Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 19 Feb 2008 20:26:06 +0300
From: Solar Designer <>
Subject: Re: FAQ for upstream maintainers

On Mon, Feb 18, 2008 at 11:57:27AM -0900, Jonathan Smith wrote:
> Since my main goal (I understand if your goals differ, but they
> certainly should not conflict) for this list is to provide a way for
> upstream to coordinate with the vendors, I'm going to start a FAQ or
> tutorial or whatever dedicated to what upstream should do when they get
> a report from a user about a security issue.
> Basic rough draft:
> I'm sure it can use some cleanup... Ideas, submissions, etc welcome!

I've just applied many minor edits to this page, as well as two
important changes:

1. Added the text "... and promptly notify your users of the
availability and importance of this new release."  This will need to be
made more verbose later on - perhaps it deserves its own paragraph (what
communication channels may or should exist, etc.)

2. Replaced the suggestion to "... publish it during the embargo with
no mention of any security-related impact" with a paragraph that allows
such an action if it is absolutely necessary, but discourages it.

> Also quite welcome would be someone with wiki-fu prettying up the page :-)

Well, that does not apply to me, so I've only fixed the mailing lists
link to be an internal one so far.

We could also want to rename this web page to something containing the
likely search keywords - and possibly move it to a namespace, which
would give a keyword too, once we have a suitable one.  "whattodo" is
not a likely keyword (or not a closely relevant one).


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.