Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 16 Mar 2011 08:36:17 +0000 (GMT)
From: Mark J Cox <mjc@...hat.com>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: RE: Vendor-sec hosting and future of closed lists

> time.  The embargoes in vendor-sec were typically weeks, but I don't recall
> the longest one.  I too favor opening the vendor-sec archives after a while,
> maybe quarterly.

There were some very long embargos when third parties reporting the issues 
to vendor-sec requested delays (due to issues being actually in firmware 
in one case, and due to closed-source vendor co-ordination in another). 
And we did discuss things on the list that were never made public 
(particular ways to test or exploit vulnerabilities).  Also there were 
things reported to us by people that wished to get no credit and remain 
anonymous when the issue was public.

However all those things are exceptions and I'd support us opening the 
archives after a while and making it clear to folks reporting to us to 
expect that to happen.  We'd need to check with common reporters like 
CERT/CC who may not expect their early drafts to become public.

Thanks, Mark
--
Mark J Cox / Red Hat Security Response

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.