Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The way I see it, there are multiple grades of free software. There is difference between downloading a linux distro or apache project and downloading some dude's python library from pip.

Any software used on government systems has to go through an accreditation process. This is to prevent you from pulling in some random code that may have security vulnerabilities or backdoors. Just because it is open source doesn't mean it is secure.

As an example, we've had to run security scans on jquery for god's sake and justify every occurence of random number generation to make sure it wasn't used for anything security related....

There are other things like warranty, support, size of the community, etc...

Overall, GSA is one of the best agencies when it comes to open source. It has definitely come a long way, but still a long way to go.



> Overall, GSA is one of the best agencies when it comes to open source. It has definitely come a long way, but still a long way to go.

I think it's never been a better time to get approvals/clarifications/etc for open source at GSA. GSA's CIO posted a supportive comment on this issue here, w/r/t the White House's proposed source code policy (and 18F's comment on it), and reinforced that GSA has an "open source first" internal policy for the enterprise on the books:

https://github.com/WhiteHouse/source-code-policy/issues/73#i...

Of course, policies only give people the space to spend energy making the policy really mean something -- which I encourage you to do. Find me on 18F's GitHub or GSA email any time if you have ideas you want to talk about.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: