oss-sec mailing list archives

Re: Vendor-sec hosting and future of closed lists


From: "S.P.Zeidler" <spz () NetBSD org>
Date: Sat, 5 Mar 2011 21:17:51 +0100

Hi,

Thus wrote Solar Designer (solar () openwall com):

- If yes, would it be an idea to confine or split into lists of focus groups?
  (like Linux vendors, BSD vendors, all OSS source using vendors, etc?)

My current proposal is: split into several sub-lists.  I'd start with
three: Linux vendors, *BSD vendors, security "researchers".  The vendor
groups would be for externally submitted reports (by non-members) and
for cross-vendor discussions.

I'd suggest four, then: Linux (kernel and libc), BSD (kernel and other
items shared between BSDs, but not commonly seen in Linux distributions),
shared/userland (who eg doesn't have OpenSSL?), and researchers
(no opinion on the latter).

best regards,
        spz
-- 
spz () serpens de (S.P.Zeidler) spz () NetBSD org


Current thread: