Live data from Hacker News

EU to fund bug bounty programs for open-source projects

zdnet.com

71–80 of 153 posts

Re: EU to fund bug bounty programs for open-source projects

#71
post #48
post #3

Seems like it would quite easy to game the system. Make contributions with known vulnerabilities and then submit an anonymous bug report when the contribution is approved.

Follow up: This situation is similar to when England wanted Delhi to be rid of cobras so they started offering rewards for dead cobras. The citizens of Delhi responded to this incentive by farming cobras. What's the difference? It's a systemic flaw. If there exists an incentive for finding vulnerabilities, there exists an incentive for introducing vulnerabilities. Bug bounties work great for closed source companies b…

> Follow up #2: For the skeptical downvoters, I'll put my money where my mouth is and attempt to capture the bounties using the method described above.

Please don't.

Re: EU to fund bug bounty programs for open-source projects

#72
post #64
post #61

Earlier quoted context omitted.

KDE is not worse than MATE. A full featured desktop environment with software suite compared to a fork of GTK 2.

MATE is a fork of GNOME 2, which is a full featured desktop environment as well. MATE runs orders of magnitude faster and is much more stable than KDE. Especially on the old workstations where they installed LiMux. I'm not going to say that the project failed entirely because of technical reasons, but at first glance it really looks like they took bad decisions. It's hard to defend a move where you end up with worse…

There's barely any development on the GitHub. And also it seems like there are few contributers.

Whilst KDE is a much bigger project that is actively developed.

Re: EU to fund bug bounty programs for open-source projects

#73

Great idea, I hope they also put money to help get orgs out of PHP, Drupal and other dead/terrible software. If not this is a bit depressing and short sighted.

What would be good alternatives for php and drupal?

Nginx and Hugo, depending on whether the website really needs that backend database or not.

eg Hugo does static websites, but obviously that doesn't meet the needs of everyone. :)

Re: EU to fund bug bounty programs for open-source projects

#74
post #10

Earlier quoted context omitted.

The city of Munich tried to develop a Linux distribution "Limux" that was used for some time, but political considerations ultimately reversed the decision. https://en.m.wikipedia.org/wiki/LiMux

Munich did that, but they didn't do the second part of parent's suggestion: "and they invested it in an open source office suite..." Surely most of the problems with the opensource tools they were using could have been resolved by helping the opensource projects fix bugs.

Yup. Going open source requires a shift in mindset when handling support issues. Coming from a paralyzed, complaining-to-vendor position, into taking responsibility and fixing the problems yourself.

Re: EU to fund bug bounty programs for open-source projects

#76
post #25

Earlier quoted context omitted.

PHP is used for a massive amount of software out there. I hate the language as much as anyone (probably more since I had to work with it extensively), but that doesn't change the above fact. From Wordpress and Drupal to countless custom websites and apps built with Laravel or Symfony, this is a very worthwhile area to invest this money in. Regardless of how much you don't like PHP.

I very well know how much PHP is used. However the possibilities and outcomes a learning developper has by choosing PHP are very well enclosed to the few things PHP gives instead of the myriads of things other tools offer. I won't even talk about the semantic. On the other hand letting the dev learn JS or Python or even C++ in a pre-thought way will let much more different technologies and "tech-area" to their grasp…

You are really confusing two things here.

I wouldn't voluntarily start any new project in PHP, but that doesn't change the massive amounts of existing PHP code that can benefit from an investment in security.

PHP is (sadly) not going anywhere for a long time.

Also, as others mentioned, it's just so easy to host PHP based solutions like WP etc that you can't reasonably recommend anything else to a non-technical user.

Even someone clueless can figure out how to host something with PHP on cheap shared hosting with a little internet research. Good luck doing the same thing with Python or Ruby or even Rust.

Re: EU to fund bug bounty programs for open-source projects

#77
post #70

Never heard about "Digital Signature Services (DSS), FLUX TL, midPoint, WSO2". Why were they chosen?

As others have said, they are most likely being used by the EU in some parts of their infrastructure. Then the question becomes "Why were they using these software in their infrastructure?" The answer to that is probably along the lines of "a guy that was assigned to project used it because it came up in google," if I were to hazard a guess.

Re: EU to fund bug bounty programs for open-source projects

#78
post #70

Never heard about "Digital Signature Services (DSS), FLUX TL, midPoint, WSO2". Why were they chosen?

DSS is EU-owned library I believe. I used it instead reimplementing digital signature verification for XMLs, PDFs, hadling certificate revocation, etc. Makes sense that they want to secure own library that secures many other applications.

WSO2 is Enterprise Service Bus that I used at another company (owned by government BTW) instead of one from whoever-makes-commercial-ESBs.

Re: EU to fund bug bounty programs for open-source projects

#79

This is a very strange distribution of projects. There are projects like VLC, Filezilla, and 7-zip, next to often mission-critical pieces of software, like Kafka, Tomcat, and GlibC. I wonder what went into the decision process to include each of these libraries. I also dislike the 'bug bounty platforms'. Why can't I simply report it upstream, and if accepted, claim my price? Each of the projects should have CVE proto…

>This is a very strange distribution of projects. There are projects like VLC, Filezilla, and 7-zip, next to often mission-critical pieces of software, like Kafka, Tomcat, and GlibC. I wonder what went into the decision process to include each of these libraries.

The EU (Brussels offices, etc) actually using them?

Re: EU to fund bug bounty programs for open-source projects

#80
post #72
post #64

Earlier quoted context omitted.

MATE is a fork of GNOME 2, which is a full featured desktop environment as well. MATE runs orders of magnitude faster and is much more stable than KDE. Especially on the old workstations where they installed LiMux. I'm not going to say that the project failed entirely because of technical reasons, but at first glance it really looks like they took bad decisions. It's hard to defend a move where you end up with worse…

There's barely any development on the GitHub. And also it seems like there are few contributers. Whilst KDE is a much bigger project that is actively developed.

If that's your indicative of the quality of a project then I understand your position.
Post reply on HN