5 ms·
The European Parliament has approved budget for VLC bug bounty program
- gcbw2 9y agowhat about this rationale: > The purpose of the procedure is to provide the European institutions with open source software projects or libraries that have been properly screened for potential vulnerabilities; I don't think bug bounty is a substitute for certification. And it benefits the most if is a long-run with accumulating rewards. making it short term with only one payout will only attract people with automated tools for the initial period. Then code will get "certified" and forgotten. It all seems wrong. Hopefully it is just bad wording on the official PR.
- em3rgent0rdr 9y agoShouldn't fixing bugs a prerequisite for being certified?
- sandworm101 9y ago>> I don't think bug bounty is a substitute for certification. Nor does certification preclude the need for a BB program. These are very different schemes with very different outcomes.
- matt4077 9y ago> I don't think bug bounty is a substitute for certification. Neither does the EU: by extending the free software security audit programme (FOSSA)[...]. Meaning: there already is an audit, certification and audit being synonymous for this purpose. > making it short term This is a trial run, to be extended later: we are trialing the VLC application on a bug bounty program > with only one payout There will be as many payouts as security-relevant bugs are found: Rewards may range from $100 up to $3,000. > will only attract people with automated tools This is a private trial, where people with automated tools submitting low-impact bugs will presumably not be invited: We invite hackers and bounty hunters (aka researchers) based on a variety of factors - reputation, previous track record (high quality reports) > Then code will get "certified" and forgotten. This is VLC, one of the most-used open source programs. How will code merged into the product be forgotten? > It all seems wrong. Indeed... > Hopefully it is just bad wording on the official PR. I think the problem is more likely caused by a complete lack of reading skills.
- heavenlyblue 9y agoWhy VLC?
- Numberwang 9y agoYeah, mpv.io is where it's at.
- thresh 9y agompv is dead
- Numberwang 9y agoeh, no?
- saagarjha 9y agoTheir thriving Git repository says otherwise: https://github.com/mpv-player/mpv https://github.com/mpv-player/mpv
- mrob 9y agoLooks alive to me: https://github.com/mpv-player/mpv/commits/master https://github.com/mpv-player/mpv/commits/master
- agumonkey 9y agoso lovely I use it on windows. so lovely also has lua scripting support https://mpv.io/manual/stable/#lua-scripting https://mpv.io/manual/stable/#lua-scripting
- Fnoord 9y agoWhy?
- detaro 9y agoBecause it's software the EU institutions use. EDIT: VLC was the third-highest ranked one from a survey on what software to study, with the two already reviewed ones (KeePass and Apache HTTPD) being above it.
- barrkel 9y agoIs anyone else concerned at the perverse incentives created by bug bounties on open source software? Monetizing bugs may end up encouraging the creation of insidious, underhanded bugs explicitly so that bounties can later be claimed by other parties supposedly at arms length.
- dvt 9y agoThis seems a bit paranoid. It's not like OSS doesn't have code review processes.
- barrkel 9y agoIt pays to be paranoid. I believe I'd be able to add exploitable bugs that would not be detected in most code reviews; there's a large library of techniques available from underhanded C competitions and similar.
- timthelion 9y agoFor those wondering, here is a link to underhanded c http://www.underhanded-c.org/_page_id_2.html http://www.underhanded-c.org/_page_id_2.html
- a3_nm 9y agoIf malicious people can add exploitable bugs and claim a bug bounty later, then they can also add exploitable bugs to actually exploit them. So I'd say that bug bounties also work here: they create an incentive to review the code of open-source projects more closely.
- dvt 9y agoAfter a look at some of the bugs linked at http://www.underhanded-c.org/_page_id_2.html http://www.underhanded-c.org/_page_id_2.html, they are very niche and difficult to exploit in any meaningful way. Not only that, but even a mediocre test suite would find something fishy with most.
- 9y ago
- chasil 9y agoIt would be nice if they also approved one for Android Stagefright. All monthly Android security bulletins from this year have critical CVEs in the media system. https://source.android.com/security/bulletin/ https://source.android.com/security/bulletin/
- icebraining 9y agoI think Google can afford to pay for that.