[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] Security policy ambiguities - XSA-108 process post-mortem
Bastian Blank writes ("Security policy ambiguities - XSA-108 process post-mortem"): > [snip] > > List members who are service providers may deploy fixed versions > > during the embargo, PROVIDED THAT any action taken by the service > > provider gives no indication (to their users or anyone else) as to > > the nature of the vulnerability. > > Why this constraint to "who are service providers"? +1 We already have a definition of eligibility for membership of the pre-disclosure list and therefore I don't think it is necessary or desirable to further constrain specific privileges to subsets of the list members. Cheers, James -- James Bulpin Sr. Director, Technology, XenServer/Networking, Cloud & Service Provider Group Citrix Systems Inc. _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |