New top story on Hacker News: Ask HN: How do you responsibly report security bugs to open-source projects? - Hindi Top Breaking News - Hindi News, Latest News in Hindi, Breaking News

Papermag-smooth

India Hindi News app brings you the latest news and videos from the Hindi Top Breaking News studios in India. Stay tuned to the latest news stories from India and the world. Access videos and photos on your device with the Hindi Top Breaking News India News app.

Breaking

Home Top Ad

Post Top Ad

Tuesday, December 31, 2019

demo-image

New top story on Hacker News: Ask HN: How do you responsibly report security bugs to open-source projects?

Responsive Ads Here
Ask HN: How do you responsibly report security bugs to open-source projects?
16 by WinonaRyder | 6 comments on Hacker News.
I found a DOS vulnerability in an Open Source project whose maintainer seems to be MIA at the moment. I found it in-the-wild, but not as an exploit so I've only made minimal effort to contact said maintainer - no surprise I haven't gotten a response so far. I don't want to draw any attention to it in a bug report and I'm not sure it's OK to dig up email addresses from commit logs either. It also got me thinking: why don't we have a Bug Bounty-like program for Open Source projects as a whole. What I mean is somewhere where we can post sensitive bugs (even for no pay) and have someone who knows what they're doing guide the process of reporting it responsibly. I know some big projects have this, but e.g. look at the mountain of dependencies that most projects are built on - many of them barely maintained.

No comments:

Post a Comment

Post Bottom Ad

Pages