Live data from Hacker News

EU to fund bug bounty programs for open-source projects

zdnet.com

151–153 of 153 posts

Re: EU to fund bug bounty programs for open-source projects

#151
post #70

Never heard about "Digital Signature Services (DSS), FLUX TL, midPoint, WSO2". Why were they chosen?

As others have said, they are most likely being used by the EU in some parts of their infrastructure. Then the question becomes "Why were they using these software in their infrastructure?" The answer to that is probably along the lines of "a guy that was assigned to project used it because it came up in google," if I were to hazard a guess.

Isn't this how most software is chosen? Someone finds it, realises it's useful, recommends it further, ... And down the line it's an essential tool.

Re: EU to fund bug bounty programs for open-source projects

#153

So now the game for developers is to include intentional but sufficiently abscure bugs that they can harvest money off down the line.

I don't think developers would be eligible for bounties for vulnerabilities found in their own projects.

So? You sell your exploits to another dev at a fraction of the bounty, other devs so the same for you. It’s not like that puts up any real obstacle.
Post reply on HN