Web Images Videos Maps News Shopping Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Security disclosure - let's resolve this
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  9 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Jonas Sicking  
View profile  
 More options May 25 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: "Jonas Sicking" <sick...@bigfoot.com>
Date: 2000/05/25
Subject: Re: Security disclosure - let's resolve this
I think we should have a "security group". If anyone is interested in
"cracking" mozilla then he/she will probobly think it is worth the effort to
get "can-confirm" access.

/ Jonas Sicking

"Mitch Stoltz" <msto...@netscape.com> wrote in message

news:392C5C00.924DACAB@netscape.com...


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Ben Bucksch  
View profile  
 More options May 25 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: Ben Bucksch <mozilla.n...@bucksch.org>
Date: 2000/05/25
Subject: Re: Security disclosure - let's resolve this
Sorry for pending my followup for so long. So, I'll just dump my ideas
with some keywords. Maybe this is less emotional than my original
followup.

- I really think, we should completely open all bugs to everybody. See
<http://www.tuxedo.org/~esr/writings/cathedral-bazaar/cathedral-bazaar...,
Claim 8 (quoted on <http://www.mozilla.org/quality/>). Vendors have to
find a way to distribute fixes fast.
- IF you won't open all bugs to everybody, at the very least open them
completely to developers with CVS write access. (I don't know, if this
is a subset to the can-can-commit-bugs group.)
- Please also consider the developers and testers, of which we have
nearly 500.000 now. I'm supposed to eat dogfood, but I won't give up my
security and privacy for Mozilla development. I must at least know about
sec. bugs, so I can adjust my usage.

--
<http://www.bucksch.org>


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Ben Bucksch  
View profile  
 More options May 25 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: Ben Bucksch <mozilla.n...@bucksch.org>
Date: 2000/05/25
Subject: Re: Security disclosure - let's resolve this

Ben Bucksch wrote:
> - I really think, we should completely open all bugs to everybody.

After talking with some Linux guys, I don't think, that's reasonable.
Let me adjust my proposal:

- Completely open bugs as soon as they are fixed
- If a bug can't be fixed within reasonable time (say, 1 or 2 weeks),
disclose it to everybody


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jesse Ruderman  
View profile  
 More options May 25 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: "Jesse Ruderman" <davi...@home.com>
Date: 2000/05/25
Subject: Re: Security disclosure - let's resolve this

> - If a bug can't be fixed within reasonable time (say, 1 or 2 weeks),
> disclose it to everybody

it would be useful to have a "reason for restriction" field that everyone
can see.

"browser security hole reported 5/25, will open bug and hopefully fix by
6/1"


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jesse Ruderman  
View profile  
 More options May 25 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: "Jesse Ruderman" <davi...@home.com>
Date: 2000/05/25
Subject: Re: Security disclosure - let's resolve this

> - Completely open bugs as soon as they are fixed

does that mean "set groupset=0 on fixed bugs"?  "post the bug on the
mozilla.org front page and spam all the users, telling them to upgrade"?
something in between?

by the way, this whole debate is pointless until bugzilla's security is
patched up.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Daniel Veditz  
View profile  
 More options May 25 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: Daniel Veditz <dved...@netscape.com>
Date: 2000/05/25
Subject: Re: Security disclosure - let's resolve this

Jesse Ruderman wrote:

> > - If a bug can't be fixed within reasonable time (say, 1 or 2 weeks),
> > disclose it to everybody

> it would be useful to have a "reason for restriction" field that everyone
> can see.

> "browser security hole reported 5/25, will open bug and hopefully fix by
> 6/1"

Good idea. I would recommend a keyword ("security", "exploit"?) to flag
these and using the "Status Whiteboard" field for the other information.
The whiteboard field already exists for this sort of purpose.

The reason for the keyword is so we can search for these bugs once they've
been marked unprivate. While they're private you can search on the Group ID,
but after they'd just meld into the morass of bugs. We can't rely on the
"Security" **component** because I've seen security bugs marked under the
component in which the bug exists. For example, some of the "unsafe skin"
bugs are assigned to Hyatt and given a XPToolkit (whatever it is) component.

-Dan Veditz


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Dan Mosedale  
View profile  
 More options May 25 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: dm...@mozilla.org (Dan Mosedale)
Date: 2000/05/25
Subject: Re: Security disclosure - let's resolve this

"Jesse Ruderman" <davi...@home.com> writes:

> by the way, this whole debate is pointless until bugzilla's security is
> patched up.

Ummm, what?

Dan

--


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mitch Stoltz  
View profile  
 More options May 25 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: Mitch Stoltz <msto...@netscape.com>
Date: 2000/05/25
Subject: Re: Security disclosure - let's resolve this
Jonas,
   I want to be clear about this. People who are determined to crack mozilla
will succeed whether they can see the bug reports or not. No policy on bug
disclosure will stop a determined attacker, especially not when the Mozilla
source is available to all anyway. We are trying to stop casual troublemakers
from using bug reports to take advantage of security holes. That's all we can
reasonably do. That said, I am in favor of the security group plan. Just not
for the reason you give here.
     -Mitch


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jonas Sicking  
View profile  
 More options May 26 2000, 3:00 am
Newsgroups: netscape.public.mozilla.security
From: "Jonas Sicking" <sick...@bigfoot.com>
Date: 2000/05/26
Subject: Re: Security disclosure - let's resolve this
One issue is, how casual should you be able to be. I agree that if someone
is determined enough then there is no way of stoping him/her. But the higer
the security the more people we keep off.

Just out of curiosity, if this is not the reason you want a security group,
what is?

/ Jonas Sicking

"Mitch Stoltz" <msto...@netscape.com> wrote in message

news:392DC8CD.CC457C84@netscape.com...


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google