Live data from Hacker News

Full-disclosure – Administrivia: The End

marc.info

1–10 of 142 posts

Re: Full-disclosure – Administrivia: The End

#4
Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?

Re: Full-disclosure – Administrivia: The End

#5
post #4

Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?

Yes (vulnerabilities rather than exploits, although these disclosures often contained proofs of concept.) It was the de facto standard vehicle for this.

Re: Full-disclosure – Administrivia: The End

#6
post #4

Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?

http://en.wikipedia.org/wiki/Full_disclosure_(mailing_list)

  Full disclosure is a lightly moderated security mailing 
  list generally used for discussion about information
  security and disclosure of vulnerabilities. The list 
  was created on 9 July 2002 by Len Rose and is 
  administered by John Cartwright.
The wikipage goes on to list some notable zero-day vulnerabilities.

Re: Full-disclosure – Administrivia: The End

#9

He didn't really explain the full problem so maybe I am not fully appreciating the situation here, but this seems like a pretty big overreaction for a stupid request from some a single user.

Are you unfamiliar with the phrase he used, "straw that broke the camel's back"?

Re: Full-disclosure – Administrivia: The End

#10
post #4

Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?

Snippets from the mailing list charter[0] and listinfo[1] which simply say briefly:

    About Full-Disclosure

    Unlike bugtraq, this list serves no one except the list members themselves
    We don't believe in security by obscurity, and as far as we know, full 
    disclosure is the only way to ensure that everyone, not just the insiders 
    have access to the information we need to survive.

    We will try to operate this list without moderation, as we feel moderation 
    is an impediment to communication. 

    Any information pertaining to vulnerabilities is acceptable, for instance 
    announcement and discussion thereof, exploit techniques and code, related 
    tools and papers, and other useful information.
and, forebodingly:

    Politics should be avoided at all costs.
There's also the original announcement on the SuSE Linux security mailing list[2] and a follow-up by Mr Cartwright with some further rationale[3].

[0] https://web.archive.org/web/20050306210635/http://lists.nets...

[1] https://web.archive.org/web/20041205194605/http://lists.nets...

[2] http://marc.info/?l=suse-security&m=102639105014466&w=2

[3] http://marc.info/?l=full-disclosure&m=102965261426089&w=2

Post reply on HN