oss-sec mailing list archives
RE: Vendor-sec hosting and future of closed lists
From: Mark J Cox <mjc () redhat com>
Date: Wed, 16 Mar 2011 08:36:17 +0000 (GMT)
time. The embargoes in vendor-sec were typically weeks, but I don't recall the longest one. I too favor opening the vendor-sec archives after a while, maybe quarterly.
There were some very long embargos when third parties reporting the issues to vendor-sec requested delays (due to issues being actually in firmware in one case, and due to closed-source vendor co-ordination in another). And we did discuss things on the list that were never made public (particular ways to test or exploit vulnerabilities). Also there were things reported to us by people that wished to get no credit and remain anonymous when the issue was public.
However all those things are exceptions and I'd support us opening the archives after a while and making it clear to folks reporting to us to expect that to happen. We'd need to check with common reporters like CERT/CC who may not expect their early drafts to become public.
Thanks, Mark -- Mark J Cox / Red Hat Security Response
Current thread:
- Re: Vendor-sec hosting and future of closed lists, (continued)
- Re: Vendor-sec hosting and future of closed lists Greg KH (Mar 03)
- Re: Vendor-sec hosting and future of closed lists Michael Gilbert (Mar 03)
- Re: Vendor-sec hosting and future of closed lists Greg KH (Mar 03)
- Re: Vendor-sec hosting and future of closed lists Mike O'Connor (Mar 14)
- Re: Vendor-sec hosting and future of closed lists Eugene Teo (Mar 15)
- Re: Vendor-sec hosting and future of closed lists Mike O'Connor (Mar 15)
- RE: Vendor-sec hosting and future of closed lists Menkhus, Mark (GSE Security HP SSRT) (Mar 15)
- Re: Vendor-sec hosting and future of closed lists Eugene Teo (Mar 15)
- RE: Vendor-sec hosting and future of closed lists Menkhus, Mark (GSE Security HP SSRT) (Mar 16)
- Re: Vendor-sec hosting and future of closed lists Eugene Teo (Mar 16)
- RE: Vendor-sec hosting and future of closed lists Mark J Cox (Mar 16)
- Re: Vendor-sec hosting and future of closed lists Mike O'Connor (Mar 16)
- Re: Vendor-sec hosting and future of closed lists Dan Rosenberg (Mar 03)
- Re: Vendor-sec hosting and future of closed lists Greg KH (Mar 03)
- Re: Vendor-sec hosting and future of closed lists Mark J Cox (Mar 04)
- Re: Vendor-sec hosting and future of closed lists David Hicks (Mar 04)
- Re: Vendor-sec hosting and future of closed lists Nelson Elhage (Mar 04)
- Re: Vendor-sec hosting and future of closed lists Steven M. Christey (Mar 04)