Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding episode artwork

EPISODE · May 21, 2024 · 42 MIN

Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

ZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable? Project founder Simon Bennetts and OWASP co-founder Mark Curphey join Chris to examine the uncomfortable economics of widely used open-source security tools. Simon describes the nontechnical work behind maintaining ZAP, from community support to managing companies that build commercial offerings on top of it. Mark explores funding structures, foundations, and the incentives that leave critical infrastructure dependent on too few people. They connect those pressures to the XZ backdoor and ask whether licenses can require commercial users to contribute. The episode makes the sustainability problem concrete: open source may be free to consume, but healthy projects still require money, time, governance, and long-term institutional support.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Mark Curphey and Simon Bennetts:→ Mark Curphey on LinkedIn→ Simon Bennetts on LinkedIn→ ZAP→ The Software Security ProjectMentioned in this episode:→ ZAP→ Linux Foundation→ The Software Security Project→ Crash Override→ OpenSSLFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Sustaining ZAP and open-source security00:35 From OWASP to the Linux Foundation and independence08:48 Balancing CISO priorities with practitioner needs11:42 Fifteen years of maintaining ZAP12:21 The business challenges behind open-source projects18:08 The XZ backdoor as a case study in underfunding20:30 Commercial products built on top of ZAP22:55 What a sustainable funding model could look like27:56 Independent foundation or collaborative community34:38 Can licensing require commercial users to contribute?41:07 Final recommendations for open-source sustainability

Episode metadata supplied by the publisher feed · Published May 21, 2024

Embed this episode

ZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable? Project founder Simon Bennetts and OWASP co-founder Mark Curphey join Chris to examine the uncomfortable economics of widely used open-source security tools. Simon describes the nontechnical work behind maintaining ZAP, from community support to managing companies that build commercial offerings on top of it. Mark explores funding structures, foundations, and the incentives t...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding

0:00 42:32

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 42 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on May 21, 2024.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!