|
|
Message-ID: <SYBPR01MB6336B704782A9B3ED105B1ECEED72@SYBPR01MB6336.ausprd01.prod.outlook.com> Date: Sat, 1 Aug 2026 02:14:36 +0000 From: Peter Gutmann <pgut001@...auckland.ac.nz> To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com> Subject: Re: Some Changes to GNOME Security Tracking Jeremy Stanley writes: >Now the vast majority of bug reports we receive are from disconnected >"researchers" looking to make a name for themselves, pad their resumés/CVs, >or promote their LLM-oriented code auditing services. Bit of an aside, I've been working on a presentation "The Cost of Stunt Cryptography" that looks at the real-world cost to open-source project maintainers of stunt cryptography / CVEnhancement "vulnerabilities" that present no practical attack or weakness but can result in months of remediation work and thousands to tens of thousands of dollars in costs to projects with a lot of downstreams. I've got several examples already but if anyone has any particularly egregious examples with accompanying data (time spent, cost) that they'd like to share I'm always looking for more. Peter.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.