Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S262156AbVAOCoD (ORCPT ); Fri, 14 Jan 2005 21:44:03 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S262160AbVAOCoD (ORCPT ); Fri, 14 Jan 2005 21:44:03 -0500 Received: from fw.osdl.org ([65.172.181.6]:36044 "EHLO mail.osdl.org") by vger.kernel.org with ESMTP id S262156AbVAOCoA (ORCPT ); Fri, 14 Jan 2005 21:44:00 -0500 Date: Fri, 14 Jan 2005 18:43:59 -0800 From: Chris Wright To: Alan Cox Cc: Chris Wright , Florian Weimer , Linux Kernel Mailing List Subject: Re: security contact draft Message-ID: <20050114184359.D469@build.pdx.osdl.net> References: <20050113125503.C469@build.pdx.osdl.net> <87mzvd9f9a.fsf@deneb.enyo.de> <20050113141229.G24171@build.pdx.osdl.net> <1105744352.9838.33.camel@localhost.localdomain> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <1105744352.9838.33.camel@localhost.localdomain>; from alan@lxorguk.ukuu.org.uk on Sat, Jan 15, 2005 at 12:33:14AM +0000 Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1063 Lines: 31 * Alan Cox (alan@lxorguk.ukuu.org.uk) wrote: > On Iau, 2005-01-13 at 22:12, Chris Wright wrote: > > > UNIRAS and probably others require NDAs from affected software vendors > > > before they share vulnerability information. It makes things easier > > > if you state upfront that you won't play such games. > > > > Fair point, I can add that easily. > > Is it worth adding the stipulation up front about who sets release dates > and within what limit as well > Guess it's an open question. Do you agree with these basics bits? - no guarantee - attempt to work with reporter - attempt to work with vendors - goal of timely release - retain final say - within immediate to few weeks Hard to put real time on it. thanks, -chris -- Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/