Backlash mounts over NHS England's open-source code withdrawal

An open letter opposing NHS England's decision to pull its open-source software from public view amid AI hacking fears has garnered 682 signatures, including from author Cory Doctorow and former health secretary Matt Hancock. Critics argue the policy undermines transparency and security in taxpayer-funded code.

As reported earlier this week, NHS England directed staff on May 1 to privatize all existing and future open-source repositories by May 11, citing risks from AI models like Anthropic's Mythos, which recently demonstrated finding software flaws. The policy, which contradicts prior NHS standards mandating open-sourcing of public-funded code, has faced swift opposition.

A co-authored open letter has attracted 682 signatures, decrying the move as harmful to transparency and security. Signatories include Cory Doctorow and former UK health secretary Matt Hancock, who called it a 'huge mistake' on LinkedIn: 'One of the smartest things the NHS has done in recent years is open-source its code. Taxpayers paid for it, so taxpayers should benefit from it. But the practical case is just as strong: open source code is more rigorously tested, more secure, and allows the best minds anywhere in the world to build on top of it.'

Vlad-Stefan Harbuz at the University of Edinburgh, a letter co-author, used Mythos to scan existing public NHS code, uncovering severe vulnerabilities that he responsibly disclosed. 'It’s the helpers that we’re hurting by making things closed source, not the attackers,' he said.

Terence Eden, experienced in UK Civil Service data openness, echoed the sentiment, calling open-source 'non-negotiable' for trust in healthcare tools. Despite concerns, the UK AI Security Institute assessed Mythos as posing risks only to 'small, weakly defended and vulnerable enterprise systems,' with no threat to secure networks.

NHS England maintains the restriction is temporary: 'We will continue to publish source code where there is a clear need.' The UK Department of Health and Social Care did not comment.

관련 기사

Tech leaders announcing Linux Foundation's AI-powered cybersecurity initiative for open source software with major partners.
AI에 의해 생성된 이미지

Linux Foundation announces AI security initiative with tech partners

AI에 의해 보고됨 AI에 의해 생성된 이미지

The Linux Foundation has launched a new initiative using Anthropic's Claude Mythos preview for defensive cybersecurity in open source software. Partners include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan, Microsoft, NVIDIA, and Palo Alto Networks. The effort aims to secure critical software amid the rise of AI for open source maintainers.

NHS England is pulling its publicly available software from view due to concerns over AI models capable of hacking. The move reverses long-standing open-source policies for taxpayer-funded code. Security experts call the decision unnecessary and counterproductive.

AI에 의해 보고됨

A surge in AI written code submissions is overwhelming volunteers who maintain open source software, leading some to quit the field entirely.

Daniel Stenberg, creator of the widely used curl program, draws parallels between his project and a cyberattack that nearly succeeded two years ago. In an interview in Huddinge, he stresses the importance of trust in open-source software underpinning the internet. An expert warns he could theoretically shut down half the internet.

AI에 의해 보고됨 사실 확인됨

A recent podcast episode raised concerns that the UK government’s growing use of AI tools in public services—and potentially in elements of legislative work—could increase security and sovereignty risks tied to overseas providers.

The government has decided to launch an inquiry into the regions' journal systems in healthcare. The announcement has sparked joy among doctors in Dalarna who have long criticized the Cosmic system.

AI에 의해 보고됨

Germany's financial regulator BaFin has warned banks about risks from Anthropic's Claude Mythos AI model, following US Treasury alerts. The model autonomously detects IT vulnerabilities at scale, potentially accelerating cyberattacks. US banks are testing it amid restrictions.

 

 

 

이 웹사이트는 쿠키를 사용합니다

사이트를 개선하기 위해 분석을 위한 쿠키를 사용합니다. 자세한 내용은 개인정보 보호 정책을 읽으세요.
거부