About the vulnerability reporting instructions on the web site
Sergio Gelato <[email protected]> Wed, 30 Aug 2017 12:18:31 +0200
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
I am under the impression that Heimdal's process for reporting sensitive bugs is broken. I am referring to the following sentence on https://www.h5l.org/ : "Security sensitive bug reports should be sent to [email protected] using this PGP key (key id 3B81827E)." Not only do I get the impression that bug reports sent in this manner are not being acted on (it could be just a lack of feedback but that's also a problem), but all subkeys of that PGP key have expired: the ones in the file on the web site ten years ago, the newer ones available through the PGP keyservers more recently. The web site *is* being updated with release information so I don't understand why it is not also being updated with contact information.
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEdy2TlEpbXQu4A6YbrueYj9pYv8QFAlmmkO4ACgkQrueYj9pY v8RC6RAAtq/8rfZuvOimrM/SydIUG/7e0oteqR8SG1yq8dik3XuBtqFmy7fWazfg 5C96rICQ9VfWhFsZ0kiSOdH5rZAf0aqJYoczdJ3Xee7EdapMmTPbWmqyv8sfS7xV 3kkRQgo4UTW045eV1rGi7bCKf0nHhfsg0Vt41Y5C0Z4kJ0AYnLXWKxdF9qwIhxMn 9p+9TWQMTWG4Muah4ipEsBCwWK1bCeUe/xDHOxB409CiWfik7Hgs+stt6Rc3jbB2 pd7AxvYBImVbpU9SrFmINM1QT5otjhvNWvOVdpUIA93hV6qNa66qvc4EhM16khmc lUBUZIdJ5V95A2uLnH/OuHwBbp9/WnrxpS5HxzUYCXKoxYt7n1dn9hq3KwKejQZF vrRSDsOsBlCcG5Jkh2Pgj/ieF3J3/gbk9k/pd0+cKldlA29aT2Ic/hhEMSniLDBa t+2jMMDRsEDlHjiY6NG2DNFci8XW85yBFuACiqBb/A0eCz2sqOfKaS+ldQwOcLIA cJME9eFHnZn8H58FtYQdaUXl6cbfnPjKC5XcIsLDrup+H1+JdklhkKkgujG5AECx BqPVyanaj6uHyIeUzvC8c2CeDRrkwvOt8ntkA/2e8WUCUAOQ5/udLXSy79mciO5o uhEQqIt87nd9I9I9baQIxnA/yrFBbLZ00PGnCcYlLEbwDpGJPXc= =Jq/t -----END PGP SIGNATURE-----