ICANN report: DNS runs on FOSS
ICANN's Security and
Stability Advisory Committee (SSAC) has announced
a report
on "the critical role of Free and Open Source Software (FOSS)
within the Domain Name System (DNS)
". The report is aimed at
policymakers and examines recent cybersecurity regulations in the US,
UK, and EU as they apply to FOSS in the DNS system; it includes
findings and guidelines "to strengthen the FOSS ecosystem that is
critical to the secure and stable operation of the Internet
". From
the report's summary:
This ecosystem depends on a global network of maintainers and contributors who are often unpaid volunteers. While many are unpaid volunteers, the DNS space is unique in also relying on a handful of long-lived maintenance organizations. This creates a model based on community collaboration rather than the commercial contracts that define a traditional software supply chain, which introduces unique risks related to financial sustainability for the maintenance organizations and maintainer burnout for volunteers.
These unique characteristics mean that regulatory frameworks designed for proprietary software may not be well-suited for FOSS and therefore could have severe unintended consequences to the stability of critical Internet infrastructure.
Thanks to SSAC member Maarten Aertsen for the tip.