The EU is Giving Out Bug Bounties for Open Source Projects

in #open-source6 years ago

Source


I've recently discovered through the blog of Julia Reda (Pirate Party European Parliament member), that the EU is funding bug bounties for open-source projects, starting mid-January 2019.

Back in 2014, vulnerabilities were found in OpenSSL and this prompted Julia Reda & Max Andersson to start an Open-Source software audit project called FOSSA. Through the first iteration of this project, two Open-Source project received security audits that were funded by the EU, the Apache webserver and the KeePass password manager.

Back in 2017, it was decided to add bug bounties to the scope of the FOSSA project and below you can see a list of projects for which bug bounties are available. In total, there's €851.000 in bug bounties to be earned and the amount of each individual bounty depends on the severity of the issue, together with the importance on the project.


Software ProjectBug Bounty Amount (Euro)Start DateEnd DateBug Bounty Platform
Filezilla€58.00007/01/201915/08/2019HackerOne
Apache Kafka€58.00007/01/201915/08/2019HackerOne
Notepad++€71.00007/01/201915/08/2019HackerOne
PuTTY€90.00007/01/201915/12/2019HackerOne
VLC Media Player€58.00007/01/201915/08/2019HackerOne
FLUX TL€34.00015/01/201915/10/2019Intigriti/Deloitte
KeePass€71.00015/01/201931/07/2019Intigriti/Deloitte
7-zip€58.00030/01/201915/04/2020Intigriti/Deloitte
Digital Signature Services (DSS)€25.00030/01/201915/10/2019Intigriti/Deloitte
Drupal€89.00030/01/201915/10/2020Intigriti/Deloitte
GNU C Library (glibc)€45.00030/01/201915/12/2019Intigriti/Deloitte
PHP Symfony€39.00030/01/201915/10/2019Intigriti/Deloitte
Apache Tomcat€39.00030/01/201915/10/2019Intigriti/Deloitte
WSO2€58.00030/01/201915/04/2020Intigriti/Deloitte
midPoint€58.00001/03/201915/08/2019HackerOne
TOTAL€851.000

So, if you're currently already contributing to the Bug Hunting category on @utopian-io, you might also want to look into getting some of these bounties. You still have ample amount of time to prepare and you might discover some serious security flaws in your favourite Open-Source projects!

Featured image was made by Brent-Ritztro and released under CC-BY-SA 3.0

Data used in this article was originally gathered by Julia Reda and adapted by me (added totals). With permission.

Original Source: https://juliareda.eu/2018/12/eu-fossa-bug-bounties/


This is not a submission for @utopian-io, though I have used the tag since the information presented here could be of use for Utopian contributors

Sort:  

Thats a cool initiative that that provide funds to motivate people to work and find solutions ot these issues

Wishing you and yours a Happy New Years and all the best for 2019

Happy NY for you too @tattoodjay!

Thanks Kindly :)

Wow, this is really cool and also a bit scary as I look at the list, I use a lot of those programs on a daily basis. Glad that there is this initiative to get them secure!

Thank you so much for participating the Partiko Delegation Plan Round 1! We really appreciate your support! As part of the delegation benefits, we just gave you a 3.00% upvote! Together, let’s change the world!

Hi @daan!

Your post was upvoted by @steem-ua, new Steem dApp, using UserAuthority for algorithmic post curation!
Your UA account score is currently 3.903 which ranks you at #4094 across all Steem accounts.
Your rank has improved 77 places in the last three days (old rank 4171).

In our last Algorithmic Curation Round, consisting of 268 contributions, your post is ranked at #57.

Evaluation of your UA score:
  • You're on the right track, try to gather more followers.
  • The readers like your work!
  • Great user engagement! You rock!

Feel free to join our @steem-ua Discord server

Congratulations! This post has been chosen as one of the daily Whistle Stops for The STEEM Engine!

You can see your post's place along the track here: The Daily Whistle Stops, Issue 358 (01/01/19)

Coin Marketplace

STEEM 0.18
TRX 0.16
JST 0.030
BTC 65974.40
ETH 2637.70
USDT 1.00
SBD 2.67