Live data from Hacker News

The European Parliament has approved budget for VLC bug bounty program

hackerone.com

31–37 of 37 posts

Re: The European Parliament has approved budget for VLC bug bounty program

#31
post #10

Is anyone else concerned at the perverse incentives created by bug bounties on open source software? Monetizing bugs may end up encouraging the creation of insidious, underhanded bugs explicitly so that bounties can later be claimed by other parties supposedly at arms length.

http://dilbert.com/strip/1995-11-13

Re: The European Parliament has approved budget for VLC bug bounty program

#32
post #10

Is anyone else concerned at the perverse incentives created by bug bounties on open source software? Monetizing bugs may end up encouraging the creation of insidious, underhanded bugs explicitly so that bounties can later be claimed by other parties supposedly at arms length.

I'm not concerned. First, with git we can look who introduced the bugs. Second, the worst-case you fear would still imply development of the project, which is good. After all, you can't maliciously introduce a bug without changing anything.

Re: The European Parliament has approved budget for VLC bug bounty program

#34
post #16
post #8

Earlier quoted context omitted.

Because it's software the EU institutions use. EDIT: VLC was the third-highest ranked one from a survey on what software to study, with the two already reviewed ones (KeePass and Apache HTTPD) being above it.

It's because VLC was written in Europe, in Paris specifically. It's more multinational now, but still primarily a European project. Realistically they are not going to fund an American project. I know the Internet makes "country" semi-obsolete (at least when describing software), countries themselves still care a lot about that.

They're still funding an American company (HackerOne) despite having European platforms (at least two in France for instance)
Post reply on HN