Vulnerability Reporting Badge #18
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This is a random thought, and one that I might decide is rubbish in the light of day.
Security.txt (RFC9116) suggests an acknowledgements/hall of fame section. We don't have a paid bug bounty, so maybe a compromise is that we create a badge and hand it out for making the reports? Then we can just link to the list of users who have the badge in the security.txt.
I expect this to be infrequent enough that it can be manually issued.
@thebeanogamer wrote in #18 (comment):
I like the idea in theory... but the last thing we want to do is have to wade through crap reports from people who are only reporting because they want the badge.
It's the same problem places with actual bug bounty programs are dealing with, people using AI to find 'issues' just so they can try to get a payout. And then the project has to deal with crap reports.
Sadly, the only people a badge will matter to is existing Fedora Users. External security people probably aren't going to care about user flare like a badge. I could be wrong though.
When I first read the ticket I thought... hey... that's not a bad idea. Then I thought about it a little more and thought about some of the community members I've dealt with over the years... and on second thought I'm not so sure.
Maybe I'm just being a curmudgeon though. So disregard my ramblings unless others agree. haha
No you raise a fair point. My hope was that by making it something as obscure to the general public as a Fedora Badge we might avoid spam, but I might be overthinking it. I think having the security contact on fedoraproject.org will probably drive more spam than this does.
People do chase the bugs for non-paying programs on HackerOne, but that's a dedicated platform so it's not an entirely fair comparison.
For reference, $DAYJOB is in a similar state. We have a public vulnerability reporting email address but no bug bounty program. Off the top of my head, I think we get ~1 report per month and maybe 1/3 are worth investigating. I don't think we've ever gotten a report that's not just tool output shoved through an LLM though.
As I say though, it's just an idea. I'm not going to lose sleep if we don't do it.
I actually agree to both of you and think there might be a means in the middle that would not cause a large effort but still be attractive to audience both within and outside of Fedora:
Having worked with people from pentesting in the past, their world has one thing with open source in common: reputation is currency. Getting public appreciation of them having identified security issues that no one else has identified is not only social confirmation for them but also professionally valuable.
So, if someone finds a security issue that is sufficiently noteworthy for us to act (may it be time critical or not?), we can publish a topic in the News Category in Discourse about it. The News are auto-enabled for users and my experience is that a lot of people read it (they are quite good ranked in SEO as well). In any case, it gives someone a type of "evidence" with us confirming that they found something valuable. This can go along with a badge for those active in Fedora, or not.
I can publish in the News category, but I would need to check out in advance (maybe in a new topic?) if everyone agrees to this, and then I can check with the moderation team if anyone there would have an objection. If not, I could implement these News posts, without further "bureaucracy".
Just to have the possibility mentioned :)
Supplement: as alternative to the News category, we can use the #security-sig tag in the Project Discussion category. Well ranked too. But not as good as News, and "less formal" too. Only News is News, I could imagine that makes a difference :)
Involving the magazine people is another possibility, one of the editors is in the moderation team (magazine articles are mirrored to Discourse), but that would then become a more formal project of course -> not sure if that is worth the effort considering we don't know how much this incentive will pay back in a context like ours. But its possible...
This got a 👍 at the meeting, but we'd appreciate feedback from @Jflory7 before proceeding.
If he's agreeable, I'll raise a ticket with the Design SIG for the artwork and a PR on the Badges repo to implement.
I remove the meeting label for now, but feel free to add it again at any time if anything comes up.
@thebeanogamer Sorry for the late follow-up! It is not clear to me what part of the above discussion you would like my feedback on. Could you clarify? Thanks!