poor social estrategy
Posted Jan 8, 2005 23:05 UTC (Sat) by PaXTeam
In reply to: poor social estrategy
Parent article: grsecurity 2.1.0 and kernel vulnerabilities
Andrea is a kernel hacker, he's not a security contact nor is he the maintainer of the VM (if you know otherwise, show me the proof). and you ditched my original question, so let me ask it again: what is the 'proper procedure' *you* were talking about?
as for DJB: DJB didn't give any time for the authors he notified (well, in case of nasm it was one day, but that was probably the exception, not the rule). contrast that to my 2-3 weeks and several emails to establish contact before going public. pick a better example next time.
to post comments)