
oss-sec mailing list archives
Re: Thoughts about security of Linux distributor collaboration platforms, bugtrackers for opensource software
From: Hanno Böck <hanno () hboeck de>
Date: Sat, 13 Feb 2016 14:15:13 +0100
On Sat, 13 Feb 2016 05:52:44 +0000 halfdog <me () halfdog net> wrote:
Hence really critical security material perhaps should not go to such platforms, e.g. Ubuntu Launchpad, or the platform should be modified to send security issues only in encrypted mails without talkative title, members without mail public key registered should get only message "Bug [Number]: Info changed" including the HTTPS link to the issue in the platform.
This is roughly what mozilla does and I like it a lot. They have a bug tracker over https and you can add a PGP key. If you don't add a PGP key and report a security bug you won't get updates via mail unencrypted. I think this is definitely an area that could need improvement. A lot of projects don't have any reasonable way to securely report bugs. And some actively discourage reporting bgus in a secure way (apache has some note on their webpage that you may send your reports encrypted to some people, but have to expect longer delays if you do so instead of using the "normal" unencrypted way). One problem is also that e.g. the github bugtracker (and I think many other bugtrackers as well) doesn't consider sensitive bug reports. But I also agree with Florian: Part of the problem can be mitigated by not keeping things under the hood for too long. I'm often disappointed with slow reaction times. -- Hanno Böck https://hboeck.de/ mail/jabber: hanno () hboeck de GPG: BBB51E42
Attachment:
_bin
Description: OpenPGP digital signature
Current thread:
- Thoughts about security of Linux distributor collaboration platforms, bugtrackers for opensource software halfdog (Feb 12)
- Re: Thoughts about security of Linux distributor collaboration platforms, bugtrackers for opensource software Scotty Bauer (Feb 12)
- Re: Thoughts about security of Linux distributor collaboration platforms, bugtrackers for opensource software Hanno Böck (Feb 13)
- Re: Thoughts about security of Linux distributor collaboration platforms, bugtrackers for opensource software Kristian Fiskerstrand (Feb 13)