This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: Community feedback on EU-FOSSA2 program.


On 2/4/19 11:12 AM, Florian Weimer wrote:
> * Carlos O'Donell:
> 
>> I'm looking to get community feedback regarding glibc's involvement with
>> this program, and the extent to which we should be involved.
> 
> We already are.  We do not have a say in this matter; the program has
> already started.  Since you (as stewards) sat on this for several weeks
> after the initial contact from Intigriti last year, we will never know
> if we had any chance in negotiating something else.

That is very important feedback. Thank you for providing that.

I disagree with your position though. Intigriti is open to talking with
us, and we can ask any questions we want, and be on the record as having
made any request we want.

I take sole responsibility for taking 8 days to respond to Intigriti,
which was mostly because it looked like spam and started with:
"This is not a sales mail, please have a look at the complete mail."
I don't know why Intigriti only emailed me directly, this was an odd choice
given that we ask for:
"You can reach out to the stewards directly and privately with your 
questions or comments by sending email to libc-maintainers@gnu.org." on
the wiki.

Responding to requests like this takes time, and between initial contact
and today it has only been 39 days. In this time we had to look to legal
for guidance, and the GNU project, all to ensure that we didn't place
anyone, including ourselves, at risk.

Again, I think we can do anything we want, but the nature of the
relationship is that Intigriti is in a contract with the EU, and not
with us, and so our own positions are just that our own.

>> The stewards are already discussing this with RMS as part of a GNU position
>> on the matter, and we met privately with Intigriti last week to understand
>> what role we have in this program. We had many suggestions to improve the
>> text of the agreement for perspective bug hunters (like needing copyright
>> assignment to contribute the fix that gives you a +20% bounty bonus), but
>> we need community input to decide which steps to take next.
> 
> As an outcome of this meeting, I added post-exploitation countermeasures
> to:
> 
>   <https://sourceware.org/glibc/wiki/Security%20Exceptions>

Should we add a section on "Bug Bounties" there? To clarify what the
community considers as valid targets for example?

I know we exclude regular expression parsing from the list of security
bugs, but we could make it clearer that for bug bounties we would also
not consider a dozen regexp bugs as being real security bugs?

> I do *not* plan to participate on the Intigriti platform and review
> issues before they are passed on to distribution security teams, under
> our documented security process:
> 
>   <https://sourceware.org/glibc/wiki/Security Process>
> 
> I will contact the distribution security teams later today and notify
> that they might get reports via the Intigriti platform.

That is a great idea. Thank you for taking that task.

-- 
Cheers,
Carlos.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]