Note: Due to technical difficulties, the Archives are currently not up to date.
GMANE provides an alternative service for most mailing lists. c.f. bug 424647
List Archive: gentoo-security
<br><br><div class="gmail_quote">On Fri, Aug 26, 2011 at 2:57 PM, Alex Legler <span dir="ltr"><<a href="mailto:a3li@g.o">a3li@g.o</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
<div class="im">On Friday 26 August 2011 14:18:20 Daniel A. Avelino wrote:<br>
> Alex.<br>
><br>
> May be a call for volunteers more "intense" could improve the manpower. This<br>
> could be a more<br>
> easy start point to address, no?.<br>
<br>
</div>Well, the staffing needs page IS the point for making such calls. It's not<br>
that we haven't had people contacting us about helping, it's that they usually<br>
disappear shortly after that again after they've seen the tasks at hand.<br>
<div class="im"><br></div></blockquote><div>I know how it works!<br> <br></div><blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;"><div class="im">
> I work too in some [smaller] security processes and can figure out what kind<br>
> of work are you talking about.<br>
><br>
> As Kauhaus pointed, may be somethings should be automated but again, this is<br>
> a hard job to<br>
> implement and to keep results trustable.<br>
><br>
<br>
</div>Automation is a key thing I've been introducing in the new tools and processes<br>
for sending advisories.<br>
I'd rather not focus on a temporary automated system however, knowing that<br>
we're about to get back to the/near the status quo.<br>
<div class="im"><br></div></blockquote><div>When I think about automation, I had in mind something that could help developers to find<br>vulnerabilities in a more fast way [searching and confronting CVE, for example] and start a <br>
"call for solution" process. I work with solutions of this type for WEB vulnerabilities discover<br>and some tools are very interesting to reduce the correction time.<br><br>By the way, I will start to read about what a Padawan should know instead of <br>
make speculations prematurelly. :D<br> <br></div>Thank you very much for the explanations.<br><br>Daniel A. Avelino<br></div>
|
|