Ask HN: How do you responsibly report security bugs to open-source projects?
11 by WinonaRyder | 4 comments on Hacker News.
I found a DOS vulnerability in an Open Source project whose maintainer seems to be MIA at the moment. I found it in-the-wild, but not as an exploit so I've only made minimal effort to contact said maintainer - no surprise I haven't gotten a response so far. I don't want to draw any attention to it in a bug report and I'm not sure it's OK to dig up email addresses from commit logs either. It also got me thinking: why don't we have a Bug Bounty-like program for Open Source projects as a whole. What I mean is somewhere where we can post sensitive bugs (even for no pay) and have someone who knows what they're doing guide the process of reporting it responsibly. I know some big projects have this, but e.g. look at the mountain of dependencies that most projects are built on - many of them barely maintained.
Post Top Ad
Tuesday, December 31, 2019

Home
Hacker News
New top story on Hacker News: Ask HN: How do you responsibly report security bugs to open-source projects?
New top story on Hacker News: Ask HN: How do you responsibly report security bugs to open-source projects?
Tags
# Hacker News
Share This
About Unknown
Templatesyard is a blogger resources site is a provider of high quality blogger template with premium looking layout and robust design. The main mission of templatesyard is to provide the best quality blogger templates which are professionally designed and perfectlly seo optimized to deliver best result for your blog.
New top story on Hacker News: The Alien-Life Summit (2013)
AnonymousMay 23, 2023New top story on Hacker News: Show HN: I'm open sourcing Harmonic, the Android Hacker News client
AnonymousMay 23, 2023New top story on Hacker News: What It Was Like to Live Inside Habitat 67
AnonymousMay 22, 2023
Labels:
Hacker News
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment