TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OWASP Needs to Evolve

201 pointsby bretpiattover 2 years ago

13 comments

ath0over 2 years ago
Counterpoint from Josh Sokol, former OWASP board member: <a href="https:&#x2F;&#x2F;www.linkedin.com&#x2F;feed&#x2F;update&#x2F;urn:li:activity:7031305273990389760&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.linkedin.com&#x2F;feed&#x2F;update&#x2F;urn:li:activity:7031305...</a><p>The OWASP nonprofit isn’t like the well-funded Linux Foundation; it runs on a shoestring budget made worse by the loss of conference revenue during the pandemic. OWASP charters events, local meetups, training content and OSS projects - the authors of this memo focus only on the OSS project needs. The OWASP board sees itself as community first and foremost; projects should seek their own sponsorships.
评论 #34847754 未加载
chrismorganover 2 years ago
I have a very poor opinion of OWASP <i>content</i>, because the couple of areas I’ve paid any attention to have never been any better than mediocre, clearly written by amateurs long ago and largely unmaintained ever since, with <i>known</i> errors and heavily misleading statements hanging around for over a decade on no or unsound justification, among many other problems obvious to any that actually know the field. (See <a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=chrismorgan%20owasp&amp;type=comment" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=chrismorgan%20owasp&amp;type=comme...</a> for a few comments with somewhat more detail, but things have historically been just <i>so</i> bad and so <i>obviously</i> bad that I haven’t bothered enumerating more than the issue that has annoyed me the most.)<p>(Sigh. I see that as part of fixing a lot of the obvious unsuitability of <a href="https:&#x2F;&#x2F;cheatsheetseries.owasp.org&#x2F;cheatsheets&#x2F;Cross_Site_Scripting_Prevention_Cheat_Sheet.html" rel="nofollow">https:&#x2F;&#x2F;cheatsheetseries.owasp.org&#x2F;cheatsheets&#x2F;Cross_Site_Sc...</a> some time in the past two years—and it <i>is</i> much better now, though there are still a few dodgy things about it in both content and presentation—they <i>reintroduced</i> the erroneous advice to entity-encode &#x2F;, which was only <i>finally</i> removed two years ago. Feel free to try to get that fixed, anyone; for my part, I have no interest in trying to work with OWASP.)
评论 #34846967 未加载
评论 #34847804 未加载
评论 #34848239 未加载
评论 #34846966 未加载
weinzierlover 2 years ago
&gt; <i>Today, many projects operate independently, in some cases managing their own sponsorships, finance, websites, domains, communication platforms, and developer tools.</i>&quot;<p>This is quite noticeably when you look at the difference between Dependency-Track and DefectDojo. Both are OWASP projects, but one seems to be modern up-to-date software the other looks like straight from the early 2000s.
评论 #34846327 未加载
评论 #34850598 未加载
eastboundover 2 years ago
In other words, they’re asking for funding and a clear plan per project. OWASP does the Maven dependency scanner, which relies on the NIST db.<p>As a small software vendor, buying other security scanning solutions is very expensive, and they still aren’t as accurate as a pentester investigating our code.<p>Would it be a good idea if OWASP had a paid service where companies would pay for the verification of OSS libraries (hi NPM!)? and that would innocent you in front of EU’s diligence requirements?
Ekarosover 2 years ago
So where do they expect to get the 3-8 million in extra funding just for their projects? From the current whole budget of OWASP of 2 million...
评论 #34847538 未加载
评论 #34848920 未加载
secondcomingover 2 years ago
OWASP<p>&gt; The Open Worldwide Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software.
Syttenover 2 years ago
One of the reason we started to work on my own startup was to provide a credible alternative to Burpsuite as Zap was not evolving in that direction. If we had funding in the amount this letter wants per year it would easy to build it open source and free, but where do they think this money will come from? This is not like the Linux foundation which produces something businesses can use to produce massive amount of money on top. This is competing with commercial products in the space and potentially reducing their revenue.
airzaover 2 years ago
Last time i heard from owasp was when they wanted me to do unpaid review for papers being accepted to a paid conference..
评论 #34846443 未加载
评论 #34846422 未加载
评论 #34847132 未加载
KrugerDunningsover 2 years ago
Look at this thiefdom of tools, ZAP is the only cool thing on this list, all the other things are bean counting apps.
评论 #34846897 未加载
Mountain_Skiesover 2 years ago
Reading between the lines, sounds like they want control handed over to large corporations with everything controlled by a CoC, enforced by representatives of those corporations, directly or covertly.
markl42over 2 years ago
I’m not familiar with the work that OWASP does, other than the cheat sheet series.<p>The cheat sheet series is amazing - a great resource to defer to when you don’t know or want to think about how to do &lt;x&gt;, you just want to look up and implement the industry standard.<p>It’s a great reference, and I use it lot. &lt;3 to the folks working on that :)
评论 #34849755 未加载
ethereal-hazeover 2 years ago
You&#x27;d think with all those name, they could come up with a better standard or something
sdiqover 2 years ago
owasp-change.github.io