Re: [stable] Linux 2.6.25.10

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Theodore Tso <tytso@...>
Cc: Linus Torvalds <torvalds@...>, Greg KH <greg@...>, Andrew Morton <akpm@...>, <linux-kernel@...>, <stable@...>
Date: Tuesday, July 15, 2008 - 4:28 pm

Hello!

On 15 Jul 2008 at 14:33, Theodore Tso wrote:


not that new, just not a subscriber, but i've been following it on and
off for many years now. just a few comments below:


he's on security@kernel.org i think.


Linus has just explained that he does *not* have any stand on full
disclosure in fact, he prefers no disclosure.


yes, he does that. what he doesn't do is mention the fact that he's
just fixed a security bug.


Ted, the discussion is *not* about what the best disclosure policy
would be for the kernel. the problem i raised was that there's one
declared policy in Documentation/SecurityBugs (full disclosure) yet
actual actions are completely different and now Linus even admitted
it. the problem arising from such inconsistency is that people relying
on the declared disclosure policy will make bad decisions and potentially
endanger their users. there're two ways out of this sitution: either
follow full disclosure in practice or let the world at large know
that you (well, Linus) don't want to. in either case people will adjust
their security bug handling processes and everyone will be better off.

cheers,
  PaX Team

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Linux 2.6.25.10, Greg KH, (Wed Jul 2, 11:58 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Thu Jul 3, 1:08 pm)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 1:29 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Sat Jul 5, 3:54 am)
Re: Linux 2.6.25.10, Greg KH, (Tue Jul 8, 12:12 am)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 2:57 pm)
Re: Linux 2.6.25.10, , (Thu Jul 3, 3:31 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Mon Jul 14, 8:04 am)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 8:47 pm)
RE: [stable] Linux 2.6.25.10, , (Fri Jul 18, 9:01 pm)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 9:51 pm)
Re: [stable] Linux 2.6.25.10, Willy Tarreau, (Sat Jul 19, 1:41 am)
Re: [stable] Linux 2.6.25.10, , (Mon Jul 14, 10:14 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Mon Jul 14, 10:27 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:15 pm)
Re: [stable] Linux 2.6.25.10, Bernd Eckenfels, (Sat Jul 19, 9:13 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:34 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 11:31 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 2:33 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 4:28 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 6:39 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:09 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 6:47 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:22 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 7:35 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:08 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 7:21 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:26 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:26 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:07 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 3:03 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 3:16 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:13 pm)
Re: [stable] Linux 2.6.25.10, Aidan Thornton, (Thu Jul 17, 5:08 pm)
Re: Linux 2.6.25.10, Greg KH, (Wed Jul 2, 11:58 pm)