Re: security contact draft

From: Chris Wright
Date: Fri Jan 14 2005 - 21:45:22 EST


* Alan Cox (alan@xxxxxxxxxxxxxxxxxxx) wrote:
> On Iau, 2005-01-13 at 22:12, Chris Wright wrote:
> > > UNIRAS and probably others require NDAs from affected software vendors
> > > before they share vulnerability information. It makes things easier
> > > if you state upfront that you won't play such games.
> >
> > Fair point, I can add that easily.
>
> Is it worth adding the stipulation up front about who sets release dates
> and within what limit as well >

Guess it's an open question. Do you agree with these basics bits?

- no guarantee
- attempt to work with reporter
- attempt to work with vendors
- goal of timely release
- retain final say
- within immediate to few weeks

Hard to put real time on it.

thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/