|
Message-Id: <20110403201111.06034772.michael.s.gilbert@gmail.com> Date: Sun, 3 Apr 2011 20:11:11 -0400 From: Michael Gilbert <michael.s.gilbert@...il.com> To: oss-security@...ts.openwall.com Subject: Re: Closed list Dan Rosenberg wrote: > On Sun, Apr 3, 2011 at 6:58 PM, Benji wrote: > > This is pathetic. You've all just made your personal and 'work' email > > addresses targets by having a ridiculous public 'signup' system, and > > the fact you all feel the need to hide behind some sort of veil for > > security issues. > > > > > > Do you really think anyone is gaining new information by discovering > that, say, a member of the security team for a major distro will be on > this mailing list? Such information seems pretty obvious to me. Benji's trolling does raise a couple real issues. The private keys and passphrases of those responding here have now become highly lucrative targets for attackers. Hence, everyone on this new list needs to use good practices to keep their keys, hard drives, and computers safe. There should probably be some common guidelines for key safety for all participants. A private period is rather unfortunate, and hopefully it hasn't been and isn't being used as a veil. I for one am for full transparency (especially given Mark Cox's statistic that vendor-sec was only relevant for 29 out of over 700 open source issues last year). However, I recognize that there seems to be a need for some private coordination at present. Perhaps all discussions should be published in the open something like 2 months after the initial posting? That would be a kind of maximum private coordination period. Best wishes, Mike
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.