The Case For a Government Bug Bounty Program Slashdotby Soulskill on bug at January 1, 1970, 1:00 am (cached at May 31, 2013, 11:32 pm)

Trailrunner7 writes "Bug bounty programs have been a boon for both researchers and the vendors who sponsor them. From the researcher's perspective, having a lucrative outlet for the work they put in finding vulnerabilities is an obvious win. Many researchers do this work on their own time, outside of their day jobs and with no promise of financial reward. The willingness of vendors such as Google, Facebook, PayPal, Barracuda, Mozilla and others to pay significant amounts of money to researchers who report vulnerabilities to them privately has given researchers both an incentive to find more vulnerabilities and a motivation to not go the full disclosure route. This set of circumstances could be an opportunity for the federal government to step in and create its own separate bug reward program to take up the slack. Certain government agencies already are buying vulnerabilities and exploits for offensive operations. But the opportunity here is for an organization such as US-CERT, a unit of the Department of Homeland Security, to offer reasonably significant rewards for vulnerability information to be used for defensive purposes. There are a large number of software vendors who don't pay for vulnerabilities, and many of them produce applications that are critical to the operation of utilities, financial systems and government networks. DHS has a massive budget–a $39 billion request for fiscal 2014–and a tiny portion of that allocated to buy bugs from researchers could have a significant effect on the security of the nation's networks. Once the government buys the vulnerability information, it could then work with the affected vendors on fixes, mitigations and notifications for customers before details are released."

Read more of this story at Slashdot.



The Case For a Government Bug Bounty Program Slashdotby Soulskill on bug at January 1, 1970, 1:00 am (cached at May 31, 2013, 11:32 pm)

Trailrunner7 writes "Bug bounty programs have been a boon for both researchers and the vendors who sponsor them. From the researcher's perspective, having a lucrative outlet for the work they put in finding vulnerabilities is an obvious win. Many researchers do this work on their own time, outside of their day jobs and with no promise of financial reward. The willingness of vendors such as Google, Facebook, PayPal, Barracuda, Mozilla and others to pay significant amounts of money to researchers who report vulnerabilities to them privately has given researchers both an incentive to find more vulnerabilities and a motivation to not go the full disclosure route. This set of circumstances could be an opportunity for the federal government to step in and create its own separate bug reward program to take up the slack. Certain government agencies already are buying vulnerabilities and exploits for offensive operations. But the opportunity here is for an organization such as US-CERT, a unit of the Department of Homeland Security, to offer reasonably significant rewards for vulnerability information to be used for defensive purposes. There are a large number of software vendors who don't pay for vulnerabilities, and many of them produce applications that are critical to the operation of utilities, financial systems and government networks. DHS has a massive budget–a $39 billion request for fiscal 2014–and a tiny portion of that allocated to buy bugs from researchers could have a significant effect on the security of the nation's networks. Once the government buys the vulnerability information, it could then work with the affected vendors on fixes, mitigations and notifications for customers before details are released."

Read more of this story at Slashdot.



First woman elected to FIFA's executive body AL JAZEERA ENGLISH (AJE)(cached at May 31, 2013, 11:00 pm)

Burundi's Lydia Nsekera elected to serve full four-year term on executive committee of football's world governing body.
Helikoptrar bekämpar stor skogsbrand SvD Inrikes(cached at May 31, 2013, 10:32 pm)

En omfattande skogsbrand rasade i dag i Pajala kommun.
Helikoptrar bekämpar stor skogsbrand SvD Inrikes(cached at May 31, 2013, 10:32 pm)

En omfattande skogsbrand rasade i dag i Pajala kommun.
When Smart Developers Generate Crappy Code Slashdotby Soulskill on programming at January 1, 1970, 1:00 am (cached at May 31, 2013, 10:32 pm)

itwbennett writes "If you've ever worked on a team you can probably recall a time when, as a group, you produced work that was not as good as any one of you could have done on your own. Sarah Mei had this sort of sub-par teamwork experience, which she shared in her session at the O'Reilly Fluent Conference this week. Mei 'spoke about a time she worked on a team with really expert developers. Every one of them was someone whom you'd admire, who had previous written code that you and I would boast to have created. Yet, these smart people created modules that didn't talk to each other. And its quality was, to be kind, on the rotten side.' It's not an uncommon story, but why and how does it happen? The answer, says Mei, is that code quality 'is defined by its patterns of dependencies,' not all of which have equal weight. And, as it turns out, team communication is the heaviest dependency of all."

Read more of this story at Slashdot.



When Smart Developers Generate Crappy Code Slashdotby Soulskill on programming at January 1, 1970, 1:00 am (cached at May 31, 2013, 10:32 pm)

itwbennett writes "If you've ever worked on a team you can probably recall a time when, as a group, you produced work that was not as good as any one of you could have done on your own. Sarah Mei had this sort of sub-par teamwork experience, which she shared in her session at the O'Reilly Fluent Conference this week. Mei 'spoke about a time she worked on a team with really expert developers. Every one of them was someone whom you'd admire, who had previous written code that you and I would boast to have created. Yet, these smart people created modules that didn't talk to each other. And its quality was, to be kind, on the rotten side.' It's not an uncommon story, but why and how does it happen? The answer, says Mei, is that code quality 'is defined by its patterns of dependencies,' not all of which have equal weight. And, as it turns out, team communication is the heaviest dependency of all."

Read more of this story at Slashdot.



Polisanmälan i moderatbråk SvD Inrikes(cached at May 31, 2013, 10:02 pm)

Det är kris inom Moderaterna i Sundsvall.
Polisanmälan i moderatbråk SvD Inrikes(cached at May 31, 2013, 10:02 pm)

Det är kris inom Moderaterna i Sundsvall.
App-Sky-0.0.1 search.cpan.orgby Shlomi Fish at January 1, 1970, 1:00 am (cached at May 31, 2013, 10:01 pm)

wrapper to rsync/etc. to upload files to a remote server and give download links.
Math-Counting-0.1202 search.cpan.orgby Gene Boggs at January 1, 1970, 1:00 am (cached at May 31, 2013, 10:01 pm)

Combinatorial counting operations
JIRA-REST-0.002 search.cpan.orgby Gustavo Leite de Mendonça Chaves at January 1, 1970, 1:00 am (cached at May 31, 2013, 10:01 pm)

A thin wrapper around JIRA's REST API
SVN-Dump-0.06 search.cpan.orgby Philippe Bruhat (BooK) at January 1, 1970, 1:00 am (cached at May 31, 2013, 10:01 pm)

A Perl interface to Subversion dumps
Inline-Python-0.42 search.cpan.orgby Stefan Seifert at January 1, 1970, 1:00 am (cached at May 31, 2013, 10:01 pm)

Write Perl subs and classes in Python.
Git-Hooks-0.042 search.cpan.orgby Gustavo Leite de Mendonça Chaves at January 1, 1970, 1:00 am (cached at May 31, 2013, 10:01 pm)

A framework for implementing Git hooks.