skip to main content
European Commission Logo
en English
Newsroom

Overview    News

More bug bounties and a hackathon in the next stage of EU FOSSA

What can we do for security of open source software? This was the question after the Heartbleed bug shocked the world revealing a serious vulnerability in the widely used OpenSSL library. With the help of Members of the European Parliament, DG Informatics addresses the issue through a number of actions in the EU-FOSSA pilot project.

Related topics

Informatics

date:  09/02/2018

The objective of EU-FOSSA is to try different methods to address the security of open source software used at the European Institutions and to make investing in security of OSS a permanent action of the EU.

The novelty in the new phase, called EU-FOSSA 2, are the bug bounties. The results of a recent proof of concept for the popular open source media player VLC were presented by Marek Przybyszewski at FOSDEM – the annual forum for open source software in Brussels. The bug bounty activity was open for submissions for 6 weeks. A total of 28 participants tried to find vulnerabilities in VLC, 5 of them succeeded and were awarded.

’’This is something the European institutions never did before, they never paid researchers or hackers to find bugs in software. We managed to prove that this approach really works’’, Marek pointed out revealing that a new Call for Tenders is currently under preparation to launch more bug bounty activities. More than 20 critical OSS projects are planned to be audited with a budget of 1.6 M EUR in 2018-2019.

Hackathon in November 2018

Also in the plan is to organise a hackathon, bringing developers from a selected open source software community for a couple of days in Brussels. They will meet in person, possibly for the first time ever, to fix outstanding difficult problems in their project.

 

Follow the page of EU-FOSSA for updates

Related Content

Connected Content