Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

I don't get why the initial reporter should have to do that legwork. The kernel maintainers should be doing that.


Ffs, we're talking about open source projects here. Those mailing lists, mentioned there, ARE PUBLIC.

Make them private? Now you have a nice stream of zero days, long before fixes are available, making bad actors who made it in filthy rich.


If you're suggesting a private disclosure channel, made for all the maintainers of the ~600 actively maintained distributions (including those that pop into existence just to get access to the disclosures), then that would be a point you could make. But, that text above is reasonable, because the mailing lists they're referring to are public.

Open source code process must assume bad actors are involved (because they have been historically, and will be always and forever). So, this isn't some "easy" scenario. Talking to the guy that can fix it first, and assumed the distributions contain bad actors, then disclosing to them once the fix is available, is reasonable, and I don't see an alternative.

I would be interested in seeing what the thoughts are on a proper disclosure cycle, for those 600 distributions. Seems very complex.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: