TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The European Parliament has approved budget for VLC bug bounty program

168 点作者 D3_4dl1N3超过 7 年前

4 条评论

barrkel超过 7 年前
Is anyone else concerned at the perverse incentives created by bug bounties on open source software?<p>Monetizing bugs may end up encouraging the creation of insidious, underhanded bugs explicitly so that bounties can later be claimed by other parties supposedly at arms length.
评论 #15846373 未加载
评论 #15850398 未加载
评论 #15849353 未加载
chasil超过 7 年前
It would be nice if they also approved one for Android Stagefright.<p>All monthly Android security bulletins from this year have critical CVEs in the media system.<p><a href="https:&#x2F;&#x2F;source.android.com&#x2F;security&#x2F;bulletin&#x2F;" rel="nofollow">https:&#x2F;&#x2F;source.android.com&#x2F;security&#x2F;bulletin&#x2F;</a>
评论 #15847931 未加载
heavenlyblue超过 7 年前
Why VLC?
评论 #15846327 未加载
评论 #15846357 未加载
评论 #15846298 未加载
gcbw2超过 7 年前
what about this rationale:<p>&gt; The purpose of the procedure is to provide the European institutions with open source software projects or libraries that have been properly screened for potential vulnerabilities;<p>I don&#x27;t think bug bounty is a substitute for certification. And it benefits the most if is a long-run with accumulating rewards.<p>making it short term with only one payout will only attract people with automated tools for the initial period. Then code will get &quot;certified&quot; and forgotten. It all seems wrong. Hopefully it is just bad wording on the official PR.
评论 #15846307 未加载
评论 #15846290 未加载
评论 #15846153 未加载