Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20110405123037.GA17570@openwall.com>
Date: Tue, 5 Apr 2011 16:30:37 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Closed list

On Tue, Apr 05, 2011 at 07:19:08AM -0400, Josh Bressers wrote:
> Not adding Apple to any coordination list would be plain silly. They were
> far more active than most of the distributions.

Yes.  But why do they need to be aware, say, of glibc vulnerabilities
(ones that are in fact believed to be glibc-specific)?

> I'm starting to worry we've created rules for the sake of rules, which
> almost never has a net positive outcome.

What do you propose?  Go back to a vendor-sec style list, open to
anyone who is approved by other list members, and accept the accusations
of being subjective in who we subscribe?  I can set one up alongside the
Linux distros list... then let the senders decide which list they want.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.