Chapter Democrazy
I am realizing that currently the OWASP chapter organization is not very democratic.
Chapter leaders are not elected. Currently you only have to apply for chapter leadership and without much control you’ll be granted OWASP chapter leadership.
This is not necessarily bad, and I have no knowledge of abuse. I do however know that in some countries there are disagreements on how the OWASP chapter activities are organized. Let me know your thoughts on that (on- or offline)?
Nevertheless, I think it would be better to have an OWASP chapter leader (re)election on a regular base. But how to organize this without creating a administrative hassle?
I have also seen that some countries have OWASP ‘boards’ that organize the chapter meetings. I think this is a good thing, it spreads the workload among different people. If an election was to be organized, board election is also something to think about?
I hope this will become part of How OWASP Works.
I am looking forward to your comments. Because of the increasing amount of blog comment spamming attempts, you will now have to be registered.

February 19th, 2007 at 11:17 am
I figure OWASP could mirror ISSA in terms of policy…
Use the Blog RBL (blbl.org - down right now) or script stuff using the Akismet perl module - http://search.cpan.org/dist/Net-Akismet/
Definitely also install this plugin: http://unknowngenius.com/blog/wordpress/spam-karma/
Also the Bad Behavior plugin - http://www.homelandstupidity.us/software/bad-behavior/
And read this: http://en.wikipedia.org/wiki/Spam_in_blogs
Those few things should cut down on the blog spam. Enabling comments for everyone seems like a pretty good idea to me…
I figured out how to make Wordpress look like MediaWiki, so you’ll have to ask Mike later today and see if he can do it or not…
February 19th, 2007 at 11:24 am
Are comments even working for logged in users? Why not just moderate them? It would be nice if people besides logged in users could post comments, right?
Also check out theseWordpress plugins:
http://unknowngenius.com/blog/wordpress/spam-karma/
http://www.homelandstupidity.us/software/bad-behavior/
And this stuff:
http://search.cpan.org/dist/Net-Akismet/
http://en.wikipedia.org/wiki/Spam_in_blogs
http://blbl.org/ (down right now, maybe the reason you’re getting spam)
To answer your question about Chapters/Boards/etc - we certainly don’t have that problem in Phoenix, but for places that do have a problem you might try mirroring whatever ISSA does since the two are so closely related. Actually, it would be nice if there was a [unwritten?] rule that the OWASP and ISSA chapter leaders cannot be the same people.
Oh hey btw - about the blogs: I am going to send Mike some information on how to make a Wordpress Theme that looks like MediaWiki today. I couldn’t find one that already is… but I’ll keep looking.
Here’s a question for you - how do I get on the main owasp mailing-list (i.e. owasp@owasp.org)?