Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: [RHSA-2002:246-18] Updated Canna packages fix vulnerabilities
From: Mark Cox <mjc () redhat com>
Date: Wed, 11 Dec 2002 04:02:05 -0500 (EST)

Can redhat explain what do they mean by "responsible disclosure"?

It's always been our policy to credit the folks that discover an issue
when they give us some advance notice to prepare updates and where we can
co-ordinate with them.  That practice has recently been labelled
"responsible disclosure".  I agree that we do need to define what we mean
by "responsible disclosure" as this phrase has been used for all sorts of
disclosure practices recently.  Personally, for example, I wouldn't class
the practice of researchers telling people who pay them for some product
or service before the issue is public "responsible disclosure" but many 
seem to.

Cheers, Mark
Mark J Cox / Security Response Team / Red Hat

Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]