|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] Security policy ambiguities - XSA-108 process post-mortem
Bastian Blank writes ("Security policy ambiguities - XSA-108 process
post-mortem"):
> [snip]
> > List members who are service providers may deploy fixed versions
> > during the embargo, PROVIDED THAT any action taken by the service
> > provider gives no indication (to their users or anyone else) as to
> > the nature of the vulnerability.
>
> Why this constraint to "who are service providers"?
+1
We already have a definition of eligibility for membership of the
pre-disclosure list and therefore I don't think it is necessary or
desirable to further constrain specific privileges to subsets of the
list members.
Cheers,
James
--
James Bulpin
Sr. Director, Technology, XenServer/Networking, Cloud & Service Provider Group
Citrix Systems Inc.
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |