Securing Open Source for a Trusted and Inclusive Digital Future
Abstract
Open source solutions empower innovation and accessibility worldwide, but their security challenges can hinder responsible and inclusive digital development. The EU-funded SecOPERA project addresses this by delivering a holistic framework for securing open source software and hardware, reinforcing trust and sustainability.
Full text
ERCIM NEWS 142 October 2025 10 Special Theme Securing Open Source for a Trusted and Inclusive Digital Future by George Hatzivasilis and Sotirios Ioannidis (Technical University of Crete) Open source solutions empower innovation and accessibility worldwide, but their security challenges can hinder responsible and inclusive digital development. The EUfunded SecOPERA project addresses this by delivering a holistic framework for securing open source software and hardware, reinforcing trust and sustainability. Open source software (OSS) and open source hardware (OSH) have transformed digital ecosystems, democratising technology and fostering inclusive innovation. However, their security gaps remain a barrier to sustainable adoption. While open source solutions and free versions provide great flexibility and transparency, they often lack the dedicated security assurance and professional support that commercial products typically receive. Many open source components are maintained by small communities or volunteers without formal security audits, making them vulnerable to unnoticed flaws and slow patching cycles. This gap can deter organisations and public services from adopting open solutions, even when they would otherwise benefit from their adaptability and cost-effectiveness. The EU Horizon Europe project SecOPERA (Security Assurance and Hardening for Open Source Software and Hardware) [L1] responds to this challenge by providing a comprehensive security framework tailored for the complexities of open solutions. The approach aligns with the goals of responsible innovation and inclusive digital infrastructures, ensuring that openness does not come at the cost of trust. A key concept in SecOPERA is the decomposition of any open source solution into four interrelated layers [1]: Device Layer: Open hardware cores and processors. Application Layer: Libraries, OS kernels, and software frameworks. Network Layer: Open network stacks and security libraries. Cognitive Layer: Machine learning models and training datasets. Each layer faces distinct threats, requiring specialised security checks and mitigations. SecOPERA introduces Secure Flows, an end-to-end proof that open source components work together securely without creating hidden vulnerabilities [1]. This layered auditing ensures that even highly interconnected OSS/OSH systems can be trusted in critical contexts. SecOPERAs methodology rests on five pillars: Decompose, Audit/Assess, Secure, Adapt, and Update/Patch (see Figure 1). Decomposition maps out all components and dependencies, building clear security boundaries. The Audit/Assess pillar applies state-of-the-art techniques, including static and dynamic analysis, fuzzing, and cross-layer penetration testing. The Secure pillar provides add-on security modules, such as trusted computing extensions or quantum-safe cryptography. Adapt focuses on code debloating to reduce attack surfaces, while Update/Patch automates ongoing monitoring and patching, ensuring long-term resilience. By embedding security assurance throughout the open source lifecycle, SecOPERA empowers developers and maintainers to adopt DevSecOps practices without sacrificing openness. This supports more inclusive technology by making robust security accessible even for communities or SMEs lacking dedicated security teams. To validate its impact, SecOPERA deploys its framework in real pilots (see Figure 2). In the automotive supply chain, PINNO and VoXel use SecOPERAs tools to secure co-developed hardware/software prototypes and maintain ISO-compliant DevSecOps practices. In smart city water management, Figure 1: The SecOPERA functionalities.
ERCIM NEWS 142 October 2025 11 GreenCitizen applies SecOPERA to secure IoT devices monitoring urban water infrastructure, ensuring safe and sustainable services for communities [1]. According to the Open Source Security and Risk Analysis (OSSRA) Report [2], a typical application today includes hundreds of open source components maintained by diverse communities. Keeping such ecosystems secure requires collaborative, transparent, and automated assurance. SecOPERA addresses this challenge with a unified hub architecture, combining a dashboard, orchestrator, audit engines, secure module pools and update mechanisms. This creates a European-scale playground for collaboration, where open source modules can be securely analysed, hardened and shared [1]. By strengthening security without undermining openness, SecOPERA demonstrates that responsible innovation and inclusion can go hand in hand. Trustworthy open source infrastructures empower diverse user communities, reduce digital divides and foster sustainable growth. As digital technologies advance, securing openness becomes a societal imperative. SecOPERA shows how Europe can lead by example, turning security into an enabler for accessible, professionally trusted, and resilient digital futures. Link: [L1] SecOPERA project: https://secopera.eu/ References: [1] A. Fournaris et al., Providing Security Assurance & Hardening for Open Source Software/Hardware: The SecOPERA approach, IEEE CAMAD 2023. [2] Synopsys Inc., Open Source Security and Risk Analysis (OSSRA) Report 2025. Please contact: George Hatzivasilis Technical University of Crete (TUC), Greece [email protected] Figure 2: SecOPERA use cases of automotive supply chain and smart city water management. The Role of AI-Based Age Estimation in Promoting Safer Digital Environments for Children: Ethical and Accessibility Considerations by Emmanouela Kokolaki and Paraskevi Fragopoulou (FORTH-ICS) In Greece, SafeLinethe national hotline for reporting illegal online content and a core service of the Greek Safer Internet Center under the auspices of the Foundation for Research and TechnologyHellas (FORTH), is the first officially recognized Trusted Flagger under the Digital Services Act (DSA). Among its key activities is monitoring emerging challenges brought about by new regulatory developments. At present, a matter of particular concern to the Greek Hotline regarding children's access to online services is age estimation techniques. Do these practices truly serve the best interests of children, or do they risk reinforcing surveillance and bias at the expense of fostering genuine inclusion? A key research focus for SafeLine [L1] is children's online habits in relation to the DSAs provisions (Figure 1), with particular emphasis on age assurance and the widespread circumvention of age limits on very large online platforms (VLOPs). Within this context, age estimation has emerged as a key method to enable effective age assurance mechanisms. Age estimation refers to methods used to determine a users likely age or age range [1]. The relevant processes may involve automated analysis of behavioural or environmental data, monitoring user interactions with devices or other users, utilizing metrics from motion analysis, testing the users cognitive capacities and employing biometric classifiers. According to the Commissions Guidelines on the protection of minors under the DSA [L2], the implementation of age assurance measures is a key approach to ensuring minors' privacy, safety, and security on online platforms by restricting access to age-inappropriate content and by mitigating risks such as minors exposure to grooming behavior. Along with self-declaration and age verification, age estimation is one of the most commonly employed age assurance measures. Before applying age-based access restrictions, providers must assess the necessity and proportionality of such measures, and determine whether alternative, less intrusive measures can offer an equal level of protection. Age estimation techniques are considered by the Commission to be an appropriate and proportionate measure to protect minors privacy, safety, and security when either (i) platform terms set a minimum age below 18 due to identified risks to minors, or (ii) medium-level risks identified through a risk assessment cannot be mitigated by less restrictive measures. For age estimation to be considered an appropriate and proportionate measure, however, it is essential that it be conducted either