9 ms·
OWASP Needs to Evolve
- weinzierl 4y ago> Today, many projects operate independently, in some cases managing their own sponsorships, finance, websites, domains, communication platforms, and developer tools." This is quite noticeably when you look at the difference between Dependency-Track and DefectDojo. Both are OWASP projects, but one seems to be modern up-to-date software the other looks like straight from the early 2000s.
- throwboatyface 4y agoIn my experience if the authors get their wish then both will look 20-years-old.
- robertlagrant 4y agoThreatDragon[0] is also looking nice. [0] https://www.threatdragon.com https://www.threatdragon.com
- secondcoming 4y agoOWASP > The Open Worldwide Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software.
- airza 4y agoLast time i heard from owasp was when they wanted me to do unpaid review for papers being accepted to a paid conference..
- quelltext 4y agoSo, like any other instance of this (in academia).
- tptacek 4y agoI was going to say: that describes Usenix, too.
- wccrawford 4y agoI understand the visceral reaction there, but OWASP is a nonprofit foundation, and conferences cost money to host. They were attempting to make the conference as cheap as possible by getting volunteers instead of paying people for whatever work they could, I'm sure. If this was a for-profit company, I'd completely agree with you, but it's not.
- aaron695 4y ago[dead]
- eastbound 4y agoIn other words, they’re asking for funding and a clear plan per project. OWASP does the Maven dependency scanner, which relies on the NIST db. As a small software vendor, buying other security scanning solutions is very expensive, and they still aren’t as accurate as a pentester investigating our code. Would it be a good idea if OWASP had a paid service where companies would pay for the verification of OSS libraries (hi NPM!)? and that would innocent you in front of EU’s diligence requirements?
- KrugerDunnings 4y agoLook at this thiefdom of tools, ZAP is the only cool thing on this list, all the other things are bean counting apps.
- unixhero 4y agoBean counters get funding to improve cyber security and hire the techies. Respect the Excel jockies mate.
- KrugerDunnings 4y agoOnly if they use Excel instead of these tools buddy
- chrismorgan 4y agoI have a very poor opinion of OWASP content, because the couple of areas I’ve paid any attention to have never been any better than mediocre, clearly written by amateurs long ago and largely unmaintained ever since, with known errors and heavily misleading statements hanging around for over a decade on no or unsound justification, among many other problems obvious to any that actually know the field. (See https://hn.algolia.com/?query=chrismorgan%20owasp&type=comment https://hn.algolia.com/?query=chrismorgan%20owasp&type=comme... for a few comments with somewhat more detail, but things have historically been just so bad and so obviously bad that I haven’t bothered enumerating more than the issue that has annoyed me the most.) (Sigh. I see that as part of fixing a lot of the obvious unsuitability of https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Sc... some time in the past two years—and it is much better now, though there are still a few dodgy things about it in both content and presentation—they reintroduced the erroneous advice to entity-encode /, which was only finally removed two years ago. Feel free to try to get that fixed, anyone; for my part, I have no interest in trying to work with OWASP.)
- colbyx 4y agoAgreed, that matches my experience too, it's the clueless leading the clueless. I actively steer people away from OWASP regarding training and reference materials.
- programmarchy 4y agoWhat’s the best alternative?
- dwheeler 4y agoThis doesn't exactly answer your question, but if you want a basic course for software developers in how to develop secure software, check out this free course from the OpenSSF: https://openssf.org/training/courses/ https://openssf.org/training/courses/ Full disclosure: I'm the primary author.
- Mountain_Skies 4y agoReading between the lines, sounds like they want control handed over to large corporations with everything controlled by a CoC, enforced by representatives of those corporations, directly or covertly.
- ath0 4y agoCounterpoint from Josh Sokol, former OWASP board member: https://www.linkedin.com/feed/update/urn:li:activity:7031305273990389760/ https://www.linkedin.com/feed/update/urn:li:activity:7031305... The OWASP nonprofit isn’t like the well-funded Linux Foundation; it runs on a shoestring budget made worse by the loss of conference revenue during the pandemic. OWASP charters events, local meetups, training content and OSS projects - the authors of this memo focus only on the OSS project needs. The OWASP board sees itself as community first and foremost; projects should seek their own sponsorships.
- electroly 4y agoIf OWASP wants to focus on chapters and events, why do they have projects under their umbrella at all? We had a similar problem in the .NET ecosystem with the .NET Foundation. It turned out they don't really do that much for the projects they oversee after all, so what's the point? Why be part of an organization that isn't providing the support you need? Perhaps, indeed, they should not be. Given this response, it sounds to me like the projects should leave. What they need is simply different than what OWASP wants or is financially able to provide. The projects have outgrown the organization, and the organization doesn't see itself as being primarily about the projects. Sounds, to me, like it's time to make a clean break that unburdens OWASP and frees the projects.
- throwaway2847 4y agoThe projects should leave. I don't think they are a critical component of OWASP compared to the educational material provided through their documentation and conferences.
- tptacek 4y agoTwo of the major projects in the list of cosigners on this are the OWASP Top 10 project and ASVS, which are the two big educational projects at OWASP. I don't especially love either of those projects, but they're arguably the two most important things OWASP works on outside of the conferences. The Top 10 project can't really leave OWASP (ASVS could). ZAP is the only other project there that I think is all that important to the identity of OWASP itself, but it should just go find its own sponsorship anyways. People like ZAP, but the industry standard is Burp Suite; Burp is Microsoft Office to ZAP's... LibreOffice? Like all the software freedom stuff aside, if you're a professional, you use Word.
- Ekaros 4y agoSo where do they expect to get the 3-8 million in extra funding just for their projects? From the current whole budget of OWASP of 2 million...
- DyslexicAtheist 4y agoany security standards today and legislations such as radio equipment directive (RED) for IoT piggy-backs on the work done by OWASP. maybe it's time for these standards bodies, ETSI, ISO, UL, IoXT, ... to give back and help with some of the funding.
- tptacek 4y agoThey're explicitly asking for corporate membership on the OWASP board, to attract more sponsorship dollars.
- deleted 4y ago[deleted]
- Sytten 4y agoOne of the reason we started to work on my own startup was to provide a credible alternative to Burpsuite as Zap was not evolving in that direction. If we had funding in the amount this letter wants per year it would easy to build it open source and free, but where do they think this money will come from? This is not like the Linux foundation which produces something businesses can use to produce massive amount of money on top. This is competing with commercial products in the space and potentially reducing their revenue.
- sdiq 4y agoowasp-change.github.io
- ethereal-haze 4y agoYou'd think with all those name, they could come up with a better standard or something
- markl42 4y agoI’m not familiar with the work that OWASP does, other than the cheat sheet series. The cheat sheet series is amazing - a great resource to defer to when you don’t know or want to think about how to do <x>, you just want to look up and implement the industry standard. It’s a great reference, and I use it lot. <3 to the folks working on that :)
- chrismorgan 4y agoThe main cheat sheet I’ve looked closely at is the XSS one, and it’s never been better than mediocre, with (for over a decade, despite it being known about; only recently has it been redone to be tolerable, though still not excellent) awful framing, grossly misleading structure (seriously, almost every citations I’ve seen of it has misapplied it because of this), irrelevant and excessive content in some areas and critical missing content in other areas. Therefore my recommendation is: use it for general awareness, perhaps, but do not trust it. Because there probably isn’t anyone really working on it—you’re probably actually looking at something that was written well over 10 years ago by an amateur, and has received almost no maintenance since then.
- CaliforniaKarl 4y agoCan you recommend a good substitute for the Cheatsheets?