Acknowledgements
The vast majority of OWASP's work is undertaken by volunteers, and the necessary goodwill of their employers and families. OWASP also has a few paid staff which it funds through conferences, training events and some sponsorship. But this money is not generally available to individual projects. OWASP Cornucopia, first created in 2012, is now much more mature, and is supported by time donated by many volunteers. People can download all the files for the game free of charge from the OWASP website, or play online using our Copi platform, or buy individual decks from commercial sources. But we know that handing out printed card decks at talks and other events is the best way to get the word out and drive adoption. Volunteers have had to self-fund printing decks to hand out and we feel this is unfair. We also have costs associated with hosting the Copi game engine. We have therefore developed some sponsorship ideas to provide alternative ways for businesses and other organisations help contribute to our operational and promotional costs. The donation would be made through the OWASP Foundation, but allocated to the OWASP Cornucopia project.
If you would like to give a gift to the OWASP Cornucopia project or be listed as a sponsor on our websites, releases or card decks you can donate here.
Sponsors
Image: Gold Sponsor Missing
We thank our donors for providing the funds to support us on our project activities. If you would like to become a sponsor for our project, please do not hesitate to get in touch with us.
Read more about the benefits of becoming a Gold, Silver, Bronze, or Supporter sponsor here.
OWASP Cornucopia & the OWASP Foundation is very grateful for the support by the individuals and organizations listed. However please note, the OWASP Foundation is strictly vendor neutral and does not endorse any of its supporters. Donations do not influence the content of OWASP Cornucopia in any way.
Volunteers
Cornucopia is developed, maintained, updated and promoted by a worldwide team of volunteers. The contributors to date have been:
- Mayur Agnihotri
- Ayman Algamal
- Artim Banyte
- Simon Bennetts
- Thomas Berson
- Rishii Bharadhwaj
- Jorun Kristin Bremseth
- Mahaboobunnisa Md
- Tom Brennan
- Graham Bryant
- Gerardo Mathías Canedo Prendez
- Fabio Cerullo
- Oana Cornea
- Johanna Curiel
- Todd Dahl
- Ruggero DallAglio
- Andrey Danin
- Luis Enriquez
- Darío De Filippis
- André Ferreira
- Pedro Fortuna
- Ken Ferris
- Norbert Gaspar
- Spyros Gasteratos
- Sebastien Gioria
- Xavier Godard
- Tobias Gondrom
- Timo Goosen
- Anthony Harrison
- Martin Haslinger
- Isha Parmar
- John Herrlin
- Jerry Hoff
- Toby Irvine
- Prajakta Kamble
- Aashish Kharel
- Marios Kourtesis
- Aleksey Krasnov
- Suresh Krishna
- Adarsh Kumar
- Franck Lacosta
- Sebastian Legarraga
- Mathias Lemaire
- Khushal Malhotra
- Antonis Manaras
- Jim Manico
- Jef Meijvis
- Mark Miller
- Muhammad Awais Mohsin
- Cam Morris
- Christoph Niehoff
- Grant Ongers
- Ben Ramirez
- Tanmay Ranjan
- Susana Romaniz
- Ravishankar Sahadevan
- Abhijit Sahoo
- Kéren A. Saint-Hilaire
- Max Alejandro Gómez Sánchez Vergaray
- Tao Sauvage
- Riccardo Sirigu
- Prasun Srivastav
- Aditya Srivastava
- Johan Sydseter
- Elias Brattli Sørensen
- Izar Tarandach
- Mradul Tiwari
- Ive Verstappen
- Sachin Vishwakarma
- Wagner Voltz
- Stephen de Vries
- Colin Watson
- Marysia Winkels
Additionally, Gerardo Canedo and student volunteers to OWASP Threat Dragon from the Universidad Católica del Uruguay (UCU) who took part in a Coding Challenge to provide integration between Cornucopia and Threat Dragon.
Please let us know if we have missed anyone from this list.
Others
Adam Shostack and the Microsoft SDL Team for the Elevation of Privilege (EoP) Threat Modelling Game, published under a Creative Commons Attribution license, as the inspiration for Cornucopia and from which many ideas, especially the game theory, were copied.
Keith Turpin and contributors to the “OWASP Secure Coding Practices Quick Reference Guide”, originally donated to OWASP by Boeing Inc, which is used as the primary source of security requirements information to formulate the content of the Website App Edition cards. David Rook for his "Principles of Secure Development", a proponent for following a small repeatable set of principles during development rather than focusing on vulnerabilities - an approach which inspired Cornucopia's suit names.
Contributors, supporters, sponsors and volunteers to the OWASP ASVS, AppSensor, Web Framework Security Matrix and MASVS/MASTG projects, Mitre’s Common Attack Pattern Enumeration and Classification (CAPEC™), and SAFECode’s “Practical Security Stories and Security Tasks for Agile Development Environments” which are all used in the cross-references provided.
Playgen for providing an illuminating afternoon seminar on task gamification, and tartanmaker.com for the online tool to help create the original card back pattern.
Travelex UK Limited for donating printable files.
Blackfoot UK Limited for creating and donating print-ready design files, and for distributing printed card decks free of charge.
OWASP Foundation for instigating the creation of an OWASP-branded case and foldable leaflet, and for distributing printed card decks free of charge.
OWASP's past and current employees.
Secure Delivery Ltd for developing and donating Copi, the platform to play Cornucopia and EoP online.
dotNET Lab for creating and donating website code and content, and for donating printed card decks.
Colin Watson as author of OWASP Cornucopia Ecommerce Edition, the original card deck.