All news

Open source is given restrictions

The Ministry of Digital Development is preparing a unified regulation of existing repositories instead of the planned unified Russian repository with open source code from 2020. This may include unified cybersecurity requirements. Experts emphasize that the rejection of a unified repository is entirely logical in connection with the solutions existing on the market and that unified state requirements ensure compliance with "at least the minimum acceptable level of security" of the database.

Ilya Massukh, director of the Center for Import Substitution in Information and Communication Technologies, reported that the Ministry of Digital Development is preparing a document defining the rules and requirements for a Russian repository instead of a single Russian repository with open source code. PROF-IT conference, October 10. According to Mr. Massukh, the Ministry of Digital Development has decided to abandon the single code repository (Kommersant wrote on April 18 that the Ministry of Digital Development is leaning toward making such a decision) and instead of it there is now a "Russian repository of concepts" at a high level of readiness", which includes uniform requirements for storage security. The Ministry of Digital Development told Kommersant: "We are currently working with interested departments and organizations on the concept of creating and developing a storage ecosystem located on the territory and jurisdiction of the Russian Federation."

The idea of ​​Microsoft to create an analogue of the American GitHub came to the Russian authorities in 2020. At that time, the Ministry of Economy planned to allocate 2.1 billion rubles for the project. However, experts believed that "status codes" would not be in demand among developers (see Kommersant, January 20, 2020). This idea was developed after the start of military action in Ukraine. GitHub blocked the accounts of several Russian companies, banks, and a number of private users (see Kommersant, February 28, 2022).

"The topic of Russian free software repositories was controversial at first, because it was unclear who needed a single repository. Alexey Smirnov, chairman of the board of directors of FOSS Bazalt, explains: "The idea was put forward to create a kind of 'repository of a repository' that would integrate existing private repositories and requirements. "We will be able to prepare," he said.

Nikolay Sokornov, head of software development at Reksoft, explains that moving away from a single code repository is “the right plan,” since distributed code storage systems are more secure. “If you have one shared repository, this can be a disadvantage. A security issue or technical failure can affect several projects at once. Splitting into several repositories increases flexibility and stability,” adds Sergey Kondratenko, technical director of IT company Noosoft.

"The introduction of the requirement is especially relevant for state-owned enterprises and large corporations, where the use of open source requires additional precautions," says Mr. Kondratenko. "Insufficient data protection can lead to the leakage of confidential information or intellectual property," added Anatoly Peskovsky, an expert in the security analysis department of the company Informzashchita.

Avenir Voronov, technical director of the logistics division of Korus Consulting, says that most developers will use open-source platforms from major players in the market, and storage requirements are advisory, not mandatory. “I am convinced that standards should not be ‘limited’ within the country, but should be exported. “We believe that through uniform national requirements we will be able to ensure at least an acceptable minimum level of security,” he says.


Source: "Коммерсантъ". Издательский дом"Коммерсантъ". Издательский дом

Loading news...

Loading news...

Speaks and shows

Loading news...

Between robots and migrants

Loading...
follow the news
Stay up to date with the latest news and updates! Subscribe to our browser updates and be the first to receive the latest notifications.
© АС РАЗВОРОТ.