Minutes
June 2013 - OWASP Global Board Meeting
*THIS MEETING IS RECORDED - Link to recording - https://6e97685ba58960d513fd-9a5cad5a20e11694f60874cbf25347e2.ssl.cf2.rackcdn.com/2013-06-10_Board_Meeting.wmv
ATTENDANCE Board Members Seba Deleersnyder Michael Coates Tom Brennan Jim Manico Eoin Keary Dave Wichers (joined 12:30pm)
Staff: Kelly Samantha Sarah
Other: Jeff Williams Dan Cornell Bil Corry
Executive Director’s Report:
- Vote requested to update Bylaws: All except Dave voted yes - Dave asked for specific wording for item #2 referring to Section 5.02. I recommend just removing the sentence referring to the Global Chapters Committee
- Michael - yes to remove
- Sarah to send out for vote via email
- Please review report and action items at top of report
OWASP Top 10
Statement by Jeff Williams re: openness, owasp sponsorship, project sponsorship, and OWASP Top methodology (see comments emailed by Dave at bottom of document)
Jim: openness of top 10, A9
Question from Eoin:
- If there was there an open call for vendors to open their data. if not why? Assuming more data (larger sample space) the better.
- Was A9 a significant enough statistic to warrant its place in the Top10?
Summary of issues [Michael]:
- Code of Ethics violation or policy violations? No
- Project branding guidelines - in progress, none currently other than the OWASP organization policies/ethics
- Should Top 10 wait for release until any guidelines are published or decided? No, recommended that we roll these out for ALL projects starting in 2014
Jim (from project handbook)
- Re: openness, integrity
- Even if there are not violations, should avoid the “appearance” of violations, which Jim thinks is present
No motions for vote
Bylaws Change - drop in person meeting requirement for Board Members
- Motion by Jim to drop from Bylaws SECTION 3.03: "and shall meet in person at least once annually at a date to be announced and agreed upon" to enable board members to participate entirely remotely in the instance that they are unable to travel or attend in person board meetings at least once annually
- Tom - not in support of motion, face to face is important to get things done
- Can we keep the “time requirement” but not the attend in person (could attend via skype, full day)?
- Eoin- I support this motion. Some members in the future may not be able to travel freely.
- Seba - Should continue to have one in person meeting, but change wording to “highly encouraged”
- Modified - SECTION 3.03: "and shall be highly encouraged to meet in person at least once annually at a date to be announced and agreed upon"
- Jim - Yes
- Tom - No
- Seba - Yes
- Eoin - Yes
- Michael - Yes
- Dave - Yes
[Jim] OWASP Board Communication and Transparency - pushed to next meeting
[Tom] Election motion: Change BOD election term to 1 year (annually) and run based on a roll (chair, vice-chair, treasurer, secretary)
- Seba -Is there a problem now that we are trying to address? What is the reasoning for this?
- Recommended - clarification on the election process
- Seba - no
- Jim- no
- Tom - yes
- Michael - no
- Eoin - no
- Dave - no
- Motion fails
End Meeting 1:50pm EST
Jeff Williams statement about the OWASP Top Ten Project
OWASP is, at the core, a project. We’ll be DONE when the world’s application aren’t riddled with known security weaknesses and new code is secure from the start. Let’s keep this in mind as we discuss the Top Ten.
Vendor Independence at OWASP
There are two different ways the term “VENDOR INDEPENDENCE” applies to OWASP, and it’s easy to get them confused.
First, there are IRS rules to ensure that leaders don’t buy from organizations they have an interest in. It should have been obvious to everyone on the Board that this is not the issue here.
But the second part of VENDOR INDEPNDENCE is trickier. OWASP can choose a policy for dealing with vendors in the application security market. This is a business judgment by OWASP. We could choose to stay completely isolated, we could interact at arms-length, or we could have vendors fully participate in everything. From the outset, OWASP has maintained independence, but allowed vendors to sponsor projects and tastefully put logos on project materials.
Under this policy, OWASP grew to the largest, most effective security organization in the world. This policy wasn’t chosen lightly, and I caution you against tinkering with what made OWASP great.
OK, so let’s talk about the OWASP Top Ten Project…
Several folks, including some on the Board, invented the totally unfounded idea that Aspect has a commercial interest in the new A9 risk added to the T10. I want to be REALLY clear on this – we have no commercial interest in A9. The ONLY reason we added it is because it is incredibly important. The risk associated with insecure components is far more widespread than SQL injection, is sometimes more dangerous, and we have no idea how to deal with it – yet. The work for adding A9 started years ago when we added a note about libraries to the insecure configuration risk in the T10 2010.
The only “partnership” Aspect has with Sonatype is that they provided the data on 113 million downloads of components for a study we published. We DO NOT resell each others’ products or services. Aspect’s only interest in insecure components is to help people understand this risk and put in place some tools and processes to deal with it. In fact, Aspect has more of a commercial interest in EVERY SINGLE OTHER item in the T10.
I have spoken at conferences and to the press about A9, Sonatype, and other tools and products focused on this problem. And I intend to KEEP ON talking about important issues in AppSec and telling the truth about products in our market. The press coverage generated by Sonatype about OWASP was EXCELLENT for OWASP, and portrayed us as the leaders and experts in ine field.
The T10 Project Has Done Nothing Unethical –OR- in Violation of Any OWASP Policy…
In fact, the T10 is an example for other projects. It started with two people and now it is so much more. For the T10 2013, we got a bunch of vendors to open their data, followed a published process, created a release candidate, issued it for notice and comment, etc….
By the way, there seems to be some idea that the T10 is unethical if it is not supported by multiple sources of data unrelated to the people on the project. Hogwash. There is no REQUIREMENT for the T10 to use data and be backwards-looking. In my mind, most of the value is in the forward-looking expert-driven aspects. What Neil Smithline has called “subjective.” This kind of decision is a project choice.
It’s the same with putting the Aspect logo in the OWASP T10. Putting a tiny logo with an acknowledgement has always been allowed… and for good reason. Attracting new projects and participants to OWASP is critically important.
If you want to be a great platform, then projects should be able to decide for themselves what makes the most sense – what license to choose, what process to follow, whether to issue a DRAFT release, and whether acknowledging contributors makes sense. If you don’t like logos, then make the business case for why people should participate.
The Board should stay out of project decisions because the POWER OF OWASP and frankly our ONLY CHANCE OF SUCCEEDING comes from being a great platform.
And THAT is the REAL Problem at OWASP…
The platform has become unattractive. Whether it’s a desired policy change or suspected abuse, the process at OWASP is to shoot first and ask questions later.
There are good reasons to debate OWASP policies. But whether you disagree with a policy or there is no clear policy in place, targeting volunteer contributors EX POST FACTO is the wrong way to effect change. Even if someone actually does VIOLATE an EXISTING policy, the approach should be to help them understand the community.
In this case, not only did Board members NOT seek to calm accusations and find out the facts, they piled on with their own accusations and threats of ridiculous lawsuits. The Board has endorsed McCarthyism as a substitute for thoughtful discussion about what helps achieve the mission.
This is the real ABUSE OF OWASP’S BRAND. Whenever anyone is attacked in the name of OWASP, it harms the platform and undermines the mission.
Application Security Is Too Important for this…
OWASP is not moving as fast as the software development community. We are LOSING ground every day. All the knowledge in the OWASP wiki, all the tools, all the everything is basically 2005 stuff.
We need to be recruiting new companies to contribute – we’re still in startup mode. We need tons of new ideas. None of OWASP’s existing ideas are going to have any significant effect. Part of me wants to abandon anything that isn’t a gamechanger.
Does anyone on the call think AT THIS POINT that the OWASP Top Ten is really going to change the way application software is developed? It’s been 10 years and there has been almost no change. Is it really the best we can do?
If you’re frustrated with the way the Top Ten project is being run… go start your own cool project. There is an almost unlimited array of possible cool documents, tools, standards, or projects that you could create to move and inspire people.
You have the power to turn OWASP around – all you have to do is let go.