4 ms·
This makes me sad. People working on open source projects get nothing. Sometimes they get some money. Sometimes they get some fame. People who don't build anyth
by pleasecalllater 8y ago
This makes me sad. People working on open source projects get nothing. Sometimes they get some money. Sometimes they get some fame. People who don't build anything, but find a hole, they are heroes, they get prizes, they are worshiped.
If there is a commonly used open source library without hackable bugs, you won't even hear about the author who committed his/her own time to build reliable software.
If someone finds a bug, then she will get some prize, and will be invited to a conference. And the library author will be publicly bashed as an idiot.
Sometimes open source people don't even get mentions.
I was working on a patch for a huge open source project once. I spent hours on that. Two other people helped me, they also spent some significant time on that. And we managed to implement this. Who was mentioned in the release changelog? The person who committed that. Then I stopped spending my precious time on such things like giving someone the credits for my work. I love programming, I work on my own projects instead.
And all that makes me sad.
- brightball 8y agoIt seems like the people who work on the code bases would know vulnerabilities better than anyone. Couldn't this provide an opportunity?
- cozzyd 8y agoThat's kind of a perverse incentive to be less careful at first and cash in later
- koliber 8y agoAnyone who has ever placed in the underhanded C contest should be automatically disqualified from committing code. You know, "your hands are deadly weapons" type of exception. \s
- nickpsecurity 8y agoNah, you just review what they submit like everyone else. If you block them, they'll do the contest under an alias or use different names for contributions. Plus, they're really smart folks who might bring a lot of value to the project.
- scbrg 8y agoAs predicted by Scott Adams some twentythree years ago :-) http://dilbert.com/strip/1995-11-13 http://dilbert.com/strip/1995-11-13
- slezyr 8y agoSure, they put them intentionally there :)
- xxs 8y agofor 500k they might as well. It's an ugly practice.
- thepumpkin1979 8y ago> Who was mentioned in the release changelog? The person who committed that. Then I stopped spending my precious time on such things like giving someone the credits for my work. I love programming, I work on my own projects instead. That was handled very poorly by the open-source project, I think all projects need something like kentcdodds's all-contributors[0] guidelines which does require additional tooling and there is definitely additional code reviewing care in order to merge Pull Requests but it makes all contributors feel good when they look back at the effort of all contributions. I experienced this first hand when I contributed to one of the open source modules of the guy, the repo tooling didn't let me submit the code and I said to myself "well this is stupid, I just need the code to be merged ASAP", after a few minutes at first I figured it out and the PR got accepted. Now I can actually go back and say "hey look at my face in the Readme of the repo, that's me, yay!" which sounds stupid but I assure you I won't hesitate to contribute again. [0]https://github.com/kentcdodds/all-contributors https://github.com/kentcdodds/all-contributors
- jdietrich 8y ago>This makes me sad. People working on open source projects get nothing. Sometimes they get some money. Sometimes they get some fame. People who don't build anything, but find a hole, they are heroes, they get prizes, they are worshiped. I think you've misunderstood what's happening here. Zerodium, the company mentioned in this article, is an exploit broker. They buy vulnerabilities from researchers, then sell them on to government intelligence agencies. The entire purpose of their business is to undermine the security of the tools we use. Bug bounties are a response to this trade in exploits. They incentivise researchers to publish vulnerabilities rather than selling them to spies. They're a necessary evil to keep zero-day vulnerabilities out of the hands of oppressive regimes. It's not nice, but that's just the world we live in. Large companies that rely on open source software have started to understand the importance of financially supporting OSS development, largely as a result of the Heartbleed crisis. The Linux Foundation's Core Infrastructure Initiative has created a secure financial foundation for critical open source projects.
- pleasecalllater 8y agoI understood. That was just my thought about the whole situation where you can earn on finding bugs, not on writing reliable software.
- xxs 8y ago> They buy vulnerabilities from researchers... or provide an opportunity for the original developers to introduce an obscure backdoor and cash out
- pas 8y agoThat's an interesting take on the situation. Was there any instance of this? Are there disincentives against this? (I guess the entity offering the bounty could say, only software released before this day is available. Though malicious contributors can very certainly guess that there will be other future bug bounties too.)
- Zophike1 8y ago
- pleasecalllater 8y agoAnd could people, who are giving me negative points, write something about what's wrong with what I wrote? The number of points for the parent comment jumps up and down.
- y0ghur7_xxx 8y ago> If there is a commonly used open source library without hackable bugs, you won't even hear about the author who committed his/her own time to build reliable software. Come on, that's not true. There was a sectest made on dovecot a while back, and it came out to be a really well written piece of software, and everybody complimented the authors and had kind words for them. Same for ssh and a lot of other oss.
- tw04 8y ago>This makes me sad. People working on open source projects get nothing. Sometimes they get some money. Sometimes they get some fame. This falls apart pretty quickly. You're assuming that people writing open source software WANT money or WANT fame. If they want those things, then they should ensure they go about it the proper way. As with nearly everything in life, nobody is just going to hand it to you. As for people finding exploits being "bad". If I volunteer to build a playground, then forget lag bolts on the walkway, is the person who reports the missing bolts bad? Or are they GOOD because they informed someone who could fix it before someone got hurt? Finding exploits, and paying for exploits isn't a bad thing. There's a reason we have inspectors. What you can very much argue is a bad this are companies like Zerodium who use those exploits to intentionally harm everyone else. It would be the equivalent of a lawyer hiring an inspector to review every public playground he could find so that he could file lawsuits.
- 0xdeadbeefbabe 8y agoBash had the shell shock bug for over 25 years before someone found it. No physical analogy for that comes to mind, but we can pretend I suppose.
- pleasecalllater 8y agoIt seems like you read something else then. I'm just saying that the situation is sad. So there were people who built a playground. And then there were people who found bugs in the design or the implementation. The sad situation is that people will make heroes only from those who found bugs. They even want to pay for that. And for the work of those who built that? Seems like they will be forgotten, or blamed for the bugs. I'd rather see both groups treated the same way. > Finding exploits, and paying for exploits isn't a bad thing. I agree. What is bad is paying only for the exploits, totally forgetting about all the people who worked on building the code. Just imagine that you are paying for building a house. But you will pay only for the problems that will be found. I think that in a couple of months you will get buildings full of problems, and then the builders will find them, and get payed. This will be quite terrible.
- mrighele 8y agoIt would kind to have the same level of rewards for people/projects with a proven track record regarding security. If you are willing to give bounties to bug hunters, you may just give them to developers in order not to introduce the bugs
- Zophike1 8y ago> This makes me sad. People working on open source projects get nothing. Sometimes they get some money. Sometimes they get some fame. People who don't build anything, but find a hole, they are heroes, they get prizes, they are worshiped. I've been looking at open source communities especially in the Vulnerability research space it seems there's been a lot of favoritism towards attack oriented research from the community.