oss-sec mailing list archives
Re: [OT] FD mailing list died. Time for new one
From: Jann Horn <jann () thejh net>
Date: Wed, 19 Mar 2014 23:06:41 +0100
On Wed, Mar 19, 2014 at 11:29:11PM +0400, gremlin () gremlin ru wrote:
On 19-Mar-2014 09:33:58 -0700, Dean Pierce wrote: > Hosting? That's what the cloud is for. Not for any sensitive data. And vulnerability descriptions are very sensitive...
After they've been made public intentionally?
> I trust Google as a neutral third party more than I would trust > most security researchers. Bwa-ha-ha-ha-ha... Behind that party which you possibly may trust, there's a B.B., which is even worse than a Big Brother - as it's a Big Business. When a Big Business faces something, it asks itself two questions: 0. Could it cause any loss? 1. Could it bring any profit? Suppose someone posts a zero-day vulnerability on the list which affects the BB; do you really think it wouldn't be censored out? No doubt, it will - otherwise that will Cause a Loss, and that's inacceptable for BB.
Have a look at the big picture. If Google censors a vuln in a google-related service on such a list, they will get massive criticism, and for a business, that's even worse. A vuln in a Google service? That's a mistake. Intentional censoring by Google in a place where they're supposed to be a neutral third party? That's evil. And "Google made a stupid mistake" in the headlines is much better for them than "Google did something evil". They won't do it, not just for ethical reasons, but also because censoring is bad for their money.
> They already host all the old newsgroup archives. It's also > free, easily consumable, and most importantly, babysat for > security issues in a way that even a team of skilled volunteers > would have a hard time pulling off. I'd prefer participating on the list hosted by some party which isn't directly affected by list postings - say, some ISP.
<sarcasm>Yeah, because we've never seen an ISP with totally crappy reactions to vuln reports.</sarcasm>
Attachment:
signature.asc
Description: Digital signature
Current thread:
- Re: [OT] FD mailing list died. Time for new one, (continued)
- Re: [OT] FD mailing list died. Time for new one Solar Designer (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Fyodor (Mar 25)
- Re: [OT] FD mailing list died. Time for new one coderman (Mar 25)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Dean Pierce (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Dean Pierce (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 19)
- Re: [OT] FD mailing list died. Time for new one gremlin (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Jann Horn (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 20)
- Re: [OT] FD mailing list died. Time for new one Dean Pierce (Mar 19)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 20)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 20)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 20)
- Re: [OT] FD mailing list died. Time for new one Georgi Guninski (Mar 22)
- Re: [OT] FD mailing list died. Time for new one Solar Designer (Mar 29)