Live data from Hacker News

The European Parliament has approved budget for VLC bug bounty program

hackerone.com

11–20 of 37 posts

Re: The European Parliament has approved budget for VLC bug bounty program

#12
post #10

Is anyone else concerned at the perverse incentives created by bug bounties on open source software? Monetizing bugs may end up encouraging the creation of insidious, underhanded bugs explicitly so that bounties can later be claimed by other parties supposedly at arms length.

This seems a bit paranoid. It's not like OSS doesn't have code review processes.

Re: The European Parliament has approved budget for VLC bug bounty program

#13
post #12
post #10

Is anyone else concerned at the perverse incentives created by bug bounties on open source software? Monetizing bugs may end up encouraging the creation of insidious, underhanded bugs explicitly so that bounties can later be claimed by other parties supposedly at arms length.

This seems a bit paranoid. It's not like OSS doesn't have code review processes.

It pays to be paranoid. I believe I'd be able to add exploitable bugs that would not be detected in most code reviews; there's a large library of techniques available from underhanded C competitions and similar.

Re: The European Parliament has approved budget for VLC bug bounty program

#14
post #13
post #12

Earlier quoted context omitted.

This seems a bit paranoid. It's not like OSS doesn't have code review processes.

It pays to be paranoid. I believe I'd be able to add exploitable bugs that would not be detected in most code reviews; there's a large library of techniques available from underhanded C competitions and similar.

For those wondering, here is a link to underhanded c http://www.underhanded-c.org/_page_id_2.html

Re: The European Parliament has approved budget for VLC bug bounty program

#16
post #8

Why VLC?

Because it's software the EU institutions use. EDIT: VLC was the third-highest ranked one from a survey on what software to study, with the two already reviewed ones (KeePass and Apache HTTPD) being above it.

It's because VLC was written in Europe, in Paris specifically.

It's more multinational now, but still primarily a European project.

Realistically they are not going to fund an American project. I know the Internet makes "country" semi-obsolete (at least when describing software), countries themselves still care a lot about that.

Re: The European Parliament has approved budget for VLC bug bounty program

#17
post #13
post #12

Earlier quoted context omitted.

This seems a bit paranoid. It's not like OSS doesn't have code review processes.

It pays to be paranoid. I believe I'd be able to add exploitable bugs that would not be detected in most code reviews; there's a large library of techniques available from underhanded C competitions and similar.

If malicious people can add exploitable bugs and claim a bug bounty later, then they can also add exploitable bugs to actually exploit them. So I'd say that bug bounties also work here: they create an incentive to review the code of open-source projects more closely.
Post reply on HN