euruko2013 / committee

EuRuKo 2013 organising committee repo
6 stars 0 forks source link

OWASP @ EuRuKo #130

Closed fotos closed 11 years ago

fotos commented 11 years ago

2 month ago a close friend of mine from the University of Athens asked me if he could have a small (standalone - standing) banner inside the foyer for OWASP and possible handout a few leaflets. He also organised the latest OWASP event in Athens.

OWASP is a NFP that focuses on software security.

They will cover their costs on their own.

From the website:

The Open Web Application Security Project (OWASP) is a 501(c)(3) worldwide not-for-profit charitable organization focused on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.

I don't know if he is still willing to do this (2 months have passed), but I feel obliged to ask the committee if we are willing to have OWASP put a small banner in EuRuKo.

@apantsiop since you know the sponsorship locations, do we have a bit of space for OWASP?

Everybody else please vote until Wednesday 12/06 14:00 if we want OWASP or not.

fotos commented 11 years ago

And my vote is :+1: for OWASP if their banner is small, we have a place to put them and they cover their costs on their own.

apantsiop commented 11 years ago

The paying sponsors always have priority. But we can always find a spot. As long as they are a non profit org I'm Ok with it.

nikosd commented 11 years ago

I'm neutral to negative on this for the following reasons:

That said I'm not reaaaaally negative but if we are 50-50 and I would rather drop it. If most us are for it I'm totally ok.

fotos commented 11 years ago

@nikosd

You are wrong on this one. They are pretty much into all universes since they talk about software (and web) security practices. It's a well respected organisation abroad by both security professionals and hackers. And it has connection with Ruby and Rails. The [Ruby on Rails security project]((http://www.rorsecurity.info/) was developed in cooperation with OWASP.

It also runs a Google SoC program and has also run joint events with Ruby meetups before like this one.

Have a look at the OWASP members...

Non-profit means nobody is gaining money out of this, just like EuRuKo. And it promotes a good cause, which is application security, a thing that few engineers have in mind when designing web apps (they mostly rely on the frameworks without understanding the implications).

nikosd commented 11 years ago

You make me feel stupid and without knowledge on the subject which is true :D

Thus, I take back my semi-negative vote and keep leave it simply neutral.

P.S.: I would like them to have physical presence on the event and not just a banner (socializing, chit-chat, etc)

fotos commented 11 years ago

I got a reply to the followup / reminder I sent, the gist of which is:

@apantsiop since you know the sponsor's space in the foyer and since you have managed all the sponsorship relationships, what's your take on this? If you are also neutral to negative about this or if you feel it might steal other sponsor's limelight and jeopardise our relationship with them then I can politely decline it and close this issue.

apantsiop commented 11 years ago

1) I think two banners is too much. I would go for 1 roll-up standalone banner. But, they will put their banner after Pamediakopes and Xing have both decided on their space. 2) We don't have some kind of table, but they can put their leaflets on another surface. i.e. HQ, bar etc. We have to ask Marian about this. Or we can put it in the bag. 3) About a gift (I don't consider a leaflet a gift)... I wouldn't go that far. But I'm OK if everybody else feels it's ok. 4) We can offer their free ticket (maybe that qualifies as a sponsorship) in a simple contest (e.g. Twitter: "the first one to... gets a free ticket..." sometime in the event).

The reason I am being flexible on this one is because they are not a company. We can always justify their participation based on this. If they give us the fee ticket you mentioned, then they are technically proper sponsors.

-- Apostolos Pantsiopoulos Software Engineer

On Mon, Jun 10, 2013 at 10:03 PM, Fotos Georgiadis <notifications@github.com

wrote:

I got a reply to the followup / reminder I sent, the gist of which is:

  • They have 2 rollup banners in the standard dimensions (200x80 cm, I guess 200cm is the height otherwise it wouldn't be rollup but rollleft or rollright)
  • They can use (i.e. install) both or one of them
  • They say that, usually, they are being provided a "table" (or something) to put their leaflets on
  • I proposed / asked in the original email (yeah, kinda stupid on my side...) if they have anything to add in the goodies bag (but then I remembered that we have rejected other companies who didn't pay). They replied that don't have time to prepare something and asked if they can add a pencil / notebook combo which is easy to produce and not really costly. I guess I will deny this without any form of sponsorship.
  • I also asked them to support us by buying 1 or 2 supporters tickets (and thus overcome any objections). There might be an issue (according to them) for giving money from a NFP to a NFP. I can ask again about this if we are interested.
  • They asked if we (will) have any kind of contest so they can chime in and offer a free ticket for appsec.eu which will be held in Hamburg this August. The ticket costs around 500 € and that conference is sponsored by HP, Imperva and Barracuda (the appliances company not the fish).

@apantsiop https://github.com/apantsiop since you know the sponsor's space in the foyer and since you have managed all the sponsorship relationships, what's your take on this? If you are also neutral to negative about this or if you feel it might steal other sponsor's limelight and jeopardise our relationship with them then I can politely decline it and close this issue.

— Reply to this email directly or view it on GitHubhttps://github.com/euruko2013/committee/issues/130#issuecomment-19219254 .

pagojo commented 11 years ago

I'll go with whatever @apantsiop decides for this one

damphyr commented 11 years ago

+1 for Pantsi

vvatikiotis commented 11 years ago

same here, my vote to pants

On Tue, Jun 11, 2013 at 12:06 PM, Vassilis Rizopoulos < notifications@github.com> wrote:

+1 for Pantsi

— Reply to this email directly or view it on GitHubhttps://github.com/euruko2013/committee/issues/130#issuecomment-19250125 .

fotos commented 11 years ago

@apantsiop you have 4 votes on your hands. Can you (pretty please) make up your mind so I can reply to the OWASP guy(s)?

So far I'm the only positive, @nikosd is neutral, so was you. Everybody else said whatever you decide (except for @chief but I intuitively know he will also leave his vote to you too :wink:).

chief commented 11 years ago

@fotos u right, my vote to pantsi too :)

apantsiop commented 11 years ago

I thought it was on, since everybody agreed. Go for it, but keep in mind the above restrictions.

-- Apostolos Pantsiopoulos Software Engineer

On Thu, Jun 13, 2013 at 9:13 PM, Giorgos Tsiftsis notifications@github.comwrote:

@fotos https://github.com/fotos u right, my vote to pantsi too :)

— Reply to this email directly or view it on GitHubhttps://github.com/euruko2013/committee/issues/130#issuecomment-19412296 .

fotos commented 11 years ago

I sent an email (committee bcc'ed) inviting OWASP to EuRuKo.

@apantsiop will handle the banner placement and all related things.

fotos commented 11 years ago

For the record, OWASP never showed up. :disappointed: