Re: [Xen-devel] Possible improvement to Xen Security Response Process

2017-01-04 Thread James Bulpin
On Wed, 2017-01-04 at 13:02, Jan Beulich wrote: On 04.01.17 at 12:58, wrote: >> On Tue, 2016-12-13 at 08:42, Jan Beulich wrote: >> On 12.12.16 at 18:11, wrote: I'll join in the bunfight with a stronger proposal (noting in passing that according to https://xenbits.xen.org/xsa/

Re: [Xen-devel] Possible improvement to Xen Security Response Process

2017-01-04 Thread James Bulpin
On Tue, 2016-12-13 at 08:42, Jan Beulich wrote: On 12.12.16 at 18:11, wrote: >> I'll join in the bunfight with a stronger proposal (noting in passing >> that according to https://xenbits.xen.org/xsa/ we are now expecting 5 >> consecutive weeks of XSA announcements): >> 1) Where practical, X

Re: [Xen-devel] Critique of the Xen Security Process

2015-11-06 Thread James Bulpin
On Fri, Nov 06, 2015, Joanna Rutkowska wrote > [snip] I was then asked to share some more > thoughts about how I thought Xen could actually improve its security > process [4]. Thanks Joanna for taking the time to put these thoughts into writing. I think there are a number of actionable things here