This talk is about best practices FOSS projects can use to preempt and respond to vulnerabilities. How security reports are received and how security patches are announced makes a huge impact on overall security. A few precautions and a plan goes a long way to protect end users. For example, every project should have a Security Policy so that researchers know where to report an issue. And a plan for who to notify during coordinated response disclosure will make communication smoother. This talk is for FOSS projects who want to protect their users by taking responsibility of their security.


Mark Esler

Mark Esler

I am an Ubuntu Security member who focuses on security maintenance, auditing software, coordinating vulnerabilities, and working to harden Ubuntu compiler flags.

黃宇強 Date Huang

黃宇強 Date Huang

Date Huang is Solution Architect in VyOS Networks, and also the maintainer of EZIO Project, bare-metal server massive deployment solution.

Speaking Experience: OpenStack Day Taiwan 2016-2017, Open Source Summit North America 2017, ISC High Performance Project Poster 2018, Hong Kong Open Source Conference 2019, OSC Tokyo 2019, COScon '19, TWNOG 4.0, COSCUP 2021, COSCUP 2023, Kubernetes Community Day 2023

分享在 2015-2022之間,在政府內部參與,包括承接乙方專案或者透過內部當工程師進行專案開發的經驗。 相關過去的專案都公開在 https://github.com/digigov/


TonyQ (王景弘)

TonyQ (王景弘)

I'm a professional with a unique blend of software engineering and digital policy experience. In my tech career, I've worked at Authme on digital identity solutions, developed software for TaiwanTaxi, and contributed to projects at QNAP. As a policy researcher, I've served at the Executive Yuan, coordinating national policies across ministries. I've also conducted research at the local government level in New Taipei City and Chiayi County. My diverse background gives me a comprehensive understanding of the digital landscape, allowing me to contribute to effective policy development and implementation at both central and local government levels.

公共程式(public code)是指將政府開發的軟體原始程式碼視為公共財,開放給全民取用,此倡議自 2010 年代在歐洲興起,臺灣亦有自由軟體和開放原始碼社群積極倡議。


用譬喻的方式來說, code.gov.tw 就像一座資訊圖書館,裡面的程式碼就像一本本書,大家可以借用這些書,去閱讀和研究,寫出一本論文,再回饋到圖書館,貢獻給這個世界。這也是公共程式的另一個價值,就是藉由公私協力,達成全民數位韌性。






劉澄真涉略涵蓋服務設計、行銷、公共關係和法律。畢業後曾於科技業擔任過國內外行銷與專案經理。其後進入立法院,協助政府推動社會創新與數位轉型與相關法規鬆綁。 2020-2022年擔任臺南市政府智慧城市辦公室秘書,專注於跨局處數位轉型和沙崙智慧綠能科學城專案管理、整合協調,曾參與疫苗預約、COVID居家照護和社區行動醫院等系統開發。 工作之餘,她以 RR 的名稱走跳於開源社群中,積極參與臺灣零時政府社群,主要關注不實資訊傳播、公私協力等面向,亦在 COVID-19 相關的公民科技專案裡貢獻良多。 劉澄真現為數位發展部系統分析師,主要關注開放原始碼、數位公民參與、公民科技國際交流和資料賦權。

政府單位在進行民間協力時,必須考量許多法規與體制上的限制。如何與使用者達成共識、與建設者建立信任,一直是不好處理的難題。但即便在既有的政策工具下,開源合作似乎仍有可能。我們參考經濟學諾獎得主 Ostrom 的制度分析與發展架構(Institutional Analysis Development, IAD),設計了一套框架,以「用獎助案溝通規格,用採購案納入體制」的方法,試圖解決公共科技建設與資訊採購遇到的痛點。






Frank Hu

Frank Hu

Frank,專注於探索區塊鏈技術如何促進機制設計和社群發展。 現為臺灣分散式自治組織 FAB DAO, g0v-da0 貢獻者、科技議題讀書會 Web3ForAll 參與者、DAO 研究員。參與2023 開拓文教基金會與數位發展部的web3研究與驗證案,協助「DAO治理框架分析規劃書」及「DAO知識傳播暨流程生產鏈規劃書」撰寫。

Frank, who focused on exploring how blockchain technology can enhance mechanism design and community development. Currently, I consider myself a contributor in FAB DAO and g0v-da0, also a participant in the technology reading group Web3ForAll, and works as a DAO researcher. In 2023, I was in the Frontier Foundation's web3 project which collaborated with Ministry of Digital Affairs. I assisted in the writing of the "DAO Governance Framework Analysis" and the "DAO Knowledge Translation, Dissemination and Communication".

Digital Bill of Rights數位權利法案:由下而上一起打造數位自由的法制基礎建設

