Re: security contact draft

From: Chris Wright
Date: Thu Jan 13 2005 - 18:25:24 EST


* Florian Weimer (fw@xxxxxxxxxxxxx) wrote:
> * Chris Wright:
>
> > To keep the conversation concrete, here's a pretty rough stab at
> > documenting the policy.
>
> Looks fine. Maybe you can add the following section?
>
> 3) Non-disclosure agreements
>
> The Linux kernel security contact is not a formal body and therefore
> unable to enter any non-disclosure agreements.
>
> UNIRAS and probably others require NDAs from affected software vendors
> before they share vulnerability information. It makes things easier
> if you state upfront that you won't play such games.

Fair point, I can add that easily.

thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/