oss-sec mailing list archives

Re: RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies


From: Alan Coopersmith <alan.coopersmith () oracle com>
Date: Sun, 06 Mar 2016 10:46:54 -0800

On 03/ 4/16 04:07 PM, Tim wrote:
* No moderation required.  Let the public decide if they believe the
   researcher or vendor.  If a moderator does bother to look over the
   content, they could deduplicate/link issues together and address any
   confusion, but beyond that, it isn't their job to decide what is a
   vulnerability and what isn't.

If the site displays *any* user-submitted text, you need at least enough
moderation to filter out spammers & trolls.

--
        -Alan Coopersmith-              alan.coopersmith () oracle com
          X.Org Security Response Team - xorg-security () lists x org


Current thread: