Reporting Kernel Security Issues
Omniscientist writes "A recent post on KernelTrap details the lkml post by Chris Wright talking about a centralized place to report security issues pertaining to the Linux Kernel and the discussion that was generated by it, including Chris's followup. It would appear that they now have created a security team to privately handle the bugs, who act as the alternative to reporting the flaw to the public immediately."
There is something to be said about keeping it private though. It would be ideal if they could keep it private and fix the bug quickly, just because this doesn't work for other companies doesn't mean they can't pull it off.
"A man is but the product of his thoughts what he thinks, he becomes." -Mahatma Gandhi
yeah, my mum is much better as swapping out hard disks than putting in CDs
There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
You got modded down as well for asking this ;-) Often I see posts clearly moderated wrongly, and this is really just a testament of that particularly moderator cluelessness. Too bad metamoderation does not really work.