Full Disclosure mailing list archives
Re: [RHSA-2002:246-18] Updated Canna packages fix vulnerabilities
From: Mark Cox <mjc () redhat com>
Date: Wed, 11 Dec 2002 04:02:05 -0500 (EST)
Can redhat explain what do they mean by "responsible disclosure"?
It's always been our policy to credit the folks that discover an issue when they give us some advance notice to prepare updates and where we can co-ordinate with them. That practice has recently been labelled "responsible disclosure". I agree that we do need to define what we mean by "responsible disclosure" as this phrase has been used for all sorts of disclosure practices recently. Personally, for example, I wouldn't class the practice of researchers telling people who pay them for some product or service before the issue is public "responsible disclosure" but many seem to. Cheers, Mark -- Mark J Cox / Security Response Team / Red Hat _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- [RHSA-2002:246-18] Updated Canna packages fix vulnerabilities bugzilla (Dec 10)
- Re: [RHSA-2002:246-18] Updated Canna packages fix vulnerabilities Georgi Guninski (Dec 10)
- <Possible follow-ups>
- Re: [RHSA-2002:246-18] Updated Canna packages fix vulnerabilities Mark Cox (Dec 11)