Misplaced Pages

vendor-sec

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.
This article is an orphan, as no other articles link to it. Please introduce links to this page from related articles; try the Find link tool for suggestions. (September 2024)


vendor-sec was an electronic mailing list dedicated to distributors of operating systems using (but not necessarily solely) free and open-source software. The list was used to discuss potential distribution element (kernel, libraries, applications) security vulnerabilities, as well as to co-ordinate the release of security updates by members.

As of March 2011, after a security compromise, vendor-sec is no longer in use. Possible alternatives to it are being considered.

Members of the list included representatives from various Linux distributions, as well as a number of BSD distributions. The list did not make a distinction between commercial and non-commercial vendors.

The mailing list was unmoderated, but requests for membership were manually vetted to ensure that only the target audience could join. This was done to avoid leaking the potentially sensitive discussions, as vendor-sec members had access to information about vulnerabilities before they become public. Vendor-sec practices responsible disclosure.

As part of the conditions of use, information discovered through vendor-sec could not be disclosed ahead of time by vendors. The balance between the time it takes to analyse an issue versus the required confidentiality has been described as "delicate" and can cause frustration ("Going to vendor-sec ... creates inexcusable delays, you to confidentiality.")

References

  1. "vendor-sec mailing list".
  2. "Red Hat Magazine: "Risk report: Three years of Red Hat Enterprise Linux 4"".
  3. "Vendor-sec hosting and future of closed lists".
  4. "Re: Reason for the change". Archived from the original on 2009-07-12. Retrieved 2008-07-28.
  5. "Torvalds bashes vendor-sec private Linux security list". Archived from the original on 2009-08-20. Retrieved 2010-09-05.
  6. "Re: Linux 2.6.25.10 (resume)".

External links

Category: