6月15日是什么日子| 内衣34是什么码| 双手发抖是什么原因| 喝啤酒不能吃什么| 房中术是什么意思| 有什么四字词语| gtp是什么意思| 土豆可以做什么美食| 身份证后六位代表什么| 白皮书什么意思| 唐塞是什么意思| 女性吃大肠有什么好处| 拉肚子吃什么水果好| 阿莫西林什么时候吃| 青筋凸起是什么原因| 世界上什么东西最大| 依巴斯汀片是什么药| 硬卧是什么样子的| 雄性激素过高是什么原因| 喝中药不能吃什么东西| 四月二十九是什么星座| 扮猪吃老虎什么意思| 久站腰疼是什么原因| 924是什么星座| 右耳朵热代表什么意思| 美国为什么不敢打伊朗| 尿液发黄是什么病| 无条件是什么意思| 红薯不能和什么一起吃| punk什么意思| 虎属什么五行| 8月23日是什么星座| 莫欺少年穷是什么意思| 吴亦凡为什么叫牛| 孵化是什么意思| 拜谢是什么意思| 大肝功能是检查什么| 平起平坐代表什么生肖| 干净的反义词是什么| 并发是什么意思| 8月20号什么星座| 澍在人名中读什么| 接触是什么意思| 尿酸低有什么危害| 一朝一夕是什么意思| 胸部彩超能检查出什么| 做胃镜之前需要注意什么| 湉是什么意思| 执业药师什么时候报名| 什么样的夜晚| 什么瓜不能吃| CNN什么意思| 黄辣丁吃什么食物| 角膜塑形镜什么牌子好| 1994属什么生肖| 黄宗洛黄海波什么关系| 支气管激发试验阴性是什么意思| 澄粉是什么粉| 副教授是什么级别| 女人绝经一般在什么年龄段| 诺如病毒吃什么药| hgh是什么意思| 液金是什么| 痱子粉什么牌子好| 11月5号什么星座| 低密度脂蛋白是什么| 什么是2B铅笔| 前列腺肿瘤有什么症状| 眉心中间有痣代表什么| 查岗是什么意思| 半斤八两什么意思| 书中自有颜如玉是什么意思| 做b超需要挂什么科| 晚上扫地有什么说法| 禾加农是什么字| noa是什么意思| 75b是什么罩杯| 一月底是什么星座| 皇帝自称什么| 胆固醇高不可以吃什么食物| 梦见梅花鹿是什么预兆| 叩齿是什么意思| simon是什么意思| 毫无保留什么意思| 润喉咙什么东西最合适| 心肌病是什么症状| 深呼吸有什么好处| 为什么脸上长痣越来越多| 大快朵颐是什么意思| 黄色衣服配什么颜色裤子好看| 老鼠最怕什么气味驱赶| 台风什么时候到福建| 什么是介入治疗| ida是什么意思| 催乳素偏高有什么影响| 月经不调是什么原因| 咖啡对心脏有什么影响| 寿司醋可以用什么代替| 前列腺炎吃什么中药| 属狗的和什么属相最配| 空代表什么生肖| 小孩风热感冒吃什么药| 航班预警是什么意思| 九九重阳节是什么意思| 吃什么水果对胃好| xrd是什么| 男人左眼下有痣代表什么| 诸葛亮长什么样| 炖牛骨头放什么调料| 反复口腔溃疡是什么原因| 跑步穿什么衣服| 硕士研究生是什么意思| 什么的云| 胃动力不足是什么原因造成的| 捭阖是什么意思| 231是什么意思| 放化疗期间吃什么好| 身高别体重是什么意思| 女鼠配什么属相最好| 蝉喜欢吃什么| 飞机杯是什么| 阴部毛变白是什么原因| 耳朵后面有痣代表什么| 狮子座跟什么星座最配| 开黄腔什么意思| hh是什么品牌| 有鸟飞进屋是什么预兆| 一起共勉是什么意思| 向晚的意思是什么| 妤是什么意思| 牛大力和什么泡酒壮阳| 异地补办身份证需要什么手续| 右肺中叶纤维灶是什么意思| 六味地黄丸什么时候吃最好| 强硬是什么意思| 市委讲师团是什么级别| 脚趾头疼是什么原因| 99新是什么意思| 1964年什么命| 牙齿冷热都疼是什么原因| 吃完饭恶心想吐是什么原因| gel是什么意思| 生机勃勃什么意思| 先天性聋哑病属于什么遗传病| 荷花的花语是什么| 取环是什么意思| 香干炒什么菜好吃| 什么体质的人才有季经| 汗疱疹用什么药| 每天吃黄瓜有什么好处| 灰姑娘叫什么名字| lp是什么的简称| 脚背浮肿是什么原因引起的| 雷字五行属什么| 杰五行属性是什么| 楚国什么时候灭亡的| 什么是车震| 白细胞是什么| 外阴瘙痒涂什么药膏| 爬山虎是什么茎| 朝霞不出门晚霞行千里是什么意思| 五红汤什么时候喝最好| 疤痕增生是什么原因| 高血压吃什么药效果好| 慰安妇是什么意思| 眼睛有点模糊是什么原因| 什么是毛囊炎| quilt什么意思| 什么是品牌| 附属是什么意思| 邮件号码是什么| 久视伤血是什么意思| 子宫息肉是什么| alienware是什么牌子| 动销是什么意思| 手肘发黑是什么原因| 婴儿胀气是什么原因| 慕字五行属什么| 西瓜又什么又什么填空| 胃疼能吃什么| 供观音菩萨有什么讲究| 益生菌什么时间段吃效果好| 烫伤后擦什么药好得快| 吃什么食物补肾最快| 孔雀喜欢吃什么食物| notice是什么意思| 什么的波涛| 木兮是什么意思| 尿道炎看什么科室好| 出库是什么意思| 轴向是什么意思| 血管鼓起来是什么原因| 珠海有什么特产| 血糖和尿糖有什么区别| 长期喝咖啡有什么好处和坏处| 肺结核复发有什么症状| b族维生素是什么意思| 卧推80公斤什么水平| 卡拉胶是什么| 蜘蛛吃什么食物| 时尚是什么意思| 怀孕了尿液是什么颜色| 人体7大营养素是什么| 甲状腺功能是什么| 极有家是什么意思| mrmrs是什么牌子| 弟弟的孩子叫姐姐什么| 喝牛奶有什么好处| 闪购是什么| 一的五行属性是什么| 免疫五项能查出什么病| 为什么睡觉会出汗| 莓茶是什么茶| 口舌是什么意思| 宝宝说话晚是什么原因造成的| 杺字五行属什么| 晚上吃什么减肥| 香茗是什么意思| 抱持是什么意思| 没事找事是什么意思| 赫兹是什么| cns医学上是什么意思| 扁桃体发炎发烧吃什么药| 请柬写伉俪什么意思| 寿者相什么意思| 咖喱是什么材料做的| 卵胎生是什么意思| 秋是什么生肖| 三点水一个兆读什么| 左眼屈光不正是什么意思| 断档是什么意思| 养生吃什么最好| 班长是什么军衔| 痛风什么水果不能吃| 高危型hpv阳性是什么意思| 碧根果和核桃有什么区别| 癖是什么意思| 神迹是什么意思| 腋下有异味是什么原因| 婴儿湿疹用什么药膏| 左下眼皮跳是什么预兆| 形同陌路是什么意思| 脾门区结节是什么意思| 伏什么意思| 奶奶的妈妈应该叫什么| 水中加什么擦玻璃干净| 来月经为什么会腰疼| 连可以组什么词| ab型和o型生的孩子是什么血型| 病毒感冒吃什么药| 木梳子梳头有什么好处| 乙肝抗体阳性什么意思| 体外射精什么意思| 脚后跟疼是什么原因引起的| 心脏有早搏吃什么药好| aa什么意思| 枕大神经痛吃什么药| 888红包代表什么意思| 刺身是什么| 喝茶对身体有什么好处| 田可以加什么偏旁| 幼儿贫血吃什么补血最快| 夜里12点是什么时辰| 风湿病是什么原因造成的| 百度Jump to content

老婆太开放!家里浴室被她装成这样,我都害羞了!

From Wikipedia, the free encyclopedia
Core Infrastructure Initiative
Mission statement"To fund open source projects that are in the critical path for core computing functions."
Commercial?No
FounderJim Zemlin
Established24 April 2014 (2025-08-08)[1]
FundingBy donations
StatusSuperseded by the OpenSSF
百度 当然实践中议会直接否决的情况本身就鲜有,循环两次以上就更难有先例了。

The Core Infrastructure Initiative (CII) was a project of the Linux Foundation to fund and support free and open-source software projects that are critical to the functioning of the Internet and other major information systems. The project was announced on 24 April 2014 in the wake of Heartbleed, a critical security bug in OpenSSL that is used on millions of websites.

OpenSSL is among the first software projects to be funded by the initiative after it was deemed underfunded, receiving only about $2,000 per year in donations.[1] The initiative will sponsor two full-time OpenSSL core developers.[2] In September 2014, the Initiative offered assistance to Chet Ramey, the maintainer of bash, after the Shellshock vulnerability was discovered.[3]

The CII has since been superseded by the Open Source Security Foundation.[4]

Heartbleed bug

[edit]
Logo representing Heartbleed

OpenSSL is an open-source implementation of Transport Layer Security (TLS), allowing anyone to inspect its source code.[5] It is, for example, used by smartphones running the Android operating system and some Wi-Fi routers, and by organizations including Amazon.com, Facebook, Netflix, Yahoo!, the United States of America's Federal Bureau of Investigation and the Canada Revenue Agency.[6]

On 7 April 2014, OpenSSL's Heartbleed bug was publicly disclosed and fixed.[7] The vulnerability, which had been shipped in OpenSSL's current version for more than two years,[8] made it possible for hackers to retrieve information such as usernames, passwords and credit card numbers from supposedly secure transactions. At that time, roughly 17% (around half a million) of the Internet's secure web servers certified by trusted authorities were believed to be vulnerable to the attack.[9]

Open-source software

[edit]

According to Linus's law, from Raymond's book The Cathedral and the Bazaar, "Given enough eyeballs, all bugs are shallow."[10] In other words, if there are enough people working on the software, a problem will be found quickly and its fix will be obvious to someone. Raymond stated in an interview that "there weren't any eyeballs" for the Heartbleed bug.[6]

Prior to the CII funding, only one person, Stephen Henson, worked full-time on OpenSSL; Henson approved well over half of the updates to more than 450,000 lines of the OpenSSL's source code.[11] Besides Henson, there are three core volunteer programmers. The OpenSSL Project existed on a budget of $2,000 per year in donations, which was enough to cover the electrical bill, and Steve Henson was earning around $20,000 per year.[8] To gather more revenue for the project, Steve Marquess, a consultant for the Defense Department, created the OpenSSL Software Foundation. This allowed programmers to make some money by consulting for organizations that used the code. However, the foundation brought in less than $1 million per year,[6] and the contract work tended to focus on adding new features rather than maintaining the old ones.[8]

Other open-source software projects have similar difficulties. For example, the maintainers of OpenBSD, a security-conscious operating system, nearly had to shut the project down in early 2014 because it could not pay the electricity bills.[12]

The initiative

[edit]

Jim Zemlin, the executive director of the Linux Foundation, conceived the idea of the Core Infrastructure Initiative not long after Heartbleed was announced, and spent the night of April 23 calling firms for support.[13] Thirteen companies responded and joined the initiative: Amazon Web Services, Cisco Systems, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Rackspace, Qualcomm and VMware.[14][15] The list was mainly determined by who Zemlin knew.[13] Each of the thirteen companies has pledged to donate $100,000 a year for the next three years bringing the initial funding pool to almost $4 million.[16][17][18] An additional five companies?—?Adobe Systems, Bloomberg L.P., Hewlett-Packard, Huawei, and Salesforce.com?—?have since joined the initiative.[19]

The money that the CII pooled was used to fund specific tasks such as providing compensation to developers to work full-time on an open-source software project, conducting reviews and security audits, deploying test infrastructure, and facilitating travel and face-to-face meetings among developers.[2]

The CII was composed of two bodies, a steering committee and an advisory board. The steering committee was made up of representatives from the member companies and other industry stakeholders[2][16] and the committee was in charge of identifying target software projects and approving specific funding to those projects. The advisory board, composed of developers and other stakeholders, provided advice to the steering committee.[2]

Projects backed in 2016

[edit]
Project Name Type Funding (USD) website
Frama-C Developer tool 192,000 [1]
GnuPG System tool or application 60,000 [2]
Network Time Protocol Daemon System tool or application 180,000
OpenSSH System tool or application 50,000 [3]
OpenSSL Developer Library 550,000 [4]
OWASP Zed Attack Proxy Testing tool or project 23,000 [5] Archived 2025-08-08 at the Wayback Machine
Reproducible Builds Testing tool or project 250,000 [6]
The Fuzzing Project Testing tool or project 60,000 [7]
The Linux Kernel Self Protection Project System tool or application 80,000 [8]
NTPsec System tool or application 150,000 [9]
Bouncy Castle Developer Library 15,000 [10]

The Core Infrastructure Initiative also invested 120,000 USD for education to the good practices of open-source development, 120,000 USD in popular open-source project analysis and 95,000 USD for auditing OpenSSL[20]

References

[edit]
  1. ^ a b "Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Rackspace, VMware and The Linux Foundation Form New Initiative to Support Critical Open Source Projects" (Press release). The Linux Foundation. 24 April 2014. Archived from the original on 10 June 2016. Retrieved 25 July 2016.
  2. ^ a b c d "Core Infrastructure Initiative FAQ". The Linux Foundation. Archived from the original on 14 April 2016. Retrieved 25 July 2016.
  3. ^ "Security experts expect 'Shellshock' software bug to be significant". The Times of India. Archived from the original on 2025-08-08. Retrieved 2025-08-08.
  4. ^ "Home". Core Infrastructure Initiative. Retrieved 2025-08-08.
  5. ^ Sullivan, Gail (9 April 2014). "Heartbleed: What you should know". The Washington Post. Archived from the original on 9 May 2014. Retrieved 14 May 2014.
  6. ^ a b c Perlroth, Nicole (18 April 2014). "Heartbleed Highlights a Contradiction in the Web". The New York Times. Archived from the original on 8 May 2014. Retrieved 14 May 2014.
  7. ^ Grubb, Ben (15 April 2014). "Heartbleed disclosure timeline: who knew what and when". The Sydney Morning Herald. Archived from the original on 25 November 2014. Retrieved 14 May 2014.
  8. ^ a b c Stokel-Walker, Chris (25 April 2014). "The Internet Is Being Protected By Two Guys Named Steve". BuzzFeed. Archived from the original on 15 May 2014. Retrieved 15 May 2014.
  9. ^ Mutton, Paul (April 8, 2014). "Half a million widely trusted websites vulnerable to Heartbleed bug". Netcraft Ltd. Archived from the original on November 19, 2014. Retrieved May 22, 2014.
  10. ^ Young, Eric S. Raymond ; with a foreword by Bob (2008). The Cathedral & the Bazaar Musings on Linux and Open Source by an Accidental Revolutionary (2nd ed.). Sebastopol: O'Reilly Media, Inc. p. 30. ISBN 978-0596553968.{{cite book}}: CS1 maint: multiple names: authors list (link)
  11. ^ Babbage (6 May 2014). "A heartbeat from disaster". The Economist. Archived from the original on 15 May 2014. Retrieved 15 May 2014.
  12. ^ Finley, Klint (22 January 2014). "Bitcoin Baron Keeps a Secretive Open Source OS Alive". Wired. Archived from the original on 11 May 2014. Retrieved 15 May 2014.
  13. ^ a b Rosenblatt, Seth (24 April 2014). "Tech titans join forces to stop the next Heartbleed". CNET. Archived from the original on 17 May 2014. Retrieved 15 May 2014.
  14. ^ "Core Infrastructure Initiative". The Linux Foundation. Archived from the original on 10 September 2016. Retrieved 25 July 2016.
  15. ^ Finley, Klint (24 April 2014). "Twitter Facebook RSS Google, Facebook, and Microsoft Team Up to Stop Another Heartbleed". Wired. Archived from the original on 14 May 2014. Retrieved 15 May 2014.
  16. ^ a b Perlroth, Nicole (24 April 2014). "Companies Back Initiative to Support OpenSSL and Other Open-Source Projects". Bits. The New York Times. Archived from the original on 30 April 2014. Retrieved 29 April 2014.
  17. ^ Vaughan-Nichols, Steven J. (24 April 2014). "Cisco, Microsoft, VMware, and other tech giants unite behind critical open-source projects". ZDNet. Archived from the original on 27 April 2014. Retrieved 29 April 2014.
  18. ^ Warren, Christina (24 April 2014). "Facebook, Google, Microsoft Join Forces to Prevent Another Heartbleed". Mashable. Archived from the original on 29 April 2014. Retrieved 29 April 2014.
  19. ^ "The Linux Foundation's Core Infrastructure Initiative Announces New Backers, First Projects to Receive Support and Advisory Board Members" (Press release). The Linux Foundation. 29 May 2014. Archived from the original on 11 July 2017. Retrieved 23 June 2014.
  20. ^ "Core Infrastructure Initiative 2016 Annual Report" (PDF). The Core Infrastructure Initiative. Archived from the original on 6 November 2017. Retrieved 14 April 2017.
[edit]
傻瓜是什么意思 气血不足是什么引起的 肾结石不能吃什么 刮宫和流产有什么区别 治疗肝脏硬化要吃什么药好
6月13日什么星座 甘油三酯高是什么原因引起的 银手镯发黄是什么原因 至死不渝下一句是什么 艾司唑仑片是什么药
于无声处是什么意思 m2是什么单位 九月二十三是什么星座 成人受到惊吓吃什么药 自言自语是什么病
结核杆菌dna检测是检查什么 和合是什么意思 冠心吃什么药好 钟乳石是什么 脊髓炎是什么病
受精卵着床有什么感觉sanhestory.com 附属医院是什么意思hcv8jop1ns4r.cn 说什么道什么hcv8jop6ns2r.cn 微波炉不热是什么原因hcv8jop5ns9r.cn 什么的河水cj623037.com
大米粉做什么好吃hcv8jop0ns9r.cn 捉摸不透是什么意思hcv8jop6ns9r.cn 属猪的护身佛是什么佛hcv8jop9ns6r.cn 白身是什么意思hcv7jop9ns6r.cn 2017 年是什么年xscnpatent.com
梦见梨是什么意思hcv7jop4ns5r.cn 上次闰六月是什么时候hcv8jop3ns9r.cn 为什么家里不能放假花hcv8jop8ns2r.cn 为什么月经迟迟不来hcv8jop3ns4r.cn 上午九点到十一点是什么时辰hcv9jop7ns4r.cn
中暑什么症状hcv8jop3ns0r.cn 男性内分泌失调有什么症状bysq.com 什么是脚气hcv8jop7ns5r.cn 乙基麦芽酚是什么东西hcv9jop4ns8r.cn 卧室放什么花最好健康hcv8jop7ns8r.cn
百度