Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-28 Thread Michael S. Tsirkin
; > Anthony Liguori > > > From: Michael S. Tsirkin [m...@redhat.com] > Sent: Monday, April 28, 2014 10:53 AM > To: Liguori, Anthony > Cc: Peter Maydell; Anthony Liguori; qemu-devel; Stefan Hajnoczi; Andreas > Färber > Subject: Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses fo

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-28 Thread Markus Armbruster
"Liguori, Anthony" writes: > I think this is a bit overkill. Many projects use private mailing > lists for this purpose. I guess you're right on the average level of paranoia among people willing to report security issues, but I'm afraid you might be off on the 90th percentile. Besides, an enc

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-28 Thread Michael S. Tsirkin
Regards, > > > > Anthony Liguori > > > > > > From: Michael S. Tsirkin [m...@redhat.com] > > Sent: Monday, April 28, 2014 6:39 AM > > To: Peter Maydell > > Cc: Anthony Liguori; qemu-devel; Stefan Hajnoczi

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-28 Thread Michael S. Tsirkin
day, April 28, 2014 6:39 AM > To: Peter Maydell > Cc: Anthony Liguori; qemu-devel; Stefan Hajnoczi; Andreas Färber; Liguori, > Anthony > Subject: Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible > disclosure > > On Mon, Apr 28, 2014 at 02:24:45PM +0100, Pet

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-28 Thread Daniel P. Berrange
On Mon, Apr 28, 2014 at 02:24:45PM +0100, Peter Maydell wrote: > On 17 April 2014 19:54, Michael S. Tsirkin wrote: > > On Thu, Apr 17, 2014 at 09:10:12AM -0700, Anthony Liguori wrote: > >> On Thu, Apr 17, 2014 at 6:54 AM, Michael S. Tsirkin > >> wrote: > >> > People sometimes detect security iss

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-28 Thread Michael S. Tsirkin
On Mon, Apr 28, 2014 at 02:24:45PM +0100, Peter Maydell wrote: > On 17 April 2014 19:54, Michael S. Tsirkin wrote: > > On Thu, Apr 17, 2014 at 09:10:12AM -0700, Anthony Liguori wrote: > >> On Thu, Apr 17, 2014 at 6:54 AM, Michael S. Tsirkin > >> wrote: > >> > People sometimes detect security iss

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-28 Thread Peter Maydell
On 17 April 2014 19:54, Michael S. Tsirkin wrote: > On Thu, Apr 17, 2014 at 09:10:12AM -0700, Anthony Liguori wrote: >> On Thu, Apr 17, 2014 at 6:54 AM, Michael S. Tsirkin wrote: >> > People sometimes detect security issues in upstream >> > QEMU and don't know where to report them in a non-public

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-17 Thread Michael S. Tsirkin
On Thu, Apr 17, 2014 at 09:10:12AM -0700, Anthony Liguori wrote: > On Thu, Apr 17, 2014 at 6:54 AM, Michael S. Tsirkin wrote: > > People sometimes detect security issues in upstream > > QEMU and don't know where to report them in a non-public way. > > Of course whoever just wants full disclosure c

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-17 Thread Michael S. Tsirkin
On Thu, Apr 17, 2014 at 09:10:12AM -0700, Anthony Liguori wrote: > On Thu, Apr 17, 2014 at 6:54 AM, Michael S. Tsirkin wrote: > > People sometimes detect security issues in upstream > > QEMU and don't know where to report them in a non-public way. > > Of course whoever just wants full disclosure c

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-17 Thread Anthony Liguori
On Thu, Apr 17, 2014 at 6:54 AM, Michael S. Tsirkin wrote: > People sometimes detect security issues in upstream > QEMU and don't know where to report them in a non-public way. > Of course whoever just wants full disclosure can just go public, > but there's nothing specified for non-public - until

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-17 Thread Michael S. Tsirkin
On Thu, Apr 17, 2014 at 03:03:48PM +0100, Peter Maydell wrote: > On 17 April 2014 14:54, Michael S. Tsirkin wrote: > > People sometimes detect security issues in upstream > > QEMU and don't know where to report them in a non-public way. > > Of course whoever just wants full disclosure can just go

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-17 Thread Peter Maydell
On 17 April 2014 14:54, Michael S. Tsirkin wrote: > People sometimes detect security issues in upstream > QEMU and don't know where to report them in a non-public way. > Of course whoever just wants full disclosure can just go public, > but there's nothing specified for non-public - until recently

Re: [Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-17 Thread Andreas Färber
Am 17.04.2014 15:54, schrieb Michael S. Tsirkin: > People sometimes detect security issues in upstream > QEMU and don't know where to report them in a non-public way. > Of course whoever just wants full disclosure can just go public, > but there's nothing specified for non-public - until recently A

[Qemu-devel] [PATCH] MAINTAINERS: addresses for responsible disclosure

2014-04-17 Thread Michael S. Tsirkin
People sometimes detect security issues in upstream QEMU and don't know where to report them in a non-public way. Of course whoever just wants full disclosure can just go public, but there's nothing specified for non-public - until recently Anthony was doing this informally. As I started doing thi