Past Meetings

OWASP Board Meeting — June 10, 2013

Official minutes of this Board meeting.

Meeting Details

  • Date: Monday, June 10, 2013
  • Time: 1:00 PM EDT – 2:30 PM
  • Location: in person at least once annually at a date to be

Call to Order

Notice of Recording

  • Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.

Time

12:00pm - 1:30pm EST

Location

Teleconference Information: https://www3.gotomeeting.com/join/942894438

International Toll Free Calling Information


Board Meeting Attendance Tracker


Meeting Minutes


Board Members

Directors will be recorded when the meeting is called to order.

Guests

  • Kelly

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

New Business

Minutes

June 2013 - OWASP Global Board Meeting

*THIS MEETING IS RECORDED - Link to recording - https://6e97685ba58960d513fd-9a5cad5a20e11694f60874cbf25347e2.ssl.cf2.rackcdn.com/2013-06-10_Board_Meeting.wmv

ATTENDANCE Board Members Seba Deleersnyder Michael Coates Tom Brennan Jim Manico Eoin Keary Dave Wichers (joined 12:30pm)

Staff: Kelly Samantha Sarah

Other: Jeff Williams Dan Cornell Bil Corry

Executive Director’s Report:

  • Vote requested to update Bylaws: All except Dave voted yes - Dave asked for specific wording for item #2 referring to Section 5.02. I recommend just removing the sentence referring to the Global Chapters Committee
    • Michael - yes to remove
    • Sarah to send out for vote via email
  • Please review report and action items at top of report

OWASP Top 10

  • Statement by Jeff Williams re: openness, owasp sponsorship, project sponsorship, and OWASP Top methodology (see comments emailed by Dave at bottom of document)

  • Jim: openness of top 10, A9

  • Question from Eoin:

    • If there was there an open call for vendors to open their data. if not why? Assuming more data (larger sample space) the better.
    • Was A9 a significant enough statistic to warrant its place in the Top10?
  • Summary of issues [Michael]:

    • Code of Ethics violation or policy violations? No
    • Project branding guidelines - in progress, none currently other than the OWASP organization policies/ethics
    • Should Top 10 wait for release until any guidelines are published or decided? No, recommended that we roll these out for ALL projects starting in 2014
  • Jim (from project handbook)

    • Re: openness, integrity
    • Even if there are not violations, should avoid the “appearance” of violations, which Jim thinks is present
  • No motions for vote

Bylaws Change - drop in person meeting requirement for Board Members

  • Motion by Jim to drop from Bylaws SECTION 3.03: "and shall meet in person at least once annually at a date to be announced and agreed upon" to enable board members to participate entirely remotely in the instance that they are unable to travel or attend in person board meetings at least once annually
  • Tom - not in support of motion, face to face is important to get things done
  • Can we keep the “time requirement” but not the attend in person (could attend via skype, full day)?
  • Eoin- I support this motion. Some members in the future may not be able to travel freely.
  • Seba - Should continue to have one in person meeting, but change wording to “highly encouraged”
  • Modified - SECTION 3.03: "and shall be highly encouraged to meet in person at least once annually at a date to be announced and agreed upon"
    • Jim - Yes
    • Tom - No
    • Seba - Yes
    • Eoin - Yes
    • Michael - Yes
    • Dave - Yes

[Jim] OWASP Board Communication and Transparency - pushed to next meeting

[Tom] Election motion: Change BOD election term to 1 year (annually) and run based on a roll (chair, vice-chair, treasurer, secretary)

  • Seba -Is there a problem now that we are trying to address? What is the reasoning for this?
  • Recommended - clarification on the election process
  • Seba - no
  • Jim- no
  • Tom - yes
  • Michael - no
  • Eoin - no
  • Dave - no
  • Motion fails

End Meeting 1:50pm EST


Jeff Williams statement about the OWASP Top Ten Project

OWASP is, at the core, a project. We’ll be DONE when the world’s application aren’t riddled with known security weaknesses and new code is secure from the start. Let’s keep this in mind as we discuss the Top Ten.

Vendor Independence at OWASP

There are two different ways the term “VENDOR INDEPENDENCE” applies to OWASP, and it’s easy to get them confused.

First, there are IRS rules to ensure that leaders don’t buy from organizations they have an interest in. It should have been obvious to everyone on the Board that this is not the issue here.

But the second part of VENDOR INDEPNDENCE is trickier. OWASP can choose a policy for dealing with vendors in the application security market. This is a business judgment by OWASP. We could choose to stay completely isolated, we could interact at arms-length, or we could have vendors fully participate in everything. From the outset, OWASP has maintained independence, but allowed vendors to sponsor projects and tastefully put logos on project materials.

Under this policy, OWASP grew to the largest, most effective security organization in the world. This policy wasn’t chosen lightly, and I caution you against tinkering with what made OWASP great.

OK, so let’s talk about the OWASP Top Ten Project…

Several folks, including some on the Board, invented the totally unfounded idea that Aspect has a commercial interest in the new A9 risk added to the T10. I want to be REALLY clear on this – we have no commercial interest in A9. The ONLY reason we added it is because it is incredibly important. The risk associated with insecure components is far more widespread than SQL injection, is sometimes more dangerous, and we have no idea how to deal with it – yet. The work for adding A9 started years ago when we added a note about libraries to the insecure configuration risk in the T10 2010.

The only “partnership” Aspect has with Sonatype is that they provided the data on 113 million downloads of components for a study we published. We DO NOT resell each others’ products or services. Aspect’s only interest in insecure components is to help people understand this risk and put in place some tools and processes to deal with it. In fact, Aspect has more of a commercial interest in EVERY SINGLE OTHER item in the T10.

I have spoken at conferences and to the press about A9, Sonatype, and other tools and products focused on this problem. And I intend to KEEP ON talking about important issues in AppSec and telling the truth about products in our market. The press coverage generated by Sonatype about OWASP was EXCELLENT for OWASP, and portrayed us as the leaders and experts in ine field.

The T10 Project Has Done Nothing Unethical –OR- in Violation of Any OWASP Policy…

In fact, the T10 is an example for other projects. It started with two people and now it is so much more. For the T10 2013, we got a bunch of vendors to open their data, followed a published process, created a release candidate, issued it for notice and comment, etc….

By the way, there seems to be some idea that the T10 is unethical if it is not supported by multiple sources of data unrelated to the people on the project. Hogwash. There is no REQUIREMENT for the T10 to use data and be backwards-looking. In my mind, most of the value is in the forward-looking expert-driven aspects. What Neil Smithline has called “subjective.” This kind of decision is a project choice.

It’s the same with putting the Aspect logo in the OWASP T10. Putting a tiny logo with an acknowledgement has always been allowed… and for good reason. Attracting new projects and participants to OWASP is critically important.

If you want to be a great platform, then projects should be able to decide for themselves what makes the most sense – what license to choose, what process to follow, whether to issue a DRAFT release, and whether acknowledging contributors makes sense. If you don’t like logos, then make the business case for why people should participate.

The Board should stay out of project decisions because the POWER OF OWASP and frankly our ONLY CHANCE OF SUCCEEDING comes from being a great platform.

And THAT is the REAL Problem at OWASP…

The platform has become unattractive. Whether it’s a desired policy change or suspected abuse, the process at OWASP is to shoot first and ask questions later.

There are good reasons to debate OWASP policies. But whether you disagree with a policy or there is no clear policy in place, targeting volunteer contributors EX POST FACTO is the wrong way to effect change. Even if someone actually does VIOLATE an EXISTING policy, the approach should be to help them understand the community.

In this case, not only did Board members NOT seek to calm accusations and find out the facts, they piled on with their own accusations and threats of ridiculous lawsuits. The Board has endorsed McCarthyism as a substitute for thoughtful discussion about what helps achieve the mission.

This is the real ABUSE OF OWASP’S BRAND. Whenever anyone is attacked in the name of OWASP, it harms the platform and undermines the mission.

Application Security Is Too Important for this…

OWASP is not moving as fast as the software development community. We are LOSING ground every day. All the knowledge in the OWASP wiki, all the tools, all the everything is basically 2005 stuff.

We need to be recruiting new companies to contribute – we’re still in startup mode. We need tons of new ideas. None of OWASP’s existing ideas are going to have any significant effect. Part of me wants to abandon anything that isn’t a gamechanger.

Does anyone on the call think AT THIS POINT that the OWASP Top Ten is really going to change the way application software is developed? It’s been 10 years and there has been almost no change. Is it really the best we can do?

If you’re frustrated with the way the Top Ten project is being run… go start your own cool project. There is an almost unlimited array of possible cool documents, tools, standards, or projects that you could create to move and inspire people.

You have the power to turn OWASP around – all you have to do is let go.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.