|
Message-ID: <CANO=Ty3=D5hum6sjTJhN4NjuhAH9yjLNDgDdsL3FXSeVwMOVdw@mail.gmail.com> Date: Wed, 25 Nov 2015 10:37:52 -0700 From: Kurt Seifried <kseifried@...hat.com> To: oss-security <oss-security@...ts.openwall.com> Subject: Re: Announcing https://github.com/RedHatProductSecurity/Certificates-Shipped/ On Wed, Nov 25, 2015 at 10:07 AM, Hanno Böck <hanno@...eck.de> wrote: > On Tue, 24 Nov 2015 21:38:35 -0700 > Kurt Seifried <kseifried@...hat.com> wrote: > > > https://github.com/RedHatProductSecurity/Certificates-Shipped/ > > > > The idea is to create a comprehensive list of shipped certs/keys/etc > > by open source vendors/distributions/projects so that: > > That's good, but in this case why limit to open source vendors? > Because this is the Open Source Security mailing list, and I work for a company (Red Hat) that does Open Source and because I have no interest in the hassles of dealing with proprietary software (legal threats/licensing/DMCA/etc.). If you would like to work with proprietary vendors on such an effort I welcome you to try, you can easily setup a project on GitHUB and move ahead without any need to coordinate with the Open Source effort. > > Actually the MS certs are probably the most interesting for > superfish/edell-like scenarios. And I see no reason why they shouldn't > be transparent. > Talk to Microsoft then, OSS-Security is not the forum for dealing with this Microsoft related issue. > > -- > Hanno Böck > http://hboeck.de/ > > mail/jabber: hanno@...eck.de > GPG: BBB51E42 > -- -- Kurt Seifried -- Red Hat -- Product Security -- Cloud PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 Red Hat Product Security contact: secalert@...hat.com
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.