What Is a Software Bill of Materials (SBOM)? – BizTech Magazine

What Is the Purpose of a Software Bill Of Materials?

The goal is to provide transparency into the composition and provenance of software, says Moyle. For the customer, you can trace the provenance and composition of what you own, and the developer can keep track of what's in their dependencies so they can offer more transparency to their customers.

Its also important for managing potential risk. SBOMs are often compared with nutritional information labels that list all the ingredients contained in a food item. The reason for that? Consider the experience of someone allergic to a commonly occurring ingredient like soy. Obviously, theyd avoid products that make first-order use of soy products that are obviously made out of it, like tofu, says Moyle. But what about second- and third-order usage? For example, a cake with chocolate icing where the chocolate in the icing uses soy lecithin as an emulsifier. Theyd still need to know about that, right? Even a small dose of the allergen can be problematic depending on the severity of the allergy.

How does that tie to SBOMs? In some situations, dependencies in software can introduce risk in a similar way; for example, when there are severe vulnerabilities in commonly occurring and widely deployed software components, says Moyle.

MORE FROM BIZTECH: Learn key lessons about protecting your organization from cyberattack.

SBOMs help make it possible to protect your supply chain because they identify what is included in your supply chain, says IDCs Al Gillen. Its like surveying your home for vulnerable access points to know where to install alarm sensors. By providing insights into software components, organizations may not merely identify potential risks but, ideally, identify them early enough that they dont make it to a final product.

That protection will be imperative as supply chains become increasingly vulnerable. In 2021, the European Union Agency for Security estimated that the number of attacks on the supply chain would increase fourfold from the previous year, Worthington says. When all it takes is a single vulnerability to disrupt a supply chain, knowing what that vulnerability might be and how to eliminate it is critical.

Experts caution, however, that SBOMs arent foolproof. Collecting, managing, inventorying, and making use of the data from them is a large, complicated exercise, says Moyle. Yes, it makes the problem of software vulnerabilities potentially more manageable, but its not magic and won't fix all problems. Worthington agrees: An SBOM is only a piece of the puzzle. Securing your software supply chain requires people, process and technology.

Because SBOMs can be code heavy, reproducing a sample here would be difficult. However, those interested can find a few examples provided by Worthington at Github, SPDX and the NTIA.

See the rest here:

What Is a Software Bill of Materials (SBOM)? - BizTech Magazine

The State Of The IBM i Base 2022: Third Party Software Conundrum – IT Jungle

April 11, 2022Timothy Prickett Morgan

Aside from death, most problems are not intractable. But people surely can be, and sometimes are. But luckily not often, and the thing about people is that, generally speaking, they can be reasonable when they are reasoned with. It is with all of this in mind that we come to the next in the State of IBM i Base stories for 2022, where we want to talk about the software trap that the remaining OS/400, i5/OS, and some IBM i shops have gotten themselves into and how we might help them get out of it to the mutual benefit of all.

As best we can figure, based on the data from the annual HelpSystems survey of the IBM i base, about two-third of the companies that take the survey have consistently said that they have homegrown applications running on their systems something that was not asked in the original surveys from years gone by and a thing that I pointed out to HelpSystems and had the question changed because I simply did not believe that most of the base had third-party applications. Over the decades, the readers of The Four Hundred have consistently been do-it-yourself application shops and I just simply did not believe that somewhere along the way that changed so dramatically.

In theory, that means that two-thirds of the base is not facing what I will call the third-party software conundrum, where they are stuck on old releases without maintenance and no easy or cost-effective way to get those applications current. In practice, many IBM i shops are facing massive technical debt in their code, a lack of people with skills and insufficient funding to update their older RPG III, RPG IV, and ILE RPG applications to free form RPG, or worse yet, have lost the source code for their applications. And as a consequence they are just as stuck as anyone using an old suite of applications from a vendor that ended up inside of Infor or Oracle or one of the few remaining mid-sized ERP vendors catering to the IBM i crowd.

Part of the problem with regard to third-party application software, I think, is the fact that there is a long history of open source application code in the IBM midrange, and another part of the problem is the long practice of selling software with a perpetual use license that also has an annual software maintenance fee.

The fact that many of the thousands of application suites available for System/3X and AS/400 systems were available as source code meant that companies buying the software could indulge in customizing software at a level that we have generally not seen in the application space heretofore. There are plenty of IBM midrange shops that used a mix of custom code and heavily customized third-party code to create the systems that run their businesses, and at some point, the code has changed so much that there is no point in paying third-party maintenance on it. Companies could not upgrade to new application versions and suites form the vendor if they wanted because all of those customizations would have to be done again. So it is not just a matter of people not wanting to pay maintenance on application software it would not get them anything if they had.

There are, of course, IBM i shops that have done a modest amount of customization on third-party code and when the budget gets tight, they stop paying for maintenance on it because they are not changing it, even if they do have the source code. And these days, with modern ERP, CRM, and SCM suites, they probably are not getting the source code for the new software unless it is grandfathered into their vendor contracts.

But even absent that, the way these licenses are sold were always a budgetary headache, and the problem is that people costs rise with gross domestic product and do not have Moores Law economic scaling, where things get cheaper per unit of capacity with each passing year, as happens with most elements of the system. This is why software maintenance really exists, and it is why it is set at 15 percent to 25 percent of the list price of the application software. That means every four to seven years, the maintenance fees are like buying the software all over again from an economic standpoint. And if the code is not changing and because customers dont want it to and all the vendor is really doing is supplying security patches, then you can understand why IBM i customers might resent these fees.

Yes, it is unfair that some customers stayed on maintenance and paid and others did not, and that some IBM i shops expect a break on after license maintenance fees if they return to the fold and upgrade to software that is certified for modern IBM i operating systems and modern Power Systems hardware. But as I explained to a reader on LinkedIn last week in response to the software release problem with IBM i, where so many customers are on 7.1 or earlier releases, we can all dig our heels in and go straight to hell together, or we can figure out some way that everyone gives a little and we all benefit.

The application ISVs can dig their heels in and say they are entitled to all the back maintenance before getting customers current, and they will probably not get very far. If customers are going to spend huge amounts of money and have to massively customize a newer version of the code anyway, they will very likely just move to a different platform for political reasons more than technical ones. The economics will suck no matter what.

The customers who just sit there on older releases of operating systems and applications are sitting on a ticking timebomb, but sometimes this is in fact the least risky behavior as well as the least costly right up to the catastrophe where all of this comes home to roost.

IBM has a hand in this, too, and has shown the way with amnesties on after license charges for IBM i Software Maintenance in 2015 and again in 2020, which you can see in the Related Stories section below.

All I know is that IBM i shops, application ISVs, and Big Blue have to all work together to solve this problem for those companies who rely on third party applications, and the fees that IBM i shops have to pay should be proportional to the amount of work it takes to get either old suites certified on new IBM hardware and operating systems or to get customizations ported to new suites that are already ported to them. (I think we all know which one is easier and cheaper.)

There is one more thing that we know. Real mitigation for Log4j security vulnerabilities has to be done, and that means IBM has to write new and secure logging software that snaps in place of Log4j and allows IBM i 7.1 releases and forward, including the Heritage Navigator as well as the new IBM i Navigator to work. Telling people with older releases to turn off Log4j and only turn it on to use Heritage Navigator at their own risk is not doing right by the customer, and IBM damned well knows it. When nearly half of the base is on IBM i 7.1, as I believe it is, and another fifth is on IBM i 6.1, and many of them are stuck, Big Blue simply cannot behave this way.

7.1 Flew Over The Cuckoos Nest

The State Of The IBM Base 2022, Part Three: The Rusting Iron

The State Of The IBM i Base 2022, Part Two: Upgrade Plans

The State Of The IBM i Base 2022, Part One: The Operating System

IBM Grants Amnesty On Software Maintenance After License Charges

Where Is The Power Systems-IBM i Stimulus Package?

IBM Grants After License Amnesty For Software Maintenance

IBM i 7.1 Extended Out To 2024 And Up To The IBM Cloud

Big Blue Revives IBM i 7.1 With Power9 Support

IBM Further Extends Service Extension For IBM i 7.1

Service Extension Outlined For IBM i 7.1 And PowerHA 7.1

Say Sayonara To IBM i 7.1 Next Spring

Big Blue To Sunset IBM i 6.1 A Year From Now

Follow this link:

The State Of The IBM i Base 2022: Third Party Software Conundrum - IT Jungle

Can we solve the zero-day threat once and for all? No, but heres what we can do – The Register

Webinar Last Decembers Log4j crisis brought the danger of zero day vulnerabilities to the front pages. But while one key flaw has been put under the microscope, does that mean the problem is over?

Sadly, the answer is no. There is no way of knowing how many other open-source apps have zero day vulns, not to mention enterprise apps and APIs.

The fact is Log4 was a wakeup call and remediating zero days is going to be an ongoing chore for security teams for the foreseeable future.

Which is why you should join this webcast, Mitigate Zero-Day Exploits, on April 26 at 5pm BST (9am PT), which doesnt just bring together experts in the field but takes you through the methods they use.

Our own Tim Phillips will be joined by Contrast Securitys Larry Maccherone, previously head of DevSecOps at Comcast; as well as CM.com CISO Sandor Incze; security architect at Floor and Dcor Darius Radford; and Joe Zanchi, lead cyber security policy and standards at Humana.

This stellar panel will explain how they grappled with the Log4Shell crisis and continue to deal with vulnerabilities whether in open-source code, enterprise web applications or APIs. And theyll show you how to understand your open-source estate and how to keep it close to latest.

Theyll also explain whole-app analysis, and why this is better at finding vulnerabilities. And theyll show you how to bock attacks short term, without having to rely on a web applications firewall.

Tapping into this cybersec brains trust is simple. Just head here, register, and well remind you on the day. The spectre of zero days isnt going away, but after this session youll be far better placed to tackle it.

Sponsored by Contrast Security

Read the original post:

Can we solve the zero-day threat once and for all? No, but heres what we can do - The Register

Everything you need to know about the Open Metaverse – SecurityBrief New Zealand

Article by CENNZnet CEO, Nicole Upchurch.

Has anyone else had that feeling lately? The troubling creeping sense that the internet is being used against us? It's a disturbing thought.

One of the century's greatest inventions, designed as an open platform for creativity and communication, is now being wielded by a small number of global corporations hungry for your data and your dollars.

It's not a new feeling. Anyone involved in the Web 3.0 movement has always had reservations about the current iteration of the internet. But until very recently, the tools to break the tyrannous hold of the tech giants existed only as whiteboard sketches and passionate discussion.

Enter the age of the Metaverse.

Decentralised, trustless, community-owned and secure, the Metaverse has quickly presented itself as the real solution to realising a better internet.

What is the Metaverse?

The Metaverse is the next evolution of the internet and the digital economy. It's not one thing, but rather, it's many things grounded in two principles:

How is the Metaverse linked to Web 3.0 and blockchain?

Web 3.0, also known as the decentralised web, is a new iteration of the internet based on blockchain technology. It envisions an internet where people control their own data, and exciting creative content is open and available to everyone using a decentralised, community-driven system.

It's becoming increasingly apparent that the Metaverse is the natural UX of Web 3.0. It offers an appealing, gamified and tangible way for people to interact with a decentralised, blockchain-powered internet.

If it's so community-driven, how come Mark Zuckerberg is all over Metaverse?

The Metaverse offers a blend of the newest technologies alongside a much-needed return to community-driven communication, creativity and fun. It is the death knell of big tech's exclusive ownership of value on the internet. So naturally, all of the giants are clamouring desperately to own the Metaverse before the revolution totally undermines them.

Rather than pursuing an open, decentralised Metaverse, big tech is looking to simply expand their own tightly controlled assets, locking everyone into their offering and charging what they like for it.

What is the 'Open Metaverse'?

With big tech already crawling all over the concept of the Metaverse, the communities actually pursuing an open-source movement have had to define their niche. The open Metaverse (or the true Metaverse) is the genuine article, not to be confused with organisations like Meta who are simply making a walled garden extension of Facebook.

What's a blockchain bridge, and why are they important to Metaverse?

A blockchain bridge, often known as a token bridge, is a connection that allows the transfer of tokens and/or arbitrary data from one blockchain to another. What this means in practice is that two or more blockchains with different core protocols can interact with each other and interoperate securely and quickly. The bridges rely on one chain proving ownership of a token (or numerous tokens). They then relay this information to other connected blockchains, which can then be used to perform actions on another chain.

This is groundbreaking for Web3. It is the realisation of a technology that will allow a network of connected blockchains, each offering its own strength or speciality and all working together in a secure, decentralised state. Essentially it enables an internet that doesn't require the ownership of centralised servers that are controlled by a single person or entity. Instead, data is stored on a network of decentralised blockchains which are anonymous, secure and community-driven.

Bridging technology allows the open-Metaverse true scope. Metaverse content can now exist across multiple blockchains, utilising features from each to give their communities excellent experiences and the ultimate decentralised freedom. For example, chains with low gas fees act as a Layer 2 solution on top of bigger chains to increase scalability and efficiency.

How is CENNZnet helping to drive the Metaverse?

In case you can't tell, we are stoked about the development of the Metaverse and Web 3.0. Our focus has always been about enabling easy onboarding of users to web3 technology. CENNZnet has been optimised to allow developers to build user-friendly applications that can merge the user experience boundaries and enable people to own their content, identity and data.

View original post here:

Everything you need to know about the Open Metaverse - SecurityBrief New Zealand

Introducing the Wind River Linux Binary Distribution – Wind River

By Jay Kruemcke

Wind River is proud to announce a new member of the commercially supported Wind River Linux family, Wind River Linux Distro. Distro is a binary Linux distribution created from our source codebased Linux product.

Wind River, the leader in the IoT and embedded operating systems, has long provided customers with the ability to create their own purpose-built Linux operating system from source. Wind River starts with the Yocto Project and adds a significant amount of integration with semiconductor vendor SDKs to provide a commercially supportable Linux distribution builder for intelligent edge solution developers.

Wind River Linux is used in tens of thousands of telecommunications, industrial, aerospace and defense, and automotive embedded solutions, but we realized that not all customers need the flexibility of building a Linux operating system from source code.

Introducing the Wind River Binary Distribution

Distro is intended for intelligent edge solution developers who want to leverage the tremendous investment in embedded device hardware and open source software made by Wind River but want to avoid the time and effort of building Linux from source.

Distro provides multiple approaches for solution developers to create a purpose-built Linux OS from binary images. These approaches include micro-start self-deploying images, Linux Assembly Tool (LAT), dnf package feeds, a container base image on Docker Hub, and a software development kit (SDK).

Because bug fixes and security updates are important for security and stability, Distro provides OSTree updates that can be used to deliver fixes or even upgrade images to a new release. Solution developers can create their own images, containers, packages and package feeds, and even their own OSTree update feeds.

Hardware Support

One of the key advantages of using Wind River Linux has always been the support available for a wide variety of hardware platforms. Wind River takes the SDKs from semiconductor vendors and integrates them into the Wind River Linux Yocto Project source base. Unlike some other binary distributions, Distro is not limited to just upstream Linux hardware enablement, and we regularly update our hardware support from the latest semiconductor vendor SDK.

The Wind River Linux binary distribution has been available for several X86 and Arm hardware platforms as a free and unsupported download since 2021. With the launch of Wind River Linux LTS21 last year, we have made thousands of image downloads available.

With this announcement, we are now offering commercial support for some of the Distro hardware platforms.

Like the Wind River Linux source-based product, Distro does not require any paid subscriptions or royalties on deployed systems. Distro is sold on a per-project basis.

We will add commercial support for additional hardware platforms based on customer demand.

Choosing the Right Wind River Linux

Generally, the Wind River Linux source-based product provides the ultimate amount of flexibility and reproducibility and is particularly well suited to intelligent edge solution developers who require complex customization of Linux, including the kernel.

In contrast, Distro is the best choice for rapid prototyping and deployment when there is limited need for Linux kernel customization, and it generally requires significantly fewer resources than does our Yocto Projectbased source product.

Try It Out at No Cost

Anyone can try Distro for free. Go to https://www.windriver.com/products/linux/download, and after you register and choose your hardware platform, you will receive a link to the images and SDK.

The quick-start guide Distro Developers Guide can help you learn to use Distro tools such as the Linux Assembly Tool (LAT) and build your embedded solution on top of Distro.

Summary

Wind River Linux Distro is a true binary distribution of Linux that solution developers can use to quickly provide a Linux OS foundation for their intelligent edge solution. Solution developers can try out the free version of Distro knowing that commercial support is available when they deploy their solution.

Continue reading here:

Introducing the Wind River Linux Binary Distribution - Wind River

Have you ever considered an open-source audit for your organisation? – JD Supra

Whether its due to needing to identify known vulnerabilities in a codebase containing open-source code, or due to an impending acquisition of a software company, youve come to the right place. This article will walk you through what open-source code is, when you should consider investing in an open-source audit all the way through to what happens after the audit has been completed.

What is Open-Source code?

Before we dive in to explaining all about open-source code audits and when you should consider them, lets first start by understanding what open-source code is.

The Source code is the part of software that most computer users dont ever see; its the code computer programmers can manipulate to change how a piece of softwarea program or applicationworks. Programmers who have access to a computer programs source code can improve that program by adding features to it or fixing parts that dont always work correctly. Open-source code is widely used by software development companies to accelerate development and reduced costs. Open-source software is software with source code that is publicly available and anyone can inspect, modify and enhance.

According to Gartner, 95% of the IT enterprises across the globe use open-source software for their mission-critical IT workloads, whether they are aware of it or not. Benefits to using open-source software include freedom and flexibility, lower costs, high quality, and innovation via communities.

However, the use of open-source software also creates challenges for businesses. These include an increase in security breaches, they can sometimes become too complex, software patches and updates will have to be managed by the IT teams and it may come with a lack of customer support. Using open-source code within proprietary software also creates challenges if the code breaches any licensing rules.

What is an open-source code audit?

An open-source code audit is used by businesses to detect and identify the existence of open-source code. The audit will identify the open-source code and their corresponding licences. There are many common open-source licenses Including:

There are certain reasons as to why businesses today use open-source audits. These include:

Investment The opportunity to invest in a software or SaaS company may be tempting. Before investing you need to ensure that the IP of the company is owned by that company and does not contain open-source code which may negatively affect the value of the company.

Acquisition (M&A) During the acquisition of a software company or the intellectual property (IP) belonging to a company, it is essential to identify if any of these products contain open-source code not owned by that company. For example, if open-source code with a GPL license exists within the code base, this will most likely be problematic.

Outsourced Developer If you subcontract software development to a third-party developer, you may request assurances or warranties that the codebase does not contain any open-source code. In order to determine if the developer is keeping to their end of the agreement, it is essential to conduct an open-source code audit to verify compliance.

Security The use of open-source code comes with security risks as the code is available to the public. Hackers can use this code to seek out and exploit vulnerabilities that may exist. Research has shown that 78% of audited codebases contained at least one open-source vulnerability, of which 54% were high-risk ones that hackers could exploit. The recent Log4j breach highlights the inherent risks of opensource code embedded within IT systems. According to cybersecurity experts, hackers can gain easy access to a companys computer server, giving them entry into other parts of a network. Its also very hard to find the vulnerability or see if a system has already been compromised. An open-source code audit and implementing a policy of maintaining a Software Bill of Materials (SBOM) will assist in identifying known vulnerabilities in a codebase containing open-source code.

What happens after the open-source code audit?

After the audit, a final audit report will be presented and should provide a complete overview of the build of materials. Items in the report may include the following:

It is important to choose an open-source code audit vendor who can walk you through what was found and provide actionable insights for the IT team within your business to run with.

Here is the original post:

Have you ever considered an open-source audit for your organisation? - JD Supra

10 Free Open Source Android Apps Source Code For Developers

If you already know how to create Android Apps, you may want to look into the open source Android apps to boost your android development skills.By reviewingsource codes of open source Android apps, you can learn how to build better apps.

To help you get started, we have a compilation of 10 Free Open Source Android Apps in this post below. As a learning purpose, use these free android apps source codes and improve your Android development skill.

If you were looking to learn Kotlin, then this calendar appis probably one of the best ways to start.This app makes it perfect to get your hands dirty learning a completely new language for developing Android apps. You can also learn to make custom desktop widgets for Android.

Difficulty: Beginner

Download from Github| Demo Play Store

A file manager is a very common Android app that you can find on almost any Android device. Though building a file manageris quite difficult to get it right on all Android platformsand all devices. You can learn how to perform proper file handling on SD cards with this app source code.

Difficulty: Intermediate

Download Github|Demo Play Store

If you are wondering how Photo and Video gallery apps for android are made,LeafPic is one of the best open source gallery apps for Androidyou can try. If you are a beginner android developer, It is perfectly suitable for you to understand.

Difficulty: Beginner

Download Github| Demo Play Store

This open source android app is ideal for any beginner android developer who wants to learn the basics of Android Development. You can use this Android photo app to stitch photos vertically or horizontally.You can also learn to make some simple yet useful custom views which can help you to get your foundation ready so that you can later move on to creating some really complex views in future.

Difficulty: Beginner

Download Github| Demo Play Store

This is one of the best open source android apps which will help you to list the popular movies with their trailers and reviews.The app showcases some really cool development stufflike MVP, Uncle Bobs Clean Architecture, gives the sweet taste of RxJava and dependency injection using Dagger 2.

Difficulty: Intermediate

Download Github

This todo app source code is also recommended for a beginner developer. With this very simple yet project, you canlearn most of the basic and fundamental aspects of Android development.

Difficulty: Beginner

Download Github|Demo Play Store

Timber is fully featured music player for Android. If you want to build your own music player or any music related app, then this is the project you need to look at.The project is very active in development, it might be a bit difficult for you if you are a beginner but it should be really interesting for any intermediate or advanced level Android developer.

Difficulty: Advanced

Download Github|Demo Play Store

If you are looking to improve your Material Design skills, then InstaMaterial Instagram clone app source code can help you.InstaMaterialtries to replicate parts of the Instagram app in beautiful Material Design.There are lots of Material Design elements, animations and transitions used in this app which you can learn and implement in your own Instagram clone project.

Difficulty: Beginner

Download Github

If you want to learn to develop a location-based Android app, then Travel mate is probably the best open source travel app to start with. You can start travel app project with this open source android app. The Travel Mate Android Travel app provides users with all necessary features that most of the travel apps offer. From choosing the destination to making all the bookings and organizing the trip, all these features are already included in this free android travel app source code.

Difficulty: Intermediate

Download Github

A simple, light-weight pedometer app which uses the hardware sensor to calculate the stepstaken with almost no impact on the battery performance of the device. It is a good project to start learning step tracking, but the coding standards and design are not good enough to be followed.

Difficulty: Beginner

Download Github

Read more here:

10 Free Open Source Android Apps Source Code For Developers

Joget Awarded Funding Through Catalyst Fund 7 for Its No-code Application Integration with the Cardano Blockchain – PR Newswire

"We welcome all builders and innovators creating useful applications on the Cardano blockchain and are impressed by the growth of the ecosystem facilitated by community decision making and the decentralized governance of Project Catalyst," said Kriss Baird, Product Owner of Input Output Global (IOG).

Citizen Developers, typically business users with little coding experience, can now visually develop applications integrated with the Cardano blockchain using the recently released Cardano Blockchain Pack. Joget plans to use the fund to further enhance the development of the plugin and expand its capabilities with more advanced features. By integrating blockchain technology with a no-code/low-code application platform like Joget, organizations can rapidly kick start their digitalization journey while lowering the associated costs and risks. This helps to narrow the gap between traditional application development methodology and a modernized no-code/low-code approach.

"We see blockchain as a critical component to the foundation of next-generation technological innovations, and we want to bring it to the masses with our no-code/low-code approach," said Raveesh Dewan, CEO of Joget, Inc. "We are thankful to the Cardano Community and the Catalyst Fund team for believing in and supporting our approach."

The Cardano Blockchain Pack is published on JogetOSS, an open source repository for the Joget platform, and a step-by-step tutorial is available on the Joget Knowledge Base.

About Joget, Inc.Joget, Inc is the developer of the Joget open source no-code/low-code application platform. Joget empowers business users, non-coders (Citizen Developers) or coders to create enterprise applications across industries and countries. With more than 200,000 downloads, 3,000 installations and 12,000 community users worldwide across various industries (including finance, manufacturing, IT, and more), Joget is a proven platform for a wide spectrum of organizations ranging from Fortune 500 companies to government agencies and small businesses.

ContactsMedia Relations[emailprotected]1.888.60J.OGET (1.888.605.6438)

SOURCE Joget

View original post here:

Joget Awarded Funding Through Catalyst Fund 7 for Its No-code Application Integration with the Cardano Blockchain - PR Newswire

OpenBB wants to be an open source challenger to Bloomberg Terminal – VentureBeat

We are excited to bring Transform 2022 back in-person July 19 and virtually July 20 - August 3. Join AI and data leaders for insightful talks and exciting networking opportunities. Learn more about Transform 2022

Let theOSS Enterprise newsletterguide your open source journey!Sign up here.

Anyone who has worked in the financial services sector will at least be aware of Bloomberg Terminal, a research, data and analytics platform used to garner real-time insights on the financial markets. Bloomberg Terminal has emerged as something of an industry standard, used by more than 300,000 people at just about every major financial and investment-related corporation globally but it costs north of $20,000 per user each year to license, a fee that is prohibitively high for many organizations.

This is something that OpenBB has set out to tackle, by democratizing an industry that has been dominated by monopolistic and proprietary incumbents for the past four decades and its doing so with an entirely open source approach.

After launching initially last year as an open source investment research terminal called Gamestonk Terminal, the founding team, Didier Lopes, Artem Veremey, and James Maslek, were approached by OSS Capital to make an investment and build a commercial company on top of the terminal. And so OpenBB is formally launching this week with $8.5 million in funding from OSS Capital, with contributions from notable angel investors including early Google backer Ram Shriram, entrepreneur and investor Naval Ravikant, and Elad Gil.

The newly named OpenBB Terminal is very much an alpha-stage product, one thats aimed at the more technically minded. Its pitched as a Python-based integrated environment for investment research, allowing any trader to access data science and machine learning smarts to unpack raw, unrefined data.

In its initial guise, OpenBB is deployed via a command line interface (CLI), though plans are afoot to build a proper GUI for regular users. The platform gleans its investment data via publicly available sources, among others that require an API key these include Alpha Vantage, Financial Modeling Prep, Finnhub, Reddit, Twitter, Coinbase, the SEC, and many more.

OpenBB leans on machine learning across myriad use-cases. For example, it can look at Apples share price over the past week, and then grab news headlines via one of Finnhubs APIs and derive sentiment from each headline using natural language processing (NLP), and then correlate the impact of news on Apples share price.

Elsewhere, OpenBB can leverage deep learning to predict stock price movement using historical data, though in reality the model can be applied to just about anything, including economic data, crypto, and more. The company plans to double down on these predictive smarts.

The idea in the future is that we dont rely just on the past historical data to train the model, but we use further data available in our platform, Lopes told VentureBeat. For example, building powerful models that use share price, news, sentiment on social media, insider trading.. anything, really.

While Bloomberg Terminal is the industry standard for countless financial organizations, there are other alternatives on the market, such as Refinitiv Eikon and Factset. But OpenBB hopes that its open source credentials, and foundations in Python, will position it to win over many new users flexibility is the name of the game.

By being open source, affordable, and highly customizable due to the usage of Python, we differentiate from these platforms as well tailor to the specific needs of small-to-medium-sized institutions, Lopes said. The advantage we have over competitors is our open source nature when it comes to incorporating external data sources.

Indeed, being open source means that the broader community can add their own flavors to the OpenBB mix by way of example, one contributor who was interested in the foreign currency exchange market (Forex) added an Oanda integration to the project.

Given that the entire source code is available for anyone to modify, companies can create their own version of the terminal with customizations that suit their niche use-cases. If they want to remove all the clutter and work purely with one type of asset, they can create a sort of light-weight version of the terminal with a much narrower focus on Forex, or cryptocurrency, for example.

But who is the actual intended end-user, exactly? In truth, it could be anyone from regional investment banks and hedge funds, to venture capitalists, family offices, and mutual funds. Although the product isnt quite at that stage yet that is where the initial seed capital enters the fray. Its all about building the product into something that could serve a potentially large market.

In the long term, we would also be able to target companies like Morgan Stanley, JP Morgan, Blackrock, Vanguard, UBS, Goldman Sachs, Deutsche Bank, and similar, Lopes explained. [But] we fully understand that this is not possible right now.

There is no escaping the pervasiveness of Bloomberg Terminal, and its clear that its not going to be knocked off its perch any time soon but that isnt the direct goal of OpenBB.

Being a product that has been around for more than 40 years, it [Bloomberg Terminal] has become a staple for many of the larger institutions, Lopes conceded. OpenBB realizes that it cant directly compete with this industry standard. One of the big caveats of the Bloomberg Terminal is that the costs are relatively high for a small-to-medium sized institution, which is an area which we can capitalize on.

OpenBB is also looking to differentiate in areas such as portfolio optimization and attribution (reports), and tailor itself more to the needs of smaller institutions. Moreover, it also aims to target different asset classes that may not be covered so well on alternative platforms this may include cryptocurrencies, NFTs, fintech lending services, and so on.

Digital assets is a niche area that isnt covered extensively for example, providing insights on movements within this industry, but also more advanced areas like valuation of loans to a farmer in Africa, Lopes said. These are topics that we can quite easily differentiate when we notice there is a lot of interest in this area. That is one of our advantages by being open source and developing in Python.

And then there is academia too, an arena where OpenBB could thrive teachers could use the terminal to explain market movements to students using real data, or PhD students could develop their thesis to build products or features that can be accessed by anyone around the world. And this could all work to OpenBBs benefit too.

Given our product being free and open source, we can easily reach academia, which allows us to stay at the vanguard of innovation since students and researchers can develop new features to further strengthen OpenBB Terminal capabilities, Lopes said.

For now, OpenBB Terminal will be an entirely free proposition, but with the weight of a commercial business behind it and $8.5 million in the bank, there will be a concerted push to monetize it. Some ideas currently under consideration include building a slick 21st century UI, as well as developing a software-as-a-service (SaaS) model, where OpenBB serves up the computational power to run machine learning models on vast amounts of data.

OpenBB is also exploring ways to build bridges between data sources and investors. For example, an investor probably wouldnt want to pay for raw data from a given data source, but if OpenBB Terminal could extract insights from that data using machine learning or data science techniques and deliver it with context this is something that an individual or organization may wish to pay for.

It is still early days for OpenBB, but the early traction it gained last year in its initial form suggests there is a real demand and that is why OSS Capital is betting on Lopes and Co.

The investment research industry has been dominated by monopolistic and proprietary incumbents since the 1980s, and it has taken until now for someone to develop an open source, democratized platform for the current and next generation of market makers, traders and equities professionals, OSS Capital founder Joseph Jacks said. OpenBB is the right idea, at the right time.

VentureBeat's mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Learn more about membership.

Read the original:

OpenBB wants to be an open source challenger to Bloomberg Terminal - VentureBeat

ScaleOut Software Builds Redis Open-Source Software Execution Capabilities into its Scaleout StateServer Product – Database Trends and Applications

ScaleOut Software is introducing support for Redis clients in ScaleOut StateServer Version 5.11, available as a community preview.

With this release, Redis users can harness the companys flagship distributed caching product to connect to a cluster of ScaleOut servers and execute Redis commands.

This integration of Redis open-source software with ScaleOut StateServer adds breakthrough capabilities for Redis users by dramatically simplifying cluster management, enabling seamless throughput scaling, and automating recovery from server and network outages, according to the vendors.

Targeted at enterprise users, ScaleOut StateServer now offers important new capabilities and the potential for substantial cost savings over competing commercial Redis products.

Redis clients can connect to a ScaleOut StateServer cluster in the same way that they connect to a Redis cluster and by using the same RESP protocol.

This version implements all Redis data structures (strings, sets, sorted sets, lists, and hashes), as well as transactions, publish/subscribe commands, and utility commands.

This release does not include support for streams, modules, LUA scripting, and AOF persistence. Redis support incorporates open source Redis version 6.2.5 code to process Redis commands, and it offers the flexibility to run on either Linux or Windows servers.

Unlike open-source Redis, ScaleOut StateServer implements fully consistent updates to stored data. In addition, ScaleOut StateServers native APIs run alongside Redis commands and incorporate advanced features, such as data-parallel computing, streaming analytics, and coherent, wide-area data replication that are not available on open source Redis clusters.

Key capabilities include:

We are excited to provide a new execution platform for Redis clients with ScaleOut StateServer to meet the needs of enterprise users, said Dr. William Bain, ScaleOut Softwares CEO and founder. By incorporating this technology, Redis users can take advantage of ScaleOut StateServers industry-leading features for cluster management to both reduce their operating costs and gain full consistency for stored data.

For more information about this news, visit http://www.scaleoutsoftware.com.

Here is the original post:

ScaleOut Software Builds Redis Open-Source Software Execution Capabilities into its Scaleout StateServer Product - Database Trends and Applications