oss-sec mailing list archives
Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies
From: Alan Coopersmith <alan.coopersmith () oracle com>
Date: Wed, 09 Mar 2016 22:23:16 -0800
On 03/ 9/16 04:22 PM, Carlos Alberto Lopez Perez wrote:
On 06/03/16 19:46, Alan Coopersmith wrote:On 03/ 4/16 04:07 PM, Tim wrote:* No moderation required. Let the public decide if they believe the researcher or vendor. If a moderator does bother to look over the content, they could deduplicate/link issues together and address any confusion, but beyond that, it isn't their job to decide what is a vulnerability and what isn't.If the site displays *any* user-submitted text, you need at least enough moderation to filter out spammers & trolls.I don't think you need that level of moderation if you implement basic measures against spammers like requiring the creation of an account with e-mail verification. Just look to all the public bugzillas out there that allow commenting (mozilla, webkit, redhat, gnome, etc). I don't think they have a problem with spam. But you have to create an account first to do any comment.
I'm one of the admins of the public bugzilla at bugs.freedesktop.org, and I've had to deal with spam there, and I've seen reports of spams in other public bugzillas for open source projects. github requires account creation as well, and I'm sure we've all seen out of control comment threads there that had to be locked down to stop abuse. -- -Alan Coopersmith- alan.coopersmith () oracle com X.Org Security Response Team - xorg-security () lists x org
Current thread:
- Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 04)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Art Manion (Mar 04)
- RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Mike Prosser (Mar 04)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Adam Caudill (Mar 04)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Tim (Mar 04)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Zach W. (Mar 04)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies mark (Mar 05)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Larry Cashdollar (Mar 05)
- RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Mike Prosser (Mar 04)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Alan Coopersmith (Mar 06)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Carlos Alberto Lopez Perez (Mar 09)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Alan Coopersmith (Mar 09)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Carlos Alberto Lopez Perez (Mar 10)
- Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Tim (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Art Manion (Mar 04)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Adam Caudill (Mar 05)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Solar Designer (Mar 05)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Tim (Mar 05)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies me (Mar 06)
- CVE Replacement Via Blockchains (was: Concerns about CVE coverage shrinking - direct impact to researchers/companies) Tim (Mar 07)