|
Subject: thoughts on kernel security issues Newsgroups: gmane.linux.kernel Date: 2005-01-12 17:48:07 GMT (4 years, 24 weeks, 5 days, 23 hours and 33 minutes ago) This same discussion is taking place in a few forums. Are you opposed to creating a security contact point for the kernel for people to contact with potential security issues? This is standard operating procedure for many projects and complies with RFPolicy. http://www.wiretrip.net/rfp/policy.html Right now most things come in via 1) lkml, 2) maintainers, 3) vendor-sec. It would be nice to have a more centralized place for all of this information to help track it, make sure things don't fall through the cracks, and make sure of timely fix and disclosure. In addition, I think it's worth considering keeping the current stable kernel version moving forward (point releases ala 2.6.x.y) for critical (mostly security) bugs. If nothing else, I can provide a subset of -ac patches that are only that. I volunteer to help with _all_ of the above. It's what I'm here for. Use me, abuse me |
|
|