Re: [yocto] Renaming the yocto-security mailing list
Rudolf J Streif <[email protected]>
| Newsgroups | org.yoctoproject.lists.yocto |
|---|---|
| Message-ID | <[email protected]> |
I don't any specifics about the incident. I suppose security-relevant information was submitted to a public mailing list. A private mailing list may help but in the end it's security-by-obfuscation. A mailing list for submitting CVEs is not the best choice imho. A secure web form should be better. We have a CVE Status page (https://wiki.yoctoproject.org/wiki/CVE_Status) that lists the current acknowledged CVEs but of course reported CVEs should go through an investigative filter and potentially sanitizing first before put on that page. :rjs On 8/19/25 8:08 AM, Marta Rybczynska via lists.yoctoproject.org wrote: > Hello all, > yesterday's incident confirms that yocto-security has a confusing name > that might cause confidential reports to arrive there. > > What about renaming the list to yocto-security-discussion or similar? > And eventually redirect yocto-security to the private security list. > > My reasoning: we shouldn't rename the private list as people might use > old versions of documentation and we want them to address the correct > private list when needed. It is less critical if a message expected > for the public list reaches the private one, than otherwise. > > What do you think? What is the process to do the change? > > Kind regards, > Marta > > -=-=-=-=-=-=-=-=-=-=-=- > Links: You receive all messages sent to this group. > View/Reply Online (#65770): https://lists.yoctoproject.org/g/yocto/message/65770 > Mute This Topic: https://lists.yoctoproject.org/mt/114782606/3617932 > Group Owner: [email protected] > Unsubscribe: https://lists.yoctoproject.org/g/yocto/unsub [[email protected]] > -=-=-=-=-=-=-=-=-=-=-=- >