|
Message-ID: <ZS1dzvDl3tfczwoK@itl-email>
Date: Mon, 16 Oct 2023 11:59:08 -0400
From: Demi Marie Obenour <demi@...isiblethingslab.com>
To: Alan Coopersmith <alan.coopersmith@...cle.com>,
oss-security@...ts.openwall.com
Subject: Re: linux-distros membership application of openEuler
On Mon, Oct 16, 2023 at 08:53:57AM -0700, Alan Coopersmith wrote:
> On 10/16/23 08:18, Demi Marie Obenour wrote:
> > The result of this is simply that those who do not have access to
> > lawyers on staff will not participate, which will reduce the value of
> > the list substantially. I suspect that most people who report
> > vulnerabilities via distros@ fall into this category. I know I do.
>
> Perhaps linux-distros is different, but on the wider distros list,
> almost all the mail is from project maintainers providing fixes -
> the researchers generally contact the individual projects directly,
> as those projects aren't on the distros list and can't see or respond
> to reports from researchers sent there.
True, but I don’t know if most project maintainers belong to
organizations with legal teams that they can ask these kinds of
questions to. For those without such access, “you need to ask your
lawyer before posting” is equivalent to “don’t post”.
--
Sincerely,
Demi Marie Obenour (she/her/hers)
Invisible Things Lab
Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.