running these downstream consumer applications- Okay ... and systems are aware and are quickly updating. And I was just reading a study yesterday from JP Morgan, that was talking about the fact that the time for vulnerability exploitation is actually down now to zero days.
And Linus Torvalds- No, it's measured in hours, in minutes. Yeah, and Linus Torvalds has publicly said that the correct approach is that if you find a vulnerability that's been discovered by AI, you have to assume that it's already public. Because if your AI has found it, the other guy's AI has found it too.
Now, so we've been- Yep ... at the Eclipse Foundation, we've been working right on the forefront of this whole problem since day one. We were part of one of the organizations that had access to the Mythos preview through Project Glasswing, through our involvement with the Alpha Omega project.
And so, we've scanned all of our projects. We've discovered on the order of 1,200 vulnerabilities. Wow.
30% of which are high or critical. Hmm. And we're now working our way through that and triaging that, working with our projects to get all of those fixed.
It's a massive job. But I do think, and still, I want to emphasize, as big as it is for us to do that with our projects and our community, the downstream consumers have a bigger job. And I mentioned earlier that we have a lot of projects in IoT and edge compute.
Let's remember that OT, like operations technology, is separate from IT, information technology. OT, there's a lot of complexity in updating systems, right? If you have to send a guy in a helicopter to update a compressor pump on a pipeline, that's a big deal Right.
These are not small cows. Some of them are just not upgradable. Look, in a past life, one of the companies I co-founded, US Department of Interior, US Geological Survey, good customer of ours.
They've got sensors on the Mariana Trench measuring earthquakes underwater. They've got sensors on the Himalayan Mountains measuring earthquakes. It's not an easy thing to send someone over there and upgrade those.
They weren't even made upgradable. You've got to replace the sensors. Yeah.
But that's a passive sensor, right? Yeah. When you're talking about water treatment, sewage treatment, electrical utilities- Well, that becomes critical ...
yeah. Those can be much more dire. Now, I think- Yep ...
I want to talk a little bit about where we are now in the journey. Let's remember, here we are in late July. The first news about Mythos, and the announcement of Project Glasswing and all of that kind of stuff was, what?
Late March, early April? Four. So we're talking- I was going to say four months ago.
Yeah, three, four months ago. And it takes the world a little bit of time to react to these sorts of things. And of course, the open source community is grappling with this.
I think we're getting to the point where we can claim that we've got kind of, we're getting a handle on what we need to do for our projects. As I mentioned before, I still think there's a huge challenge with the downstream applications to figure out their stuff. But what we're seeing is, you remember that famous XTCD cartoon where the guy says, "There's 12 standards doing the same thing.
" Right. Exactly. I'm already counting, what?
One, two, three, four, six different initiatives that claim that they're going to solve this for the open source community, right? The White House announced their Gold Eagle project. The Linux Foundation announced Secrittes.
IBM and Red Hat have Lightwell. GateChain has- Microsoft ... yeah.
Yesterday, NVIDIA announced the Open Secure AI Alliance. Finos has Ocera. We already have a real plethora of these initiatives out there.
But I do think that everything that's happened so far is necessary but not sufficient to really solve the problem. Because I do think that this is going to have to be a global initiative, and every initiative that I just rattled off is based in the US, including building repositories of all the known vulnerabilities on US soil available only to members. To actually build global cyber resilience is going to involve public-private partnerships, and are going to have to make sure that these, both from a technical and governance point of view, that these are federated solutions where- Yes ...
at the nation-state level, they don't have to worry about being cut off. At a foundation level, we don't have to worry about somebody forking our projects needlessly, but also, we don't want to be cut off. These are great initiatives.
They're all trying to help. They're all well-intentioned. But we're not done yet.
There's still work- No ... that needs to happen here before- Mike, I just wrote an article today on this, which is, it's great that NVIDIA is shepherding this because $5 trillion goes a long way. But, this is something that was made for a foundation.
This was something that was made for a global effort. Yes, the guys who have that kind of money deserve a seat at the table, but everybody has to have a say, and everyone has to benefit from this. It can't be for the big guys.
It can't just be for the people with the large purse. And I don't think- It's got to be for everyone I don't think it can just be for one country either. And it can't be for all country, or it can't just be for two countries either, because I think that's a danger we run in here.
We think of, it's a bipolar world. It's China or the US, US or China. You know what?
The EU, the rest of Asia- Yeah ... the Middle East. South Korea.
Japan. It's a big world out there. It is.
And, even in the Middle East, one minute they look at the Chinese solutions, the next minute they're moving to the US solutions because they were promised some missiles or something, who the heck knows. But, we need that. Is that something the Eclipse Foundation's willing to step up to?
Absolutely. We're going to be working on that over the next couple of months. Of course, it is the summer months, so it'll be a little bit of time.
But, again, we don't want to necessarily lead an alternate solution. We want to be part- Part of it ... of the global solution.
Yes. I think that's a really important distinction. This is not a land grab and say, we're going to solve the problem for the world.
It's a, we're going to have to figure this out together, folks. I get you. Hey, Mike, I promised you it's going to be only a 15-minute interview, and we're 10 minutes over that.
We'll have to continue this discussion. As I mentioned, I'd love to have you on Open Current with Margaret and I, and we can continue. SUSE is obviously based in Europe as well.
Yep. And, I'd love to continue the conversation with you on it. It'd be my pleasure.
Glad to come back anytime. Thank you for coming here on Techstrong TV. I appreciate it.
My pleasure. All righty. Mike Milinkovich, Executive Director, Eclipse Foundation, talking open source and security here on Techstrong TV.
We're going to take a break. We'll be back in a minute.