Re: Fostering a Hadoop security dev community

2013-06-24 Thread Andrew Purtell
Hey Aaron and others - On Mon, Jun 24, 2013 at 12:15 PM, Aaron T. Myers wrote: > I'm in favor of this in general, though I do think the proper way to do it > isn't obvious to me, given the cross-project nature of the goal. > There will be a security "design lounge" from 2pm to 4pm on Wednesday

Re: Fostering a Hadoop security dev community

2013-06-24 Thread Andrew Purtell
On Mon, Jun 24, 2013 at 12:15 PM, Aaron T. Myers wrote: > Sorry, what exactly do you mean by "meetup" ? > A like minded group meeting together to discuss and solve common cross-cutting issues, here: security. Or call it a virtual birds-of-a-feather? Note, however, that certainly not all of what

Re: Fostering a Hadoop security dev community

2013-06-24 Thread Aaron T. Myers
I'm in favor of this in general, though I do think the proper way to do it isn't obvious to me, given the cross-project nature of the goal. On Thu, Jun 20, 2013 at 1:01 PM, Andrew Purtell wrote: > On Thu, Jun 20, 2013 at 10:31 AM, Alejandro Abdelnur >wrote: > > > Is this restricted to the Hadoo

Re: Fostering a Hadoop security dev community

2013-06-24 Thread Aaron T. Myers
On Thu, Jun 20, 2013 at 10:46 AM, Larry McCay wrote: > I think that we could let the security vulnerability list know about it for > one thing. > Small clarification - note that "security@hadoop.a.o" is ostensibly only for Hadoop project security vulnerabilities - it's not really intended to be f

Re: Fostering a Hadoop security dev community

2013-06-20 Thread Roman Shaposhnik
On Thu, Jun 20, 2013 at 10:54 AM, Larry McCay wrote: > Yes, sorry for not explicitly stating it in my previous reply - this should > be a community built from representatives across the entire ecosystem. > My previous email was speaking to how we reach out to them. Do you see any role Apache Bigt

Re: Fostering a Hadoop security dev community

2013-06-20 Thread Andrew Purtell
Huge +1 On Thu, Jun 20, 2013 at 10:31 AM, Alejandro Abdelnur wrote: > Is this restricted to the Hadoop project itself or the intention is to > cover the whole Hadoop ecosystem? If the later, how are you planning to > engage and sync up with the different projects? > The intent is to cover the en

Re: Fostering a Hadoop security dev community

2013-06-20 Thread Larry McCay
t; > -Original Message- > From: Alejandro Abdelnur [mailto:t...@cloudera.com] > Sent: Friday, June 21, 2013 1:32 AM > To: common-dev@hadoop.apache.org > Subject: Re: Fostering a Hadoop security dev community > > This sounds great, > > Is this restricted to the

RE: Fostering a Hadoop security dev community

2013-06-20 Thread Zheng, Kai
common umbrella. -Original Message- From: Alejandro Abdelnur [mailto:t...@cloudera.com] Sent: Friday, June 21, 2013 1:32 AM To: common-dev@hadoop.apache.org Subject: Re: Fostering a Hadoop security dev community This sounds great, Is this restricted to the Hadoop project itself or the

Re: Fostering a Hadoop security dev community

2013-06-20 Thread Larry McCay
That's a good question I think that we could let the security vulnerability list know about it for one thing. There should be representatives of many - if not all - of the projects in the ecosystem. I suppose we could file a Jira for each to have someone represent their security concerns to t

Re: Fostering a Hadoop security dev community

2013-06-20 Thread Alejandro Abdelnur
This sounds great, Is this restricted to the Hadoop project itself or the intention is to cover the whole Hadoop ecosystem? If the later, how are you planning to engage and sync up with the different projects? Thanks. On Thu, Jun 20, 2013 at 9:45 AM, Larry McCay wrote: > It would be great to

Re: Fostering a Hadoop security dev community

2013-06-20 Thread Larry McCay
It would be great to have dedicated resources like these. One thing missing for cross cutting concerns like security is a source of truth for a holistic view of the entire model. A dedicated wiki space would allow for this view and facilitate the filing of Jiras that align with the big picture. On