Re: distros & linux-distros embargo period and message
format
[Posted February 8, 2012 by jake]
| From: |
| Kurt Seifried <kseifried-H+wXaHxf7aLQT0dZR+AlfA-AT-public.gmane.org> |
| To: |
| oss-security-ZwoEplunGu1jrUoiu81ncdBPR1lH4CV8-AT-public.gmane.org |
| Subject: |
| Re: distros & linux-distros embargo period and message
format |
| Date: |
| Wed, 01 Feb 2012 18:10:50 -0700 |
| Message-ID: |
| <4F29E29A.8050408@redhat.com> |
| Cc: |
| Solar Designer <solar-cxoSlKxDwOJWk0Htik3J/w-AT-public.gmane.org> |
| Archive-link: |
| Article, Thread
|
Also I think it's important to keep in mind a LOT of the Open Source
vendors are staffed by volunteers or people who do this as part of their
day job but not exclusively so. Increasing the burden for security
response on companies with employees is one thing, but on volunteers is
probably going to lead to a serious set of problems and some long term
consequences that are probably MUCH worse for users than a few
potentially security issues that potentially leak early.
--
Kurt Seifried Red Hat Security Response Team (SRT)
(
Log in to post comments)