Full Disclosure mailing list archives
Re: it's all about timing
From: full-disclosure () lists netsys com (Steven M. Christey)
Date: Thu, 1 Aug 2002 14:33:46 -0400 (EDT)
Georgi Guninski said:
What scares me is that the "Responsible Disclosure" FUD continues. On bugtraq people write that CERT and SecurtyFocus are "established parties" and everyone who does not give them their 0days is irresponsible... I personally won't give them my 0days early.
A number of people thought that the disclosure process draft placed too much of an emphasis on using third parties. That will be weakened to a suggestion in the next version. The Coordinator role, as described in the process draft, does not need to be restricted to parties such as SecurityFocus and CERT/CC. For example, just this year, w00w00 has taken on the Coordinator role in the disclosure of an AIM vulnerability and an IE/Office vulnerability. http://marc.theaimsgroup.com/?l=bugtraq&m=101897994314015&w=2 http://marc.theaimsgroup.com/?l=bugtraq&m=102071080509955&w=2
The "Responsible Disclosure" draft continues to get advertised, though it was not approved by IETF.
A minor clarification: while it was the subject of lively debate on the IETF Security Area Advisory Group (SAAG) mailing list, the SAAG did not think it was appropriate to pursue a document that dealt with procedures as opposed to networking protocols. So, it was not approved because the topic was outside the scope of the IETF. Other organizations have expressed support for developing the responsible disclosure concept (with some changes to the current draft), but they aren't set up for public feedback and/or document ownership like the IETF is. - Steve
Current thread:
- it's all about timing, (continued)
- it's all about timing full-disclosure () lists netsys com (Jul 31)
- Re: it's all about timing Steven M. Christey (Jul 31)
- Re: it's all about timing Georgi Guninski (Aug 01)
- Re: it's all about timing Tom Perrine (Aug 01)
- Re: it's all about timing Georgi Guninski (Aug 01)
- Re: it's all about timing Adam Megacz (Jul 31)
- RE: it's all about timing Scott, Richard (Aug 01)
- Re: it's all about timing Sunil James (Aug 01)
- it's all about timing Timothy J.Miller (Aug 01)
- it's all about timing Alan Rouse (Aug 01)
- it's all about timing Rohny Jotton (Aug 01)
- Re: it's all about timing Steven M. Christey (Aug 01)
- Re: it's all about timing Georgi Guninski (Aug 02)
- Re: it's all about timing Colin Stefani (Aug 01)
- it's all about timing Don (Aug 01)
- it's all about timing Dunbar, Gregory (Aug 01)
- it's all about timing Steven M. Christey (Aug 01)
- it's all about timing Steven M. Christey (Aug 01)
- it's all about timing Kurt Seifried (Aug 02)
- it's all about timing Steven M. Christey (Aug 01)
- it's all about timing Evrim ULU (Aug 02)
- it's all about timing Juliao Duartenn (Aug 02)
- it's all about timing Evrim ULU (Aug 02)
(Thread continues...)