Re: [stable] Linux 2.6.25.10

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Theodore Tso
Date: Tuesday, July 15, 2008 - 11:33 am

On Tue, Jul 15, 2008 at 05:31:09PM +0200, pageexec@freemail.hu wrote:

Hi, so I'm guessing you're new to the Linux kernel.  What you are
missing is while *Linus* is unwilling to play the disclosure game,
there are kernel developers (many of whom work for distributions, and
who *do* want some extra time to prepare a package for release to
their customers) who do.  So what Linus has expressed is his personal
opinion, and he is simply is not on any of the various mailing lists
that receive limited-disclosure information, such as the general
vendor-sec@lst.de mailing list, or the security@kernel.org list
mentioned in Documentation/SecurityBugs.

Both vendor-sec and security@kernel.org are not formal organizations,
so they can not sign NDAs, but they will honor non disclosure
requests, and the subscription list for both lists is carefully
controlled.

People like Linus who have a strong, principled stand for Full
Disclosure simply choose not to request to be placed on those mailing
lists.  And if Linus finds out about a security bug, he will fix it
and check it into the public git repository right away.  But he's very
honest in telling you that is what he will do --- so you can choose
whether or not to include him in any disclosures that you might choose
to make.

The arguments about whether or not Full Disclosure is a good idea or
not, and whether or not the "black hat" and "grey hat" and "white hat"
security research firms are unalloyed forces for good, or whether they
have downsides (and some might say very serious downsides) have been
arguments that I have personally witnessed for over two decades
(Speaking as someone who helped to dissect the Robert T. Morris
Internet Worm in 1988, led the Kerberos development team at MIT for
many years, and chaired the IP SEC Working Group for the IETF, I have
more than my fair share of experience).  It is clear that we're not
going settle this debate now, and certainly not on the Linux Kernel
Mailing List.

Suffice it to say, though, that there are people whose views on these
matters span the entire gamut, and I know many reasonable people who
hold very different positions along the entire continuum --- and this
is true both in the Internet community at large, and in the Linux
Kernel development community specifically.

Best regards,

					- Ted
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Linux 2.6.25.10, Greg KH, (Wed Jul 2, 8:58 pm)
Re: Linux 2.6.25.10, Greg KH, (Wed Jul 2, 8:58 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Thu Jul 3, 10:08 am)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 10:29 am)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 11:57 am)
Re: Linux 2.6.25.10, pageexec, (Thu Jul 3, 12:31 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Sat Jul 5, 12:54 am)
Re: Linux 2.6.25.10, Greg KH, (Mon Jul 7, 9:12 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Mon Jul 14, 5:04 am)
Re: [stable] Linux 2.6.25.10, pageexec, (Mon Jul 14, 7:14 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Mon Jul 14, 7:27 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 8:31 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:07 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:13 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 11:33 am)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 12:03 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:16 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 1:15 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 1:28 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 3:39 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 3:47 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:08 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 4:09 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 4:21 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 4:22 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 4:26 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:26 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:34 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 4:35 pm)
Re: [stable] Linux 2.6.25.10, Aidan Thornton, (Thu Jul 17, 2:08 pm)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 5:47 pm)
RE: [stable] Linux 2.6.25.10, david, (Fri Jul 18, 6:01 pm)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 6:51 pm)
Re: [stable] Linux 2.6.25.10, Willy Tarreau, (Fri Jul 18, 10:41 pm)
Re: [stable] Linux 2.6.25.10, Bernd Eckenfels, (Sat Jul 19, 6:13 pm)