Re: Re: Security e-mail address

From: Date: Sat, 06 Oct 2001 02:28:16 +0000
Subject: Re: Re: Security e-mail address
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-67399@lists.php.net to get a copy of this message
On Fri, 5 Oct 2001, Rasmus Lerdorf wrote: >Two issues: > >1. A private correspondence channel was requested. You are saying there > cannot be private communications in open source? Believe me there is > plenty of private communications going on in all the various open > source projects and it doesn't make them any less open source. Telling Ok. > someone that they are not allowed to communicate with members of the > PHP development team in a private manner makes no sense. Perhaps we > need a security@php.net private mailing list for this instead where > only people with php-dev cvs accounts can subscribe and either not > archive or at least delay the archiving of messages to the list by > a couple of weeks. Excellent idea. This is exactly something we really need. A private address which is not limited to 10 persons or so. What did Linus say again..enough eyes and all bugs are..something? >2. If this is indeed a big security hole we have to treat it in a > responsible manner. We need to communicate the problem as quickly as > possible *along with the fix*. It is common practice, bugtraq and It is two edged sword. If people know there are such holes, they can protect themselves e.g. with downgrading. Or other measures. Also if the 'evil' people know about such holes they might exploit them. > elsewhere, to not publically announce security issues without an > accompanying fix so that you aren't giving the black hats a big window > of time to exploit the security hole. That doesn't mean we can just I would assume that those 'black hats' know about these holes before anybody else since they are the ones LOOKING for them. Thus they can and will exploit them for a long time before anybody even suspects anything. > not immediately injecting an exploit into every search engine in the > world. Also, the other issue are the so called 'script kiddies'..so you're right in this. --Jani

« previous php.dev (#67399) next »