US Military App Study Offers a Supply Chain Lesson for Australia
Most Australian organisations know who they buy software from. Far fewer know who wrote the code inside it. That blind spot sits at the heart of new research from Purdue University, the United States Military Academy at West Point, and Florida International University. After analysing more than 220 Android apps marketed to US military personnel, researchers found that many relied on third-party software development kits (SDKs) supplied by companies based in China and Russia. The researchers found no evidence that the embedded code was stealing data or conducting espionage. Instead, the study highlights a broader software supply chain problem that affects organisations everywhere, including Australia: companies often vet the software vendor, but not the external code that ships with the application. A software visibility problem for Australia’s enterprises The military angle may grab headlines, but it is only one example of a much broader issue. Modern enterprise applications are rarely built entirely by one company. Most combine internally developed code with open-source libraries, cloud services, analytics platforms, authentication tools, advertising frameworks, mapping services, and dozens …









