create account

The EU is Giving Out Bug Bounties for Open Source Projects by daan

View this thread on: hive.blogpeakd.comecency.com
· @daan ·
$2.36
The EU is Giving Out Bug Bounties for Open Source Projects
<center>![](https://cdn.steemitimages.com/DQmYyzGNYGrkytUMUQcS7M1Pn81hFzBQqDZW4hc5hawUUcJ/image.png)</center><center>[Source](https://www.deviantart.com/brent-ritztro/art/Simply-Open-Source-267461589)</center>

---

I've recently discovered through the [blog of Julia Reda](https://juliareda.eu/2018/12/eu-fossa-bug-bounties/) (Pirate Party European Parliament member), that the EU is funding bug bounties for open-source projects, starting mid-January 2019. 

Back in 2014, vulnerabilities were found in OpenSSL and this prompted [Julia Reda](https://juliareda.eu/me-for-you-in-europe/) & [Max Andersson](https://twitter.com/maxandersson?lang=en) to start an Open-Source software audit project called FOSSA. Through the first iteration of this project, two Open-Source project received security audits that were funded by the EU, [the Apache webserver and the KeePass password manager](https://juliareda.eu/2016/07/eu-audits-keepass-apache/).

Back in 2017, it was decided to add bug bounties to the scope of the FOSSA project and below you can see a list of projects for which bug bounties are available. In total, there's €851.000 in bug bounties to be earned and the amount of each individual bounty depends on the severity of the issue, together with the importance on the project. 

---

| Software Project                        |  Bug Bounty Amount (Euro)  | Start Date | End Date | Bug Bounty Platform          |
|----------------------------------|--------|------------|------------|--------------------|
| [Filezilla](https://filezilla-project.org/)                        | €58.000  | 07/01/2019 | 15/08/2019 | [HackerOne](https://www.hackerone.com/)          |
| [Apache Kafka](https://kafka.apache.org/)                     | €58.000  | 07/01/2019 | 15/08/2019 | [HackerOne](https://www.hackerone.com/)          |
| [Notepad++](https://notepad-plus-plus.org/)                        | €71.000  | 07/01/2019 | 15/08/2019 | [HackerOne](https://www.hackerone.com/)          |
| [PuTTY](https://www.putty.org/)                            | €90.000  | 07/01/2019 | 15/12/2019 | [HackerOne](https://www.hackerone.com/)          |
| [VLC Media Player](https://www.videolan.org/)                 | €58.000  | 07/01/2019 | 15/08/2019 | [HackerOne](https://www.hackerone.com/)          |
| [FLUX TL](https://joinup.ec.europa.eu/solution/flux-tl)                          | €34.000  | 15/01/2019 | 15/10/2019 | [Intigriti/Deloitte](https://www.intigriti.com/) |
| [KeePass](https://keepass.info/)                          | €71.000  | 15/01/2019 | 31/07/2019 | [Intigriti/Deloitte](https://www.intigriti.com/) |
| [7-zip](https://www.7-zip.org/)                            | €58.000  | 30/01/2019 | 15/04/2020 | [Intigriti/Deloitte](https://www.intigriti.com/) |
| [Digital Signature Services (DSS)](https://ec.europa.eu/cefdigital/wiki/pages/viewpage.action?pageId=46992515) | €25.000  | 30/01/2019 | 15/10/2019 | [Intigriti/Deloitte](https://www.intigriti.com/) |
| [Drupal](https://www.drupal.org/)                           | €89.000  | 30/01/2019 | 15/10/2020 | [Intigriti/Deloitte](https://www.intigriti.com/) |
| [GNU C Library (glibc)](https://www.gnu.org/software/libc/)            | €45.000  | 30/01/2019 | 15/12/2019 | [Intigriti/Deloitte](https://www.intigriti.com/) |
| [PHP Symfony](https://symfony.com/)                      | €39.000  | 30/01/2019 | 15/10/2019 | [Intigriti/Deloitte](https://www.intigriti.com/) |
| [Apache Tomcat](https://tomcat.apache.org/)                    | €39.000  | 30/01/2019 | 15/10/2019 | [Intigriti/Deloitte](https://www.intigriti.com/)|
| [WSO2](https://wso2.com/)                             | €58.000  | 30/01/2019 | 15/04/2020 | [Intigriti/Deloitte](https://www.intigriti.com/) |
| [midPoint](https://evolveum.com/midpoint/)                         | €58.000  | 01/03/2019 | 15/08/2019 | [HackerOne](https://www.hackerone.com/)          |
|                                  |        |            |            |                    |
| **TOTAL**                            | €851.000 |            |            |                    |

---

So, if you're currently already contributing to the Bug Hunting category on @utopian-io, you might also want to look into getting some of these bounties. You still have ample amount of time to prepare and you might discover some serious security flaws in your favourite Open-Source projects! 

### Featured image was made by [Brent-Ritztro](https://www.deviantart.com/brent-ritztro) and released under [CC-BY-SA 3.0](https://creativecommons.org/licenses/by-sa/3.0/)

### Data used in this article was originally gathered by [Julia Reda](https://juliareda.eu/me-for-you-in-europe/) and adapted by me (added totals). With permission. 

### Original Source: https://juliareda.eu/2018/12/eu-fossa-bug-bounties/

---

*This is **not** a submission for @utopian-io, though I have used the tag since the information presented here could be of use for Utopian contributors*
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 89 others
properties (23)
authordaan
permlinkthe-eu-is-giving-out-bug-bounties-for-open-source-projects
categoryopen-source
json_metadata{"links":["https://www.deviantart.com/brent-ritztro/art/Simply-Open-Source-267461589","https://juliareda.eu/2018/12/eu-fossa-bug-bounties/","https://juliareda.eu/me-for-you-in-europe/","https://twitter.com/maxandersson?lang=en","https://juliareda.eu/2016/07/eu-audits-keepass-apache/","https://filezilla-project.org/","https://www.hackerone.com/","https://kafka.apache.org/","https://www.hackerone.com/","https://notepad-plus-plus.org/","https://www.hackerone.com/","https://www.putty.org/","https://www.hackerone.com/","https://www.videolan.org/","https://www.hackerone.com/","https://joinup.ec.europa.eu/solution/flux-tl","https://www.intigriti.com/","https://keepass.info/","https://www.intigriti.com/","https://www.7-zip.org/","https://www.intigriti.com/","https://ec.europa.eu/cefdigital/wiki/pages/viewpage.action?pageId=46992515","https://www.intigriti.com/","https://www.drupal.org/","https://www.intigriti.com/","https://www.gnu.org/software/libc/","https://www.intigriti.com/","https://symfony.com/","https://www.intigriti.com/","https://tomcat.apache.org/","https://www.intigriti.com/","https://wso2.com/","https://www.intigriti.com/","https://evolveum.com/midpoint/","https://www.hackerone.com/","https://www.deviantart.com/brent-ritztro","https://creativecommons.org/licenses/by-sa/3.0/","https://juliareda.eu/me-for-you-in-europe/","https://juliareda.eu/2018/12/eu-fossa-bug-bounties/"],"image":["https://cdn.steemitimages.com/DQmYyzGNYGrkytUMUQcS7M1Pn81hFzBQqDZW4hc5hawUUcJ/image.png"],"users":["utopian-io","utopian-io"],"tags":["open-source","bounty","technology","esteem","utopian-io"],"app":"esteem/2.0.3-surfer","format":"markdown+html","community":"esteem.app"}
created2018-12-31 13:57:06
last_update2018-12-31 13:57:06
depth0
children7
last_payout2019-01-07 13:57:06
cashout_time1969-12-31 23:59:59
total_payout_value1.772 HBD
curator_payout_value0.589 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length4,955
author_reputation68,495,317,885,928
root_title"The EU is Giving Out Bug Bounties for Open Source Projects"
beneficiaries
0.
accountesteemapp
weight1,000
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id77,662,792
net_rshares4,661,885,444,053
author_curate_reward""
vote details (153)
@bozz ·
$0.04
Wow, this is really cool and also a bit scary as I look at the list, I use a lot of those programs on a daily basis.  Glad that there is this initiative to get them secure!
👍  ,
properties (23)
authorbozz
permlinkre-daan-the-eu-is-giving-out-bug-bounties-for-open-source-projects-20190102t125838109z
categoryopen-source
json_metadata{"tags":["open-source"],"app":"steemit/0.1"}
created2019-01-02 12:58:45
last_update2019-01-02 12:58:45
depth1
children0
last_payout2019-01-09 12:58:45
cashout_time1969-12-31 23:59:59
total_payout_value0.033 HBD
curator_payout_value0.010 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length172
author_reputation2,233,470,735,904,856
root_title"The EU is Giving Out Bug Bounties for Open Source Projects"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id77,756,117
net_rshares78,835,336,159
author_curate_reward""
vote details (2)
@partiko ·
Thank you so much for participating the Partiko Delegation Plan Round 1! We really appreciate your support! As part of the delegation benefits, we just gave you a 3.00% upvote! Together, let’s change the world!
properties (22)
authorpartiko
permlinkre-the-eu-is-giving-out-bug-bounties-for-open-source-projects-20181231t143034
categoryopen-source
json_metadata""
created2018-12-31 14:30:36
last_update2018-12-31 14:30:36
depth1
children0
last_payout2019-01-07 14:30:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length210
author_reputation39,207,160,334,751
root_title"The EU is Giving Out Bug Bounties for Open Source Projects"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id77,664,460
net_rshares0
@steem-ua ·
#### Hi @daan!

Your post was upvoted by @steem-ua, new Steem dApp, using UserAuthority for algorithmic post curation!
Your **UA** account score is currently 3.903 which ranks you at **#4094** across all Steem accounts.
Your rank has improved 77 places in the last three days (old rank 4171).

In our last Algorithmic Curation Round, consisting of 268 contributions, your post is ranked at **#57**.
##### Evaluation of your UA score:

* You're on the right track, try to gather more followers.
* The readers like your work!
* Great user engagement! You rock!


**Feel free to join our [@steem-ua Discord server](https://discord.gg/KpBNYGz)**
properties (22)
authorsteem-ua
permlinkre-the-eu-is-giving-out-bug-bounties-for-open-source-projects-20190101t004952z
categoryopen-source
json_metadata"{"app": "beem/0.20.14"}"
created2019-01-01 00:49:54
last_update2019-01-01 00:49:54
depth1
children0
last_payout2019-01-08 00:49:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length641
author_reputation23,214,230,978,060
root_title"The EU is Giving Out Bug Bounties for Open Source Projects"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id77,686,874
net_rshares0
@tattoodjay ·
$0.07
Thats a cool initiative that that provide funds to motivate people to work and find solutions ot these issues 

Wishing you and yours a Happy New Years and all the best for 2019 
👍  , ,
properties (23)
authortattoodjay
permlinkre-daan-the-eu-is-giving-out-bug-bounties-for-open-source-projects-20181231t160046659z
categoryopen-source
json_metadata{"tags":["open-source"],"community":"steempeak","app":"steempeak"}
created2018-12-31 16:00:48
last_update2018-12-31 16:00:48
depth1
children2
last_payout2019-01-07 16:00:48
cashout_time1969-12-31 23:59:59
total_payout_value0.050 HBD
curator_payout_value0.015 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length178
author_reputation2,565,278,576,103,826
root_title"The EU is Giving Out Bug Bounties for Open Source Projects"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id77,669,344
net_rshares119,710,948,208
author_curate_reward""
vote details (3)
@daan ·
Happy NY for you too @tattoodjay!
properties (22)
authordaan
permlinkre-tattoodjay-re-daan-the-eu-is-giving-out-bug-bounties-for-open-source-projects-20181231t162619393z
categoryopen-source
json_metadata{"tags":["open-source"],"users":["tattoodjay"],"app":"steemit/0.1"}
created2018-12-31 16:26:18
last_update2018-12-31 16:26:18
depth2
children1
last_payout2019-01-07 16:26:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length33
author_reputation68,495,317,885,928
root_title"The EU is Giving Out Bug Bounties for Open Source Projects"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd0
post_id77,670,565
net_rshares0
@tattoodjay ·
Thanks Kindly :) 
properties (22)
authortattoodjay
permlinkre-daan-re-tattoodjay-re-daan-the-eu-is-giving-out-bug-bounties-for-open-source-projects-20181231t165546952z
categoryopen-source
json_metadata{"tags":["open-source"],"community":"steempeak","app":"steempeak"}
created2018-12-31 16:56:39
last_update2018-12-31 16:56:39
depth3
children0
last_payout2019-01-07 16:56:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length17
author_reputation2,565,278,576,103,826
root_title"The EU is Giving Out Bug Bounties for Open Source Projects"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id77,672,066
net_rshares0
@thesteemengine ·
Congratulations! This post has been chosen as one of the daily Whistle Stops for The STEEM Engine!

<center>[![](https://ethandsmith.com/wp-content/uploads/2017/12/commentSTEEMengine.jpg)](https://steemit.com/@thesteemengine)</center>

You can see your post's place along the track here: [The Daily Whistle Stops, Issue 358 (01/01/19)](https://steemit.com/curation/@thesteemengine/the-daily-whistle-stops-issue-358-01-01-19)
properties (22)
authorthesteemengine
permlinkre-daan-the-eu-is-giving-out-bug-bounties-for-open-source-projects-20190104t102839117z
categoryopen-source
json_metadata{"tags":["open-source"],"image":["https://ethandsmith.com/wp-content/uploads/2017/12/commentSTEEMengine.jpg"],"links":["https://steemit.com/@thesteemengine","https://steemit.com/curation/@thesteemengine/the-daily-whistle-stops-issue-358-01-01-19"],"app":"steemit/0.1"}
created2019-01-04 10:28:39
last_update2019-01-04 10:28:39
depth1
children0
last_payout2019-01-11 10:28:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length424
author_reputation29,011,027,184,792
root_title"The EU is Giving Out Bug Bounties for Open Source Projects"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id77,855,452
net_rshares0