FOSSA: The European Union will fund bug bounty programs for 14 open source projects, according to EU MEP Julia Reda.

The 14 projects are alphabetically the well-known applications:
7-zip, Apache Kafka, Apache Tomcat, Digital Signature Services (DSS), Drupal, Filezilla, FLUX TL, the GNU C Library (glibc), KeePass, midPoint, Notepad++, PuTTY, Symfony PHP framework, VLC Media Player, and WSO2.
Bug bounty programs (programs for finding errors in application code) are funded under the third edition of the Free and Open Source Software Audit (FOSSA) project.
EU authorities first approved FOSSA in 2015, after security researchers discovered serious vulnerabilities a year earlier in the OpenSSL library, an open source project that websites (and others) use to support HTTPS connections.
“The issue made many realize how important Free and Open Source Software is to the integrity and reliability of the Internet and other infrastructure,” Reda said in her statement.
Like many other organizations, institutions such as the European Parliament, the European Council, and the European Commission rely on Free Software to power their websites.
The first version of FOSSA was piloted between 2015 and 2016, with an initial budget of 1 million euros. The EU identified the most popular open source projects used by EU offices and employees and conducted a public survey to decide which ones to fund. Two projects were selected, the Apache web server and the KeePass password manager.
FOSSA 2 was launched in 2017 as a HackerOne bug bounty for the VLC Media Player application. The project received funding of 2 million euros.
Now, FOSSA is back for its third edition with budgets for 14 bug bounty programs. The highest budgets are for the PuTTY application and the Drupal CMS web application.
| Software | Financing | Inception | Expiry | Bug Bounty Platform |
|---|---|---|---|---|
| Filezilla | 58.000,00 € | 07/01/2019 | 15/08/2019 | HackerOne |
| Apache Kafka | 58.000,00 € | 07/01/2019 | 15/08/2019 | HackerOne |
| Notepad++ | 71.000,00 € | 07/01/2019 | 15/08/2019 | HackerOne |
| PuTTY | 90.000,00 € | 07/01/2019 | 15/12/2019 | HackerOne |
| VLC Media Player | 58.000,00 € | 07/01/2019 | 15/08/2019 | HackerOne |
| FLUX TL | 34.000,00 € | 15/01/2019 | 15/10/2019 | Integrity/Deloitte |
| KeePass | 71.000,00 € | 15/01/2019 | 31/07/2019 | Integrity/Deloitte |
| 7 zip | 58.000,00 € | 30/01/2019 | 15/04/2020 | Integrity/Deloitte |
| Digital Signature Services (DSS) | 25.000,00 € | 30/01/2019 | 15/10/2019 | Integrity/Deloitte |
| Drupal | 89.000,00 € | 30/01/2019 | 15/10/2020 | Integrity/Deloitte |
| GNU C Library (glibc) | 45.000,00 € | 30/01/2019 | 15/12/2019 | Integrity/Deloitte |
| PHP Symfony | 39.000,00 € | 30/01/2019 | 15/10/2019 | Integrity/Deloitte |
| Apache Tomcat | 39.000,00 € | 30/01/2019 | 15/10/2019 | Integrity/Deloitte |
| WSO2 | 58.000,00 € | 30/01/2019 | 15/04/2020 | Integrity/Deloitte |
| midPoint | 58.000,00 € | 01/03/2019 | 15/08/2019 | HackerOne |
So, starting in January, researchers and security companies can hunt for vulnerabilities in the above open source projects. By reporting potential vulnerabilities (bugs) in the applications listed above, they will be able to earn financial rewards from the EU, provided that the errors they discover are critical.
__________________
- Google: ceded Duck.com to DuckDuckGo
- HWiNFO: A free program to monitor your computer
- Screen recording to video with VLC media player
- Disable cookie acceptance messages
- Open Source: how it changed the world
