Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding

43 min21 maj 2024

Om avsnittet

ZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable? Project founder Simon Bennetts and OWASP co-founder Mark Curphey join Chris to examine the uncomfortable economics of widely used open-source security tools. Simon describes the nontechnical work behind maintaining ZAP, from community support to managing companies that build commercial offerings on top of it. Mark explores funding structures, foundations, and the incentives that leave critical infrastructure dependent on too few people. They connect those pressures to the XZ backdoor and ask whether licenses can require commercial users to contribute. The episode makes the sustainability problem concrete: open source may be free to consume, but healthy projects still require money, time, governance, and long-term institutional support.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Mark Curphey and Simon Bennetts:
Mark Curphey on LinkedIn
Simon Bennetts on LinkedIn
ZAP
The Software Security Project

Mentioned in this episode:
ZAP
Linux Foundation
The Software Security Project
Crash Override
OpenSSL

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Sustaining ZAP and open-source security
00:35 From OWASP to the Linux Foundation and independence
08:48 Balancing CISO priorities with practitioner needs
11:42 Fifteen years of maintaining ZAP
12:21 The business challenges behind open-source projects
18:08 The XZ backdoor as a case study in underfunding
20:30 Commercial products built on top of ZAP
22:55 What a sustainable funding model could look like
27:56 Independent foundation or collaborative community
34:38 Can licensing require commercial users to contribute?
41:07 Final recommendations for open-source sustainability

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.