4 ms·
It would be awesome if researchers documented not only the vulnerabilities they find, but also all the software they analyzed without any findings, and how they
by buitreVirtual 5y ago
It would be awesome if researchers documented not only the vulnerabilities they find, but also all the software they analyzed without any findings, and how they analyzed it. It would save the community from re-doing the same analysis and maybe suggest what else other researchers might have missed. (This is not really different from the real need to publish negative results in science.)
- justin_oaks 5y agoActively developed open source projects are a moving target, thus it'd be good to indicate which versions were reviewed or tested. If a vulnerability were later found in a version that was checked then it would be good for the OpenSSF to review how it was missed. Hopefully that'll let them be better in the future. I also like the idea of them documenting their methodology. Open source the process of finding vulnerabilities in open source projects!
- buitreVirtual 5y agoThat's the idea!
- scovetta 5y agoI love this, yes. Root cause analysis ("How did this thing happen in the first place, does it exist anywhere else, and how can we prevent it from happening again?") should be a core part of our work in Alpha-Omega, and we should include this information in our publications. To the larger point -- the idea of "open sourcing the process for finding vulnerabilities in open source" captures a lot of the work already being done in OpenSSF, but there's a lot more we can do. (If you're interested in helping us with this, we'd love to have you!)
- 74B5 5y ago>It would save the community from re-doing the same analysis I vaguely disagree. Secure software is not a well defined state so security analysis is not a process with an end condition, so theoretically, you can never stop looking. But documenting failed attempts and methods is still worthy because duplicate work may still teach a lessons.