[Ksummit-discuss] [MAINTAINERS SUMMIT] Handling of embargoed security issues

Andy Lutomirski luto at amacapital.net
Sat Sep 8 14:20:00 UTC 2018



> On Sep 8, 2018, at 4:34 AM, Greg KH <greg at kroah.com> wrote:
> 
>> On Sat, Sep 08, 2018 at 08:21:41AM -0300, Mauro Carvalho Chehab wrote:
>> IMHO, the best would be to have a formal/legal way to handle it.
> 
> No, sorry, some of us are not allowed legally to sign NDAs for stuff
> like this.  So keeping legal out of is it the best solution and we have
> done that pretty well so far.
> 

A lot us us (such as yours truly) have NDAs in place. I would love a clear mechanism by which a vendor gives explicit permission for me to communicate with other relevant parties. It doesn’t need to be fancy and legalistic, but having it written down would be very, very nice.


More information about the Ksummit-discuss mailing list