Re: new OpenSSL flaws

2014-06-08 Thread Solar Designer
On Fri, Jun 06, 2014 at 10:26:48AM +0400, Solar Designer wrote: > On Thu, Jun 05, 2014 at 04:38:24PM -0600, Theo de Raadt wrote: > > Kurt and Solar -- > > > > You are the primary contacts for the oss-security email list. > > Kurt is not. Sorry for going slightly off-

Re: new OpenSSL flaws

2014-06-08 Thread Solar Designer
On Sun, Jun 08, 2014 at 10:38:50AM +0200, Francois Ambrosini wrote: > I am a mere user who happened to spot an inconsistency and wanted to > inform all parties. I appreciate the constructive nature of your messages. > I will not comment on your guesses and opinions with information I do > not hav

Re: new OpenSSL flaws

2014-06-07 Thread Solar Designer
On Sat, Jun 07, 2014 at 09:13:36AM +0200, Francois Ambrosini wrote: > On Sat, 7 Jun 2014 07:04:47 +0400 > Solar Designer wrote: > > > Being on the distros list is not mandatory to receive advance > > notification of security issues. The list is just a tool. People > >

Re: new OpenSSL flaws

2014-06-06 Thread Solar Designer
To clarify and for the record: Being on the distros list is not mandatory to receive advance notification of security issues. The list is just a tool. People reporting security issues to the distros list are encouraged to also "notify upstream projects/developers of the affected software, other

Re: that private mailing list

2014-06-06 Thread Solar Designer
I've dropped CC to secur...@redhat.com, secur...@yandex.ru from this reply, because I don't feel like spamming them. I kept the CC to to...@yandex-team.ru, who I know is an OpenBSD user. On Thu, Jun 05, 2014 at 10:57:56PM -0600, Theo de Raadt wrote: > Solar and Kurt, a few questions: I think you

Re: new OpenSSL flaws

2014-06-05 Thread Solar Designer
Theo, On Thu, Jun 05, 2014 at 04:38:24PM -0600, Theo de Raadt wrote: > Kurt and Solar -- > > You are the primary contacts for the oss-security email list. Kurt is not. I guess the reason why you got such impression was because Kurt invited you to join distros recently, not knowing that you had

Re: that private mailing list

2014-06-05 Thread Solar Designer
Chris, the answer to your "really?" and "seriously?" is "yes, really and seriously". I am being sincere. I'll now proceed to provide replies to specific questions address to me in other messages. On Thu, Jun 05, 2014 at 10:10:57PM -0700, Chris Cappuccio wrote: >