Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 7 Oct 2014 11:58:50 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Who named shellshock?

On Tue, Oct 07, 2014 at 09:47:28AM +0200, Florian Weimer wrote:
> * Solar Designer:
> 
> > It is insufficient that "it was an honest mistake" and that "apologies
> > were made and accepted."
> 
> Why?

In my opinion, it was important for this community to know whether or
not the information leaked to someone unintended prior to the CRD.  Your
previous messages did not specifically address this question, hence my
insistence on a reply.

> Who determines what is appropriate in such cases, anyway?

Everyone determines for themselves.  I felt I was in a position where
this community would reasonably expect me to ask you this inconvenient
question.  So I did.

> > The article has "Sep 24, 2014 8:35 AM PT" on it, which is 15:35 UTC.
> > Did the article's author receive the information before or after 14:00,
> > and when exactly?
> 
> The author does not work for the news organization in question, and he
> had legitimate and need-to-know access to the information as part of
> his regular employment.  I hope this clarifies things.

Yes, it does.  Thank you!

To summarize, this article does not indicate any leak, given the
clarification you provided.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.