OWASP Needs to Evolve
github.com
github.com
The OWASP nonprofit isn’t like the well-funded Linux Foundation; it runs on a shoestring budget made worse by the loss of conference revenue during the pandemic. OWASP charters events, local meetups, training content and OSS projects - the authors of this memo focus only on the OSS project needs. The OWASP board sees itself as community first and foremost; projects should seek their own sponsorships.
Perhaps, indeed, they should not be. Given this response, it sounds to me like the projects should leave. What they need is simply different than what OWASP wants or is financially able to provide. The projects have outgrown the organization, and the organization doesn't see itself as being primarily about the projects. Sounds, to me, like it's time to make a clean break that unburdens OWASP and frees the projects.
I don't especially love either of those projects, but they're arguably the two most important things OWASP works on outside of the conferences. The Top 10 project can't really leave OWASP (ASVS could).
ZAP is the only other project there that I think is all that important to the identity of OWASP itself, but it should just go find its own sponsorship anyways. People like ZAP, but the industry standard is Burp Suite; Burp is Microsoft Office to ZAP's... LibreOffice? Like all the software freedom stuff aside, if you're a professional, you use Word.
> Honestly, if they can get $5-10M from "somewhere else", I say go for it. Then maybe the Foundation resources can be hyper focused on catering to Chapters and Events.
(Sigh. I see that as part of fixing a lot of the obvious unsuitability of https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Sc... some time in the past two years—and it is much better now, though there are still a few dodgy things about it in both content and presentation—they reintroduced the erroneous advice to entity-encode /, which was only finally removed two years ago. Feel free to try to get that fixed, anyone; for my part, I have no interest in trying to work with OWASP.)
Full disclosure: I'm the primary author.
In regards to freely available information about security, are there other resources you can recommend? Something that I find myself constantly being asked is “how should I protect my code” from engineers. I really fail to find much better freely accessible content in one place than the content available on OWASP.
Not that this would help the quality of the content, but maybe ML can help here? I know a lot of very skilled security people who post on various places around the Internet and an ML search engine to help you find relevant security material might be helpful?
At the company I work for, we are building an ML chat bot that would allow you to ask questions about security vulnerabilities and get linked to the relevant material to help you make your own determination about relevancy.
If you have some authoritative curation of the resources it may have promise, but the question becomes, why not have the product of the curation be directly consumable, rather than feed it through an opaque layer?
Inventing problems here, people. It was a nice society while it lasted.
Even if you do have some authoritative curation of resources, it's difficult for dev teams to consume it. And even for those who do understand security, it requires a lot of tedious work to check through. I wish it weren't the case, but the reality is that most teams don't have the specialist skills or the motivation to grind away at this for a significant chunk of their time.
My take about OWASP on HN has generally been: they're effective at producing communication tools that raise the salience of application security, especially within large companies. And that's about it.
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
Do you have any similar group that you do recommend?
This is quite noticeably when you look at the difference between Dependency-Track and DefectDojo. Both are OWASP projects, but one seems to be modern up-to-date software the other looks like straight from the early 2000s.
As a small software vendor, buying other security scanning solutions is very expensive, and they still aren’t as accurate as a pentester investigating our code.
Would it be a good idea if OWASP had a paid service where companies would pay for the verification of OSS libraries (hi NPM!)? and that would innocent you in front of EU’s diligence requirements?
> The Open Worldwide Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software.
If this was a for-profit company, I'd completely agree with you, but it's not.
The cheat sheet series is amazing - a great resource to defer to when you don’t know or want to think about how to do <x>, you just want to look up and implement the industry standard.
It’s a great reference, and I use it lot. <3 to the folks working on that :)
Therefore my recommendation is: use it for general awareness, perhaps, but do not trust it. Because there probably isn’t anyone really working on it—you’re probably actually looking at something that was written well over 10 years ago by an amateur, and has received almost no maintenance since then.