Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20110424123611.GA368@openwall.com>
Date: Sun, 24 Apr 2011 16:36:11 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Closed list

On Fri, Apr 15, 2011 at 05:23:17AM +0000, Zhao, Zhenfeng wrote:
> Now I use my own e-mail address instead of one exploder to apply for the membership, and I also have added Wind River info to the wiki pages. OK,  I was  a vendor-sec member representing Wind River, please add me to the new list.  

Thanks.  Unfortunately, the info you have added puts you in the same
category with MontaVista.  We haven't yet decided on what to do with
"closed" Linux vendors like this.  There has been some opposition to
them receiving advance notifications of security vulnerabilities via the
new list because the community would not be able to tell whether such
vendors are making intended use of the advance notifications or not.

http://oss-security.openwall.org/wiki/vendors#wind-river

"The process for receiving security advisories requires a Support or
Maintenance subscription."

As I wrote in another message, I am considering setting up a separate
list that would include Linux vendors like this.  Then message senders
will be the ones to decide on which categories of vendors to inform.

I consider both the existing new list and any other lists we might setup
experimental.  Everything is subject to change, even the very existence
of these lists.  We're merely trying to see what works best.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.