oss-sec mailing list archives
Re: Closed list
From: Solar Designer <solar () openwall com>
Date: Mon, 4 Apr 2011 17:40:24 +0400
On Mon, Apr 04, 2011 at 02:07:16PM +0200, Nico Golde wrote:
I can understand that you want to keep the list of subscribers low in order to prevent leaks. But from a practical point of view I see really no difference if a mail is passed to a team exploder of a distro by one of the allowed subscribers or directly sent to these members, at least in terms of attack surface/leaking risks.
I was thinking that only a subset of issues discussed on the list will be relevant to a given distro, and only a subset of those will need to be communicated to the distro's entire security team right away. Maybe this is not true for large distros, which package almost all software that Linux distros package at all.
That being said, my key data (I was added as part of Debian): pub 1024D/73647CFF 2003-11-15 Key fingerprint = FF46 E565 5CC1 E2E5 3F69 C739 1D87 E549 7364 7CFF uid Nico Golde <nion () debian org> uid Nico Golde <nico () ngolde de> uid Nico Golde <nion () gmx net> uid Nico Golde <nion () cs tu-berlin de> sub 2048g/F774030E 2003-11-15 or alternatively a stronger key: pub 4096R/A0A0AAAA 2009-06-01 Key fingerprint = E1AB DE0E FFCA AEF3 9494 7592 CD4B 2AF3 A0A0 AAAA uid Nico Golde <nion () debian org> uid Nico Golde <nico () ngolde de> uid Nico Golde <nion () cs tu-berlin de> uid Nico Golde <nion () gmx net> sub 4096R/E89CCA30 2009-06-02
Please suggest a specific e-mail address and key combination. And if you suggest other than your @debian.org address, please suggest a way to verify that the address is really "yours" (the Debian security person's). Thanks, Alexander
Current thread:
- Re: Closed list, (continued)
- Re: Closed list Solar Designer (Apr 06)
- Re: Closed list Miklos Vajna (May 27)
- Re: Closed list Mark J Cox (Apr 03)
- Re: Closed list Solar Designer (Apr 03)
- Re: Closed list Mark J Cox (Apr 04)
- Re: Closed list Marcus Meissner (Apr 04)
- Re: Closed list Marc Deslauriers (Apr 04)
- Re: Closed list Jamie Strandboge (Apr 05)
- Re: Closed list Solar Designer (Apr 05)
- Re: Closed list Solar Designer (Apr 03)
- Re: Closed list Nico Golde (Apr 04)
- Re: Closed list Solar Designer (Apr 04)
- Re: Closed list Nico Golde (Apr 04)
- Re: Closed list Solar Designer (Apr 04)
- Re: Web of trust Yves-Alexis Perez (Apr 04)
- Re: Web of trust Solar Designer (Apr 04)
- Re: Closed list Josh Bressers (Apr 03)
- Re: Closed list Solar Designer (Apr 04)
- Re: Closed list Solar Designer (Apr 04)