oss-sec mailing list archives
Re: membership request to the closed linux-distros security mailing list
From: Seth Arnold <seth.arnold () canonical com>
Date: Thu, 2 Apr 2015 16:43:57 -0700
On Fri, Mar 20, 2015 at 02:00:29PM +0100, Sona Sarmadi wrote:
On behalf of Enea Software AB, I would like to request membership to the closed linux-distros security mailing list.
Speaking strictly for myself, I'm still somewhat skeptical; the security announce archives http://mail.lists.enea.com/pipermail/security-announce/ do show some security updates, but (guessing) 15% of the actual patch links I tried to follow no longer exist. Furthermore, the advisories all suggest downloading patches via http and offer no mechanism to validate the patches before applying them. Consider this recent advisory: http://mail.lists.enea.com/pipermail/security-announce/20150326/000064.html - there's no gpg signature on this advisory - there's no cryptographic checksums in the advisory to authenticate the patch even if the advisory were signed - there's no ascii-armored signatures in the patches - there's no detached signatures at http://linux.enea.com/5.0-beta-m400/patches/ or at http://linux.enea.com/4.0/patches/ If downloading patches and applying them by hand is really the distribution model Enea has chosen, then it feels like the provenance of updates is seriously lacking. In my opinion, until some more of the security basics are covered, joining linux-distros@ is premature. Thanks
Attachment:
signature.asc
Description: Digital signature
Current thread:
- RE: membership request to the closed linux-distros security mailing list Sona Sarmadi (Apr 02)
- Re: membership request to the closed linux-distros security mailing list Kash Pande (Apr 02)
- <Possible follow-ups>
- Re: membership request to the closed linux-distros security mailing list Seth Arnold (Apr 02)
- Re: membership request to the closed linux-distros security mailing list Daniel Micay (Apr 02)
- RE: membership request to the closed linux-distros security mailing list Sona Sarmadi (Apr 03)
- Re: membership request to the closed linux-distros security mailing list Seth Arnold (Apr 03)
- Re: membership request to the closed linux-distros security mailing list Seth Arnold (Apr 03)
- Re: membership request to the closed linux-distros security mailing list Daniel Micay (Apr 02)