Date: Thu, 18 Jan 2018 18:02:02 +0100 From: ludo@....org (Ludovic Courtès) To: Florian Weimer <fweimer@...hat.com> Cc: oss-security@...ts.openwall.com Subject: Re: How to deal with reporters who don't want their bugs fixed? Florian Weimer <fweimer@...hat.com> skribis: > Subject says it all: What do you do if you receive a vulnerability > report, and the reporter requests an embargo at some time in the > future because that's when their paper/conference presentation/patent > submission is scheduled? Perhaps you could publicly state upfront that your project will not accept deadlines put forth by the people who report vulnerabilities (other than making sure to coordinate with the relevant parties)? Ludo’.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.