Why VLC?
The European Parliament has approved budget for VLC bug bounty program
11–20 of 37 posts
Re: The European Parliament has approved budget for VLC bug bounty program
#12Is anyone else concerned at the perverse incentives created by bug bounties on open source software? Monetizing bugs may end up encouraging the creation of insidious, underhanded bugs explicitly so that bounties can later be claimed by other parties supposedly at arms length.
Re: The European Parliament has approved budget for VLC bug bounty program
#13Is anyone else concerned at the perverse incentives created by bug bounties on open source software? Monetizing bugs may end up encouraging the creation of insidious, underhanded bugs explicitly so that bounties can later be claimed by other parties supposedly at arms length.
This seems a bit paranoid. It's not like OSS doesn't have code review processes.
Re: The European Parliament has approved budget for VLC bug bounty program
#14Earlier quoted context omitted.
This seems a bit paranoid. It's not like OSS doesn't have code review processes.
It pays to be paranoid. I believe I'd be able to add exploitable bugs that would not be detected in most code reviews; there's a large library of techniques available from underhanded C competitions and similar.
Re: The European Parliament has approved budget for VLC bug bounty program
#15Re: The European Parliament has approved budget for VLC bug bounty program
#16Why VLC?
Because it's software the EU institutions use. EDIT: VLC was the third-highest ranked one from a survey on what software to study, with the two already reviewed ones (KeePass and Apache HTTPD) being above it.
It's more multinational now, but still primarily a European project.
Realistically they are not going to fund an American project. I know the Internet makes "country" semi-obsolete (at least when describing software), countries themselves still care a lot about that.
Re: The European Parliament has approved budget for VLC bug bounty program
#17Earlier quoted context omitted.
This seems a bit paranoid. It's not like OSS doesn't have code review processes.
It pays to be paranoid. I believe I'd be able to add exploitable bugs that would not be detected in most code reviews; there's a large library of techniques available from underhanded C competitions and similar.
Re: The European Parliament has approved budget for VLC bug bounty program
#18Re: The European Parliament has approved budget for VLC bug bounty program
#19Earlier quoted context omitted.
Yeah, mpv.io is where it's at.
mpv is dead
Re: The European Parliament has approved budget for VLC bug bounty program
#20Earlier quoted context omitted.
Yeah, mpv.io is where it's at.
mpv is dead