oss-sec mailing list archives

Re: linux-distros membership application of openEuler


From: Demi Marie Obenour <demi () invisiblethingslab com>
Date: Mon, 16 Oct 2023 11:59:08 -0400

On Mon, Oct 16, 2023 at 08:53:57AM -0700, Alan Coopersmith wrote:
On 10/16/23 08:18, Demi Marie Obenour wrote:
The result of this is simply that those who do not have access to
lawyers on staff will not participate, which will reduce the value of
the list substantially.  I suspect that most people who report
vulnerabilities via distros@ fall into this category.  I know I do.

Perhaps linux-distros is different, but on the wider distros list,
almost all the mail is from project maintainers providing fixes -
the researchers generally contact the individual projects directly,
as those projects aren't on the distros list and can't see or respond
to reports from researchers sent there.

True, but I don’t know if most project maintainers belong to
organizations with legal teams that they can ask these kinds of
questions to.  For those without such access, “you need to ask your
lawyer before posting” is equivalent to “don’t post”.
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)
Invisible Things Lab

Attachment: signature.asc
Description:


Current thread: