|
|
Message-ID: <CAKe4=-LAib=qBaW=4yCk0w+4jfd5dErYdCV7w9BO5vuMTm-M4w@mail.gmail.com> Date: Sun, 4 Oct 2026 18:39:13 -0500 From: Jonathan Wright <jonathan@...alinux.org> To: oss-security@...ts.openwall.com Subject: Re: cloud computing provider disclosures A big question that comes up then is where is the line draw? How big must one be to qualify for this? There are tons of smaller-than-AWS/Azure/GCP/OCP but still huge hosting providers out there. On Sun, Oct 4, 2026 at 6:29 PM Jan Schaumann <jschauma@...meister.org> wrote: > Hello, > > I was wondering whether it might make sense to > establish a disclosure list for cloud computing / > virtual private server hosting providers. > > The reason that I think this might make sense is that > not every cloud computing provider necessarily offers > their own OS / Linux distribution, and thus may not be > qualified for membership on distros@. > > At the same time there are vulnerabilities that > directly and significantly impact cloud computing > providers such that the internet would benefit from > them being able to mitigate prior to disclosure on > e.g., oss-security@. > > An obvious example might be disclosure of VM escapes, > which disproportionally impacts such service > providers. > > Another option might be to grant cloud computing > providers membership on distros@ even if they do not > offer their own custom Linux distribution. > > What do people think? > > -Jan > -- Jonathan Wright AlmaLinux OS Foundation Mattermost: chat <https://chat.almalinux.org/almalinux/messages/@jonathan>
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.