United Nations · Open Source Security

Security Should Be a Strategy,
Not a Cost

The power of dedicated open source security engineers over volunteers alone.
Mila Zhou · AWS Open Source
PostgreSQL User Group Organizer
Chair, Marketing Advisory Council, OpenSSF
Late 2021

“I’m sorry.
It’s my fault.”

Christian Grobmeier, Log4j maintainer — to his son,
when the game flagged the flaw in his code.

Log4j / Christian Grobmeier

The most severe vulnerability
in the history of the internet.

A volunteer had to walk away from his own kid —
to defend half the internet. For free.

“Free to use”
is not
“free to maintain.”

We don’t run air traffic control on goodwill.

But we run the code it depends on — exactly that way.

FAA air traffic control tower
Photo: FAA tower, Philadelphia · CC BY 4.0
2025

The year open source
drowned in AI slop.

curl runs in ~30 billion devices.

Every phone. Every car. Every payment system in this room.
Maintained by Daniel Stenberg — for almost 30 years.

“The Pressure” · May 2026

4–5×

the report volume of 2024

More than one

vulnerability report — every single day

Higher quality than ever — each one takes real time to verify, patch, disclose.

Daniel Stenberg, 'The Pressure' blog post

“For the first time in my life,
my wife voiced concerns
about my work hours.”

Daniel Stenberg, curl maintainer

This is not a curl problem.
It’s the model.

We asked goodwill to carry the security of the entire digital world — more weight than it can bear. So it’s buckling.

< 5%

of the open source vulnerabilities AI surfaced in recent months have been patched.

Finding them is automated now. Fixing them isn’t.

The response · funding the work

Alpha-Omega — a fund inside the Linux Foundation

70+
grants since 2022
$20M+
into critical ecosystems
+$12.5M
added March 2026

This week: ~20 organizations — incl. banks & telecoms — launched Akrites, a coordinated defense. A signal of how seriously this is now taken.

What a paid engineer does — that a volunteer can’t

Alpha-Omega funded two in the Python world:

Two-factor authentication · the volunteer gap

Supported since 2019. Adoption stalled for years — no one had the time or the mandate.

A paid engineer drove it through.

Today: 100% of PyPI packages are published with 2FA on.

The hard, unglamorous work

SBOMs — an ingredient label for software. Soon required by the EU Cyber Resilience Act.

Complex, and the standards meetings run nine-to-five — volunteers can’t be in the room. Seth could. PEP 770.

Make it someone’s job

Pay someone, and it’s their job.
The 2 p.m. meeting. The 2 a.m. crisis. They show up.

Curl “Summer of Bliss” —
“you get a support contract and we get to read about it earlier.”

curl Summer of Bliss announcement

Stop treating its security as a cost —

and start treating it as the strategy.

Thank you.

Mila Zhou · AWS Open Source

Let’s fund it — together.

← → or Space to navigate · F for fullscreen