Linux creator Linus Torvalds had a few things to say this week about the way potential security issues are disclosed to fellow open sourcers
Published:
18 January 2005 y., Tuesday
Linux creator Linus Torvalds had a few things to say this week about the way potential security issues are disclosed to fellow open sourcers. And it wasn't all good.
His comments came as part of a mailing list discussion among kernel developers about creating a security contact point for people to use when potential kernel security issues arise.
According to kernel developer Chris Wright,who began the discussion thread, kernel security issues are currently discussed in multiple locations, including the Linux Kernel mailing list, Kernel maintainers and the limited access vendor-sec mailing list. Membership to the vendor-sec mailing list is decided by consensus among existing members, which includes most of the major Linux distributions. In addition, security advisories discussed on the list are embargoed so vendors have time to prepare fixes before full public disclosure.
Torvalds responded that the idea of a central contact point sounded like a good thing to have, as is maintaining limited access. However, he said he is strongly opposed to an embargo on the list for a variety of reasons.
"I'd be very happy with a 'private' list in the sense that people wouldn't feel pressured to fix it that day," Torvalds wrote. "And I think it makes sense to have some policy where we don't necessarily make them public immediately in order to give people the time to discuss them. But it should be very clear that no entity (neither the reporter nor any particular vendor/developer) can require silence, or ask for anything more than 'let's find the right solution.'
Šaltinis:
internetnews.com
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.
The most popular articles
Software company announced new structure_ of it_s business.
more »
According to the council's report, ATM-skimming fraud, which involves illicitly copying ATM card information stored on magnetic stripes, is increasing in Europe.
more »
Building on the success of the recent HP TouchSmart PC for the home, HP today introduced the market’s first all-in-one, touch-enabled desktop PC for businesses.
more »
Microsoft Corp. Chief Executive Officer Steve Ballmer announced the beta availability of the Windows 7 operating system as well as the availability of the latest version of the Windows Live, a suite of personal communications services and applications.
more »
Cash-cycle management, branch optimization, sales/marketing consultation and automation, automated checkout and managed services are expected highlights for January's Wincor World 2009.
more »
We all need to better understand the media we are touched by daily, especially the young, says Austrian Socialist Christa Prets. MEPs backed her report on “media literacy in a digital world” on Tuesday.
more »
Since October, readers of the European Parliament's web pages have had access to RSS, which allows them to keep up-to-date with what is going on via a free subscription.
more »
Fox and Motorola collaboration results in first all-HD programming distribution strategy.
more »
Wincor Nixdorf has won a contract to integrate its cash management solution, consisting of staff-assisted self-service terminals, software and comprehensive services, in the checkout zones and IT operations of Shell Deutschland’s 1,300 service stations.
more »
The role that the internet can play in parliamentary democracy was explored this week when 400 people gathered in Brussels for the annual “e-Parliament conference”.
more »
The EU’s new digital library brings vast treasure trove of historical documents, rare and valuable manuscripts and exquisite cultural artefacts to your desk.
more »