oss-sec mailing list archives
Re: cloud computing provider disclosures
From: Jeremy Stanley <fungi () yuggoth org>
Date: Mon, 5 Oct 2026 14:17:39 +0000
On 2026-10-04 21:45:06 -0400 (-0400), Aaron Rainbolt wrote: [...]
If cloud providers can't update with near-zero notice, they arguably shouldn't be providing cloud services.
[...]While this is true to some extent, getting early access to fixes helps reduce the window between public disclosure and risk mitigation by allowing their operators to schedule this work to coincide with a coordinated advisory publication. Also I've lost count of the number of times a public cloud operator has spotted a logic or testing gap in the pre-advisory copies of fixes which were missed by the developers in review (reviewing and testing fixes in secret under embargo is notoriously challenging for open source developer communities used to working completely in the open under normal circumstances).
The "early access to security vuln details" group should be as tiny as possible to reduce the chances of anyone malicious being in the early access list.
[...]Yes, for the open source cloud platform I'm involved in, I help coordinate and vet a list of known downstream operator contacts for (brief) advance notice of upcoming coordinated advisory publications under embargo. While we do also notify the private linux-distros list (because a majority of them package at least some of our software), I don't think we'd send advance notice to a list of cloud operators where we don't even know if they're running our software at all.
-- Jeremy Stanley
Attachment:
signature.asc
Description:
Current thread:
- cloud computing provider disclosures Jan Schaumann (Oct 04)
- Re: cloud computing provider disclosures Jonathan Wright (Oct 04)
- Re: cloud computing provider disclosures Demi Marie Obenour (Oct 04)
- Re: cloud computing provider disclosures Jan Schaumann (Oct 05)
- Re: cloud computing provider disclosures Aaron Rainbolt (Oct 04)
- Re: cloud computing provider disclosures Katie (Oct 04)
- Re: cloud computing provider disclosures Jeremy Stanley (Oct 05)
