Google, Amazon, Facebook, and Akamai (off the top of my head) will each pay that without batting an eye; that's $480k/yr. right there. I imagine they could probably get some banks in that club as well.
Also it assumes the OpenSSL team are the first to know about vulnerabilities. Heartbleed has shown that's not always the case.
If I find a vulnerability in code from a project which is pulling this sort of stunt, I will make sure I share details with distributors only under the strict condition that they are not allowed to tell the project about it.
Responsible disclosure usually means "start by telling the authors", because usually the authors know who needs to be contacted and will do that responsibly. If they're just going to sell off exploits to the highest bidders, they should have no role in the disclosure process.
Given how important OpenSSL is to the web's infrastructure (and the many companies who utilize it), I think there would be value in ensuring it has appropriate resources to fulfill that duty. This idea may not be a perfect solution, but calling it a "stunt" is hyperbole, IMO.
In my years as FreeBSD Security Officer, we in very rare cases gave advance notice of vulnerabilities to end users, and those decisions were made on the basis of "we happen to know that these people are using the software in a way which makes them particularly vulnerable". (In most or all such cases we didn't even provide a patch, just a warning of "make sure you have people around at 10AM tomorrow in case you need to release an update quickly".)
Nobody ever got advance notice by virtue of having donated money, and I reminded Security Team members that they should not give any advance disclosure to their employers.
Yes it is. If you disclose early to a select group, you are by definition delaying details to everyone else.
The paid early disclosure stuff used to exist all over the place, and it was a joke in terms of it being immediately leaked to those in the know.
What would you say if this was worded more like Patrick's "priority support" clause in his analysis of Tarsnap?Practically it would just mean they send an email to the priority support list before they send it to the listserv. I still think major enterprises would get on board.
Mail servers are fast enough these days that I don't think that it really matters what order the emails go out in. Maybe someone would want to pay to get a phone call when an advisory goes out, though.
I have no objection to providing support for paying customers, e.g., to help them figure out if they're affected by a bug. But money should not result in you hearing about a bug any earlier.
2. Wait for next vulnerability
3. Immediately sell details to hackers via bitcoin
4. ???
5. PROFIT
Unless critical vulnerability is exploited in the wild, it should first be disclosed to big Linux distributors so they can prepare patches and to companies responsible for critical Internet infrastructure so they can fix their system before telling general public. With this proposal you just charge companies who can afford it membership fees and provide this service for free to open source/non profits who could not afford it.
The goal is to give businesses who are already in the early-warning club an excuse to write $10k checks every month. The intention was not to solicit anyone and everyone.
It would continue to only be offered to organizations who are (in the collective opinions of the OpenSSL project leaders) going to neither leak nor use the vulnerability -- exactly what happens today.
They would be allowed to (and, I'd hope, would) waive the fee if a major stakeholder were obstinate about it, because (I hope) they actually care about the security of the Internet.
I don't know a lot about large companies, but I do know a little about getting small companies to give you money. Small companies are cheap, but there are a lot of us, and if you only need $800K, well, that is 800 companies donating a grand a year each. There are many thousands of small technical businesses who can afford a grand a year.
So. First problem, for a small company? You need to give us something to buy. This helps out tax-wise, and it also makes the deal feel better. Hell, you can call OpenSSL a for-profit at that point, which means little paperwork for you, and if you pay out everything you get as salary, you have to pay the same payroll taxes on that either way anyhow, if I am not mistaken.
So, what can the OpenSSL people sell me without causing a conflict of interest? How about advertising? maybe give me a website badge. "OpenSSL sponsor" maybe with a silver/gold/bronze or something (or maybe even just the amount) - Also put me on the sponsors list on the OpenSSL website with a link to my website and maybe my tagline or a logo at the more expensive levels.
I'll take the grand out of my advertising budget and it's all above-board tax wise for me, and the paperwork is easy. I've bought advertising before.
It's a lack of,
>I'll call up and close 800 businesses for you and keep track of invoicing them. As well as do product management on getting something together that is something they can support. I don't need any resources.
And for invoicing at this scale, use cashflow accounting. The sale closes when you receive payment. There will be some work matching up checks to logos, but at $1000 a pop, the 5% of customers who don't write the account identifier on the check are worth tracking down.
You do need to do accounting, but you need to do accounting at the current $2000/year level, too. I don't think they are committing themselves to all that much extra work if they only get a few buyers.
I have... intimate experience with the "I got too many customers before I had sufficient automation" problem... and yeah, it is a problem when you have $50/yr customers. It is not a problem, I think, when your smallest customers are $1000/yr.
You'd either want to talk to some senior in IT security or anyone above them, upto including the CTO or someone in risk management/liability. Doing sales to those people is most likely expensive, probably costing $10k+ per client which would be the cost of someone going to networking events, visiting prospects, presentations, documents etc.
In my experience paying yearly is much preferred to paying monthly in large orgs. due to the process that has to be gone through to purchase something (Longer than a year can cause budgeting problems).
This is why I'm suggesting something that can be sold online, at a price point that doesn't require per-customer sales effort. I don't have many $1000 per year customers, but I have a few; and I have a fair number of $500+ per year customers. I did not spend more sales effort on those customers than I did on my $100/year customers.
I say this as evidence that $1000/year is below the "high touch sales" threshold.
Selling something online, could work but the question is what do they get for their money? a t-shirt, name on website etc. Though in a world of kickstarter it could work if done right. This is a $50/yr deal for most which is 20k people to get to that same $100k with a lot more community work to keep up with those people.
$1000, from experience, is below the level where you need per-user sales.
>Selling something online, could work but the question is what do they get for their money? a t-shirt, name on website etc. Though in a world of kickstarter it could work if done right. This is a $50/yr deal for most which is 20k people to get to that same $100k with a lot more community work to keep up with those people.
http://www.netbsd.org/donations
http://www.openbsd.org/donations.html
https://www.freebsdfoundation.org/donate/sponsors
http://mirrors.centos.org/sponsors/
I would suggest that for corporate sponsors, you make it more clear than Theo does that you are buying advertising, not donating money. I think selling a "I helped pay for software you use" website badge is a good way of doing that... but look at the mirrors.centos.org sponsors page. You are very clearly buying advertising space, in that case.
Heck, the CAs charge a lot of money for badges that mean nothing; The OpenSSL people could create a similar badge. "OpenSSL developer club auxiliary" or something.
2) They need to coordinate with fortune 1000 companies to get their company listed as a United Way alternative.
3) They need to campaign the nerds in the tech community whose companies do United Way donations and ask that their donations are directed to the OpenSSL foundation.
This solves 2 problems: 1 is the immediate need for cash, and 2 is a reliable cash flow. We donate monthly. I currently give to a cancer non profit and a local hacker space. I would move my donations away from the hacker space for the foreseeable future of the OpenSSL guys did this.
Then it still doesn't guarantee they'll increase donations without marketing so people know about it. Until Heartbleed became public, I imagine few companies were aware that OpenSSL had so few resources and such great needs. They definitely need to capitalize and hope the bad press doesn't make large companies seek an alternative.
Virtus raised 1000 Euros in a month. https://www.bountysource.com/fundraisers/329-virtus-1-0-0
While the lib is an interesting one, it is a fringe library in a fringe space (Ruby). Still, it made half of what openssl made in a year in a month.
RVM, one of the Ruby version switchers/installers, raised 50k to fund the main developer a year of work on it:
https://www.bountysource.com/fundraisers/489-rvm-2-0
Thats already 1/16th of your number.
Now, OpenSSL is _far more important_ than both of these but still doesn't manage to get funds? Sounds more like they just hope people to come because they want to.
[1] http://mashable.com/2014/04/09/heartbleed-bug-websites-affec...
Or, as it seems, about $2k.
Lots of corporate IT people can get away paying $300 for a cert and know $200 of that is going to a good cause.
It's not for the IT employee to effectively give away the companies money by buying something for more than they have to spend.
The decision to donate to a good cause is usually made by other people in the company.
By that logic, the tax accountant could argue that they should arrange a company's finances so they pay more tax, in order to pay for more "stability" by funding the government.
In this case, I think it's safe to assume that a $200 contribution to OpenSSL won't repay the contributing company $200 of improvements.
Paypal fees!? :) donates to foundation.
1) Simple redesign of home page,
2) Showing prominent sponsors who've paid more than some amount in the last 12 months (e.g. Google, Redhat, Akamai),
3) And leading contributors
4) And news other than vulnerabilities (e.g. code fixes, new tests, etc.)
It might not net $800,000 per year, but it would probably help.
Sending donors one of either: a) a short story b) a picture drawn in crayon