Re: [SR-Users] Kamailio Security Policy - How to handle vulnerability reports

2015-02-25 Thread Olle E. Johansson
On 25 Feb 2015, at 18:56, Daniel Tryba wrote: > On Wednesday 25 February 2015 18:14:06 Olle E. Johansson wrote: >> Thank you for the feedback! > > BTW the Yes to is this a good thing ment: this is a really good idea to have > in writing. But you still have to rely on the bugfinders to realize t

Re: [SR-Users] Kamailio Security Policy - How to handle vulnerability reports

2015-02-25 Thread Daniel Tryba
On Wednesday 25 February 2015 18:14:06 Olle E. Johansson wrote: > Thank you for the feedback! BTW the Yes to is this a good thing ment: this is a really good idea to have in writing. But you still have to rely on the bugfinders to realize the impact/need to secrecy. > > But I fail to see how a

Re: [SR-Users] Kamailio Security Policy - How to handle vulnerability reports

2015-02-25 Thread Fred Posner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/25/2015 12:14 PM, Olle E. Johansson wrote: > > On 25 Feb 2015, at 17:24, Daniel Tryba wrote: > >> On Wednesday 25 February 2015 16:14:43 Olle E. Johansson wrote: >>> http://www.kamailio.org/wiki/securitypolicy >>> >>> >>> We encourage your fee

Re: [SR-Users] Kamailio Security Policy - How to handle vulnerability reports

2015-02-25 Thread Olle E. Johansson
On 25 Feb 2015, at 17:24, Daniel Tryba wrote: > On Wednesday 25 February 2015 16:14:43 Olle E. Johansson wrote: >> http://www.kamailio.org/wiki/securitypolicy >> >> >> We encourage your feedback! >> >> - Is this a good thing for the project? > > Yes > >> - Do you have any changes to the pol

Re: [SR-Users] Kamailio Security Policy - How to handle vulnerability reports

2015-02-25 Thread Daniel Tryba
On Wednesday 25 February 2015 16:14:43 Olle E. Johansson wrote: > http://www.kamailio.org/wiki/securitypolicy > > > We encourage your feedback! > > - Is this a good thing for the project? Yes > - Do you have any changes to the policy to suggest? Yes: >secur...@kamailio.org >This address sho

[SR-Users] Kamailio Security Policy - How to handle vulnerability reports

2015-02-25 Thread Olle E. Johansson
Hello Kamailians! During our last developer meeting, we had a discussion about implementing a security policy for the project. I drafted a proposal that seemed fine with the developer team. At this point, I'm looking for your feedback. The proposal is short and brief at this point, we'll learn