Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Supply Chain Updates

Gossamer tool aims to defend open source projects against SolarWinds-style supply chain attacks

usscmc by usscmc
January 6, 2021
Gossamer tool aims to defend open source projects against SolarWinds-style supply chain attacks
Share on FacebookShare on Twitter

Efforts to secure WordPress and Composer tracked on new website

Gossamer Project aims to defend open source projects against SolarWinds-style supply chain attacks

The software supply chain attack against IT infrastructure vendor SolarWinds last year has served to revive interest in technologies that might mitigate against this kind of attack.

Last month, the attack impacted numerous federal government agencies as well as Microsoft and threat detection firm FireEye.

One promising project aiming to prevent such incidents is Gossamer, which is billed as offering supply chain security for open source software.

Gossamer uses a combination of cryptographic signatures and transparency logs in order to safeguard software updates from tampering by making any malfeasance apparent.

Transactions (such as issuing an update or adding a software signing key) are published on an append-only cryptographic ledger. The technology offers a means to verify who released an update as well as its authenticity.

Tainted supplies

SolarWinds’ Orion software update platform was compromised in or around March 2020, nine months before the problem was detected by FireEye in December.

Previous software supply chain attacks have included the infection of the M.E.Doc tax and financial reporting package mandated by the Ukrainian government with NotPetya, a destructive strain of malware back in 2017.

The NotPetya attack disrupted the operation of multiple international firms and caused millions of dollars of damages with victims including FedEx and shipping giant Maersk.

Paragon Initiative Enterprises (PIE), the PHP security and applied cryptography experts behind the technology, foresees a variety of use cases for the technology, including in WordPress’ Automatic Updates for Themes and Plugins, Composer (the PHP dependency manager), and NPM (the Node.js dependency manager).

The development of Gossamer long predates SolarWinds which nonetheless serves as a “grim reminder” of the type of vulnerabilities IT suppliers are face with, PIE told The Daily Swig.

Significant revisions

As this timeline illustrates, the genesis of the Gossamer project dates way back to July 2014. The project has gone through numerous significant revisions in the six and a half years since its inception.

Earlier this month, PIE launched a website to track the multiple ongoing parallel efforts to secure WordPress and Composer with Gossamer integration.

The developer tools aspect of the project is described as two-thirds complete and “in progress”, whilst WordPress and Composer integration are both pending.

Asked to explain how Gossamer projected against SolarWinds-like software supply chain attacks, a spokesperson for PIE told The Daily Swig: “The mechanism in Gossamer that helps with a SolarWinds-like attack is the attestations, which were specified in libgossamer in 2019.”

Read more of the latest secure development news

Attestations allow third-party providers to assert some property about other software updates published by other providers.

The spokesperson added: “The ultimate goal of Gossamer is to ensure that PHP and WordPress developers have the capability of signing their open source software and verifying that the dependencies they install from third-party developers is authentic,” a roadmap for the project explains.

“When we have succeeded at securing the PHP ecosystem, we intend to assist other ecosystems (eg Java, Node.js, Python, Ruby) in securing their open source software supply chains.”

RELATED Microsoft downplays threat after admitting SolarWinds hackers access source code

usscmc

usscmc

No Result
View All Result

Recent Posts

  • How Hapag Lloyd captured a major market share in the Container Shipping Industry in USA
  • Why USA’s East Coast is the Favorite Destination for Manufacturing Companies
  • How Trade Relations Between the USA and UK Improved After Keir Starmer Became Prime Minister
  • Tips and Tricks for Procurement Managers to Handle Their Supplier Woes
  • The Crazy Supply Chain of Walmart Spanning Across the Globe

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Antispam
  • Contact Us
  • Disclaimer
  • Home
  • Privacy Policy
  • Terms of Use

© 2025 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us

© 2025 www.usscmc.com