TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

OWASP Needs to Evolve

201 点作者 bretpiatt大约 2 年前

13 条评论

ath0大约 2 年前
Counterpoint from Josh Sokol, former OWASP board member: <a href="https:&#x2F;&#x2F;www.linkedin.com&#x2F;feed&#x2F;update&#x2F;urn:li:activity:7031305273990389760&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.linkedin.com&#x2F;feed&#x2F;update&#x2F;urn:li:activity:7031305...</a><p>The OWASP nonprofit isn’t like the well-funded Linux Foundation; it runs on a shoestring budget made worse by the loss of conference revenue during the pandemic. OWASP charters events, local meetups, training content and OSS projects - the authors of this memo focus only on the OSS project needs. The OWASP board sees itself as community first and foremost; projects should seek their own sponsorships.
评论 #34847754 未加载
chrismorgan大约 2 年前
I have a very poor opinion of OWASP <i>content</i>, because the couple of areas I’ve paid any attention to have never been any better than mediocre, clearly written by amateurs long ago and largely unmaintained ever since, with <i>known</i> errors and heavily misleading statements hanging around for over a decade on no or unsound justification, among many other problems obvious to any that actually know the field. (See <a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=chrismorgan%20owasp&amp;type=comment" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=chrismorgan%20owasp&amp;type=comme...</a> for a few comments with somewhat more detail, but things have historically been just <i>so</i> bad and so <i>obviously</i> bad that I haven’t bothered enumerating more than the issue that has annoyed me the most.)<p>(Sigh. I see that as part of fixing a lot of the obvious unsuitability of <a href="https:&#x2F;&#x2F;cheatsheetseries.owasp.org&#x2F;cheatsheets&#x2F;Cross_Site_Scripting_Prevention_Cheat_Sheet.html" rel="nofollow">https:&#x2F;&#x2F;cheatsheetseries.owasp.org&#x2F;cheatsheets&#x2F;Cross_Site_Sc...</a> some time in the past two years—and it <i>is</i> much better now, though there are still a few dodgy things about it in both content and presentation—they <i>reintroduced</i> the erroneous advice to entity-encode &#x2F;, which was only <i>finally</i> removed two years ago. Feel free to try to get that fixed, anyone; for my part, I have no interest in trying to work with OWASP.)
评论 #34846967 未加载
评论 #34847804 未加载
评论 #34848239 未加载
评论 #34846966 未加载
weinzierl大约 2 年前
&gt; <i>Today, many projects operate independently, in some cases managing their own sponsorships, finance, websites, domains, communication platforms, and developer tools.</i>&quot;<p>This is quite noticeably when you look at the difference between Dependency-Track and DefectDojo. Both are OWASP projects, but one seems to be modern up-to-date software the other looks like straight from the early 2000s.
评论 #34846327 未加载
评论 #34850598 未加载
eastbound大约 2 年前
In other words, they’re asking for funding and a clear plan per project. OWASP does the Maven dependency scanner, which relies on the NIST db.<p>As a small software vendor, buying other security scanning solutions is very expensive, and they still aren’t as accurate as a pentester investigating our code.<p>Would it be a good idea if OWASP had a paid service where companies would pay for the verification of OSS libraries (hi NPM!)? and that would innocent you in front of EU’s diligence requirements?
Ekaros大约 2 年前
So where do they expect to get the 3-8 million in extra funding just for their projects? From the current whole budget of OWASP of 2 million...
评论 #34847538 未加载
评论 #34848920 未加载
secondcoming大约 2 年前
OWASP<p>&gt; The Open Worldwide Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software.
Sytten大约 2 年前
One of the reason we started to work on my own startup was to provide a credible alternative to Burpsuite as Zap was not evolving in that direction. If we had funding in the amount this letter wants per year it would easy to build it open source and free, but where do they think this money will come from? This is not like the Linux foundation which produces something businesses can use to produce massive amount of money on top. This is competing with commercial products in the space and potentially reducing their revenue.
airza大约 2 年前
Last time i heard from owasp was when they wanted me to do unpaid review for papers being accepted to a paid conference..
评论 #34846443 未加载
评论 #34846422 未加载
评论 #34847132 未加载
KrugerDunnings大约 2 年前
Look at this thiefdom of tools, ZAP is the only cool thing on this list, all the other things are bean counting apps.
评论 #34846897 未加载
Mountain_Skies大约 2 年前
Reading between the lines, sounds like they want control handed over to large corporations with everything controlled by a CoC, enforced by representatives of those corporations, directly or covertly.
markl42大约 2 年前
I’m not familiar with the work that OWASP does, other than the cheat sheet series.<p>The cheat sheet series is amazing - a great resource to defer to when you don’t know or want to think about how to do &lt;x&gt;, you just want to look up and implement the industry standard.<p>It’s a great reference, and I use it lot. &lt;3 to the folks working on that :)
评论 #34849755 未加载
ethereal-haze大约 2 年前
You&#x27;d think with all those name, they could come up with a better standard or something
sdiq大约 2 年前
owasp-change.github.io