Newsgroups: comp.security.unix
From: mil...@picard.med.miami.edu (H. Milton Johnson)
Date: 18 May 1994 16:20:33 GMT
Local: Wed, May 18 1994 12:20 pm
Subject: Re: 8LGM: The Future. Your views please.
In article <KARL.94May18162...@bagpuss.demon.co.uk>,
>We are currently considering what we can do to make our advisories . . . My only suggestion is to avoid posting on Friday, Saturday and -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: k...@bagpuss.demon.co.uk (Karl Strickland)
Date: 18 May 1994 15:21:37 GMT
Local: Wed, May 18 1994 11:21 am
Subject: 8LGM: The Future. Your views please.
We are currently considering what we can do to make our advisories
more acceptable to EVERYONE, rather than just the majority. We welcome all input. If you have mailed me, or 8...@bagpuss.demon.co.uk and made your views known, then your views will be taken into account. If you have posted your views here, they will be taken into account also. Please recognise that it is impossible for us to please everybody. We will not be posting further advisories until this `review' is complete, We are still committed to Full Disclosure. Having said that, this is -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: ceme...@magnus.acs.ohio-state.edu (Charles E Meier)
Date: 18 May 1994 17:52:03 GMT
Local: Wed, May 18 1994 1:52 pm
Subject: Re: 8LGM: The Future. Your views please.
In article <KARL.94May18162...@bagpuss.demon.co.uk>,
My $0.02 Assume you find the security flaw/bug on day zero. On day 1, mail the vendor and CERT an advisory that contains a description On day 3, post the description of the bug and your interim suggested fix. Wait three weeks. This is a long enough time span that most sysadmins should We get full disclosure out of this which I believe does put pressure on the cem You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: c...@fulla.ecmwf.co.uk (Mike Connally)
Date: 19 May 1994 11:02:49 GMT
Local: Thurs, May 19 1994 7:02 am
Subject: Re: 8LGM: The Future. Your views please.
In article <2rdkk3$...@charm.magnus.acs.ohio-state.edu>, ceme...@magnus.acs.ohio-state.edu (Charles E Meier) writes:
[snip] > On day 1, mail the vendor and CERT an advisory that contains a description [snip] |> On day 3, post the description of the bug and your interim suggested fix. [snip] |> Wait three weeks. This is a long enough time span that most sysadmins should |> have received the bug report and had some time to put the interim fix in |> place. Now again post the description of the bug, the suggested fix, AND NOW |> include the exploitation script. The script should be "harmless" [snip] On the face of it, that seems a pretty good plan to me. Exact timings are subject [snip] Building trust and solving problems is Yes! -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: sao...@math.ethz.ch (Karim Saouli)
Date: 19 May 1994 11:45:05 GMT
Local: Thurs, May 19 1994 7:45 am
Subject: Re: 8LGM: The Future. Your views please.
: In article <2rdkk3$...@charm.magnus.acs.ohio-state.edu>, ceme...@magnus.acs.ohio-state.edu (Charles E Meier) writes:
: [snip] : > On day 1, mail the vendor and CERT an advisory that contains a description : [snip] : |> On day 3, post the description of the bug and your interim suggested fix. : [snip] : |> Wait three weeks. This is a long enough time span that most sysadmins should : |> have received the bug report and had some time to put the interim fix in : |> place. Now again post the description of the bug, the suggested fix, AND NOW : |> include the exploitation script. The script should be "harmless" : [snip] : On the face of it, that seems a pretty good plan to me. Exact timings are subject If the bug correction on the security level would be as coherent as most of There are inherantly weak points(networking), but why aren't things like And as I said before a 2 steps operation with a delay of 2 weeks would be Regards, K. Saouli -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: rali@sysguy (Reto Lichtensteiger)
Date: 20 May 1994 17:08:46 GMT
Local: Fri, May 20 1994 1:08 pm
Subject: Re: 8LGM: The Future. Your views please.
Charles E Meier (ceme...@magnus.acs.ohio-state.edu) wrote:
[Big SNIP <g>] I concur with Mr. Meier's sequence. Add one vote in the appropriate -Reto Q: What goes "Pieces of seven! Pieces of seven!"? You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: k...@pondscum.phx.mcd.mot.com (Kevin Johnson)
Date: Sun, 22 May 1994 02:01:03 GMT
Local: Sat, May 21 1994 10:01 pm
Subject: Re: 8LGM: The Future. Your views please.
In article <2rdkk3$...@charm.magnus.acs.ohio-state.edu> ceme...@magnus.acs.ohio-state.edu (Charles E Meier) writes:
> On day 1, mail the vendor and CERT an advisory that contains a description This assumes that all vendors are identifiable. > of the bug, an exploitation script, and whenever possible, an interim > suggested fix. Give them 48 hours to look it over and reply. -- -- #include <std_disclaimer> "Frank Zappa is dead - the world is a duller shade of gray" - me .-------------------------------------------------------------------------- ---. | Kevin Johnson k...@phx.mcd.mot.com | | Information Technologies Network Administrator Motorola MCG | | MCG postmaster, MCG Network Security Administrator | You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: deje...@archimedes.chinalake.navy.mil (Francisco X DeJesus)
Date: Thu, 19 May 1994 18:08:33 GMT
Local: Thurs, May 19 1994 2:08 pm
Subject: Re: 8LGM: The Future. Your views please.
I'd like to add my voice to the "much appreciated, but please not on the
weekends" group. 'Nuff said, You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: f...@CC.MsState.Edu (Frank Peters)
Date: 20 May 1994 14:50:39 -0500
Local: Fri, May 20 1994 3:50 pm
Subject: Re: 8LGM: The Future. Your views please.
Karl Strickland <k...@bagpuss.demon.co.uk> says:
>We are currently considering what we can do to make our advisories My 2 cents worth: >more acceptable to EVERYONE, rather than just the majority. We welcome >all input. Don't post advisories on Fridays or right before common holidays. I'd I don't feel that strongly about separating the fix from the -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
Newsgroups: comp.security.unix
From: czeran...@rz.tu-clausthal.de (Joerg Czeranski)
Date: Tue, 24 May 1994 14:55:24 GMT
Local: Tues, May 24 1994 10:55 am
Subject: Re: 8LGM: The Future. Your views please.
Frank Peters (f...@CC.MsState.Edu) wrote: But don't forget checking with common holidays in Germany. > My 2 cents worth: > Don't post advisories on Fridays or right before common holidays. I'd > actually recommend that you only post in the mornings (to give 8 to 5 > types a chance to get it the same day) and cut off after Thursday > morning but that might seem like overkill to some. And only post at a time that ensures that the posting will reach Germany in the morning. :-) I think it doesn't really matter, _when_ you post; only _what_ you joerg -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
| Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy |
| ©2012 Google |