Re: Re: Security e-mail address
| From: | Jani Taskinen | Date: | Sat, 06 Oct 2001 02:28:16 +0000 |
| Subject: | Re: Re: Security e-mail address | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-67399@lists.php.net to get a copy of this message | ||
On Fri, 5 Oct 2001, Rasmus Lerdorf wrote:
>Two issues:
>
>1. A private correspondence channel was requested. You are saying there
> cannot be private communications in open source? Believe me there is
> plenty of private communications going on in all the various open
> source projects and it doesn't make them any less open source. Telling
Ok.
> someone that they are not allowed to communicate with members of the
> PHP development team in a private manner makes no sense. Perhaps we
> need a security@php.net private mailing list for this instead where
> only people with php-dev cvs accounts can subscribe and either not
> archive or at least delay the archiving of messages to the list by
> a couple of weeks.
Excellent idea. This is exactly something we really need.
A private address which is not limited to 10 persons or so.
What did Linus say again..enough eyes and all bugs are..something?
>2. If this is indeed a big security hole we have to treat it in a
> responsible manner. We need to communicate the problem as quickly as
> possible *along with the fix*. It is common practice, bugtraq and
It is two edged sword. If people know there are such holes, they
can protect themselves e.g. with downgrading. Or other measures.
Also if the 'evil' people know about such holes they might exploit them.
> elsewhere, to not publically announce security issues without an
> accompanying fix so that you aren't giving the black hats a big window
> of time to exploit the security hole. That doesn't mean we can just
I would assume that those 'black hats' know about these holes before
anybody else since they are the ones LOOKING for them. Thus they can
and will exploit them for a long time before anybody even suspects
anything.
> not immediately injecting an exploit into every search engine in the
> world.
Also, the other issue are the so called 'script kiddies'..so you're right
in this.
--Jani