Backlash mounts over NHS England's open-source code withdrawal

An open letter opposing NHS England's decision to pull its open-source software from public view amid AI hacking fears has garnered 682 signatures, including from author Cory Doctorow and former health secretary Matt Hancock. Critics argue the policy undermines transparency and security in taxpayer-funded code.

As reported earlier this week, NHS England directed staff on May 1 to privatize all existing and future open-source repositories by May 11, citing risks from AI models like Anthropic's Mythos, which recently demonstrated finding software flaws. The policy, which contradicts prior NHS standards mandating open-sourcing of public-funded code, has faced swift opposition.

A co-authored open letter has attracted 682 signatures, decrying the move as harmful to transparency and security. Signatories include Cory Doctorow and former UK health secretary Matt Hancock, who called it a 'huge mistake' on LinkedIn: 'One of the smartest things the NHS has done in recent years is open-source its code. Taxpayers paid for it, so taxpayers should benefit from it. But the practical case is just as strong: open source code is more rigorously tested, more secure, and allows the best minds anywhere in the world to build on top of it.'

Vlad-Stefan Harbuz at the University of Edinburgh, a letter co-author, used Mythos to scan existing public NHS code, uncovering severe vulnerabilities that he responsibly disclosed. 'It’s the helpers that we’re hurting by making things closed source, not the attackers,' he said.

Terence Eden, experienced in UK Civil Service data openness, echoed the sentiment, calling open-source 'non-negotiable' for trust in healthcare tools. Despite concerns, the UK AI Security Institute assessed Mythos as posing risks only to 'small, weakly defended and vulnerable enterprise systems,' with no threat to secure networks.

NHS England maintains the restriction is temporary: 'We will continue to publish source code where there is a clear need.' The UK Department of Health and Social Care did not comment.

Verwandte Artikel

Tech leaders announcing Linux Foundation's AI-powered cybersecurity initiative for open source software with major partners.
Bild generiert von KI

Linux Foundation announces AI security initiative with tech partners

Von KI berichtet Bild generiert von KI

The Linux Foundation has launched a new initiative using Anthropic's Claude Mythos preview for defensive cybersecurity in open source software. Partners include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan, Microsoft, NVIDIA, and Palo Alto Networks. The effort aims to secure critical software amid the rise of AI for open source maintainers.

NHS England is pulling its publicly available software from view due to concerns over AI models capable of hacking. The move reverses long-standing open-source policies for taxpayer-funded code. Security experts call the decision unnecessary and counterproductive.

Von KI berichtet

A surge in AI written code submissions is overwhelming volunteers who maintain open source software, leading some to quit the field entirely.

Daniel Stenberg, der Entwickler des weit verbreiteten Programms curl, zieht Parallelen zwischen seinem Projekt und einem Cyberangriff, der vor zwei Jahren beinahe erfolgreich gewesen wäre. In einem Interview in Huddinge betont er die Bedeutung von Vertrauen in Open-Source-Software, die das Fundament des Internets bildet. Ein Experte warnt, dass er theoretisch die Hälfte des Internets lahmlegen könnte.

Von KI berichtet Fakten geprüft

A recent podcast episode raised concerns that the UK government’s growing use of AI tools in public services—and potentially in elements of legislative work—could increase security and sovereignty risks tied to overseas providers.

The government has decided to launch an inquiry into the regions' journal systems in healthcare. The announcement has sparked joy among doctors in Dalarna who have long criticized the Cosmic system.

Von KI berichtet

Die deutsche Finanzaufsicht Bafin hat Geldhäuser vor den Gefahren des neuen KI-Modells „Mythos“ des US-Unternehmens Anthropic gewarnt. Das System kann IT-Sicherheitslücken eigenständig und im großen Maßstab aufspüren, was Angreifer nutzen könnten. US-Banken testen das Modell bereits.

 

 

 

Diese Website verwendet Cookies

Wir verwenden Cookies für Analysen, um unsere Website zu verbessern. Lesen Sie unsere Datenschutzrichtlinie für weitere Informationen.
Ablehnen