Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <16735.1203429843@devserv.devel.redhat.com>
Date: Tue, 19 Feb 2008 09:04:03 -0500
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: charter

> 
> Josh Bressers wrote:
> | I just added my current working draft charter:
> | http://oss-security.openwall.org/wiki/mailinglists/oss-security/charter
> 
> Good work, thanks :)
> 
> What do you mean by "Please don't send working vulnerabilities"?

We don't need the heat of people posting vulnerabilities that would allow
one to actually compromise a machine.  Ideally we want testcases the
exercise the flaw, not tools that could be used for malicious purposes.

> 
> I'd append "for non-public issues, please contact vendor-sec" to "Public
> security issues only please"

Done

> 
> "Advisories are welcome"? I thought we decided that this was
> discussion-only?

What do others think?  I can see it either way, so I put it in.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.