oss-sec mailing list archives

Re: Closed list


From: akuster <akuster () mvista com>
Date: Tue, 12 Apr 2011 11:49:38 -1000



On 04/11/2011 09:57 AM, Josh Bressers wrote:
----- Original Message -----

Postponed. I'd like to see any support for you getting onto the Linux
distros security contacts list, with reasoning, or/and any other
suggestions on what to do in this case. Josh - what do you think (as
someone who advocated the setup of a vendor-sec replacement)?


My initial thought is that a vendor without public advisories is a
liability.

Making our Advisories public could put our customers' customers at risk
depending on when we publish and when our customers can get the fixes
into their customers hands and so on down the line.

- Armin


Current thread: