|
|
|
|
|
by PhantomGremlin
3674 days ago
|
|
Since you're referred to in that article as a "security engineer", I'll ask the following: I know nothing of PHP other than its reputation. But apparently ownCloud is written in PHP and JavaScript. And PHP has its own "Security" section in its Wikipedia entry. And it has a reputation for security problems. So, how "secure" (whatever that means) is ownCloud / Nextcloud? Has security been a problem for this software in real life? |
|
There is often the perceiption that ownCloud would be insecure because we have so many advisories. But these are just there because we proactively look for security vulnerabilities and patch them. (see also https://statuscode.ch/2015/09/ownCloud-security-development-...)
Oh! And we also run a bug bounty program for ownCloud and Nextcloud will have one with probably even higher rewards soon! - HackerOne did even do a case study with us so it can't be too bad ;) (https://hackerone.com/resources)