|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] Security policy ambiguities - XSA-108 process post-mortem
On 29/10/14 13:27, James Bulpin wrote:
1 and 3 seem like a recipe for disaster as organizations and individual people who have become aware of issues may have legal and other obligations to their users, it would also add a fairly strong incentive for a large operator not to share any issues that they, or a contractor, had found until they had completed a mitigation. Perhaps: 5) Have the security team discuss with the discoverer if fixes should be permitted during the embargo period before the discovery is announced to the list. J. _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |