8 ms·
Wow, this is sad. Hope we can get more info on what was going on. Besides Bugtraq what mailing lists security wise do you follow? EDIT: Or what other general
by Bjoern 13y ago
Wow, this is sad. Hope we can get more info on what was going on.
Besides Bugtraq what mailing lists security wise do you follow?
EDIT: Or what other general means by Twitter, Websites, Databases, Blogs etc. do you recommend?
- spindritf 13y agoSecunia has a free Secunia Weekly Advisory Summary newsletter. You need to register for an account at https://secunia.com/community/profile/ https://secunia.com/community/profile/ and tick a box for a weekly summary IIRC. But it's probably easier and more convenient to subscribe for announce mailiing lists for software you're using. Unless you can turn off affected services or scramble and patch before maintainers.
- tptacek 13y agoWhy would you follow any mailing lists for security in 2014? The concept of a security mailing list predates Twitter, vulnerability databases, Reddit, and blogs. But we have all those things now, and they are all better than Full-Disclosure on its best days.
- Bjoern 13y agoYeah people keep telling me mail is dead, but its still kicking around and is very well alive. Let me edit my initial question to be email neutral though.
- icebraining 13y agoWhy are they better?
- uaygsfdbzf 13y agoAbstractly, I think the benefit email has over the above are nearly-immediate decentralization. All the other above mediums (generally) are either (A) centralized services or (b) require some sort of polling mechanism to poll a distribution point. I think it is harder to redact from an email list than any of these. Also, twitter's conversation layout in the web portal annoys the F* out of me. Sig Hash: f4bbafebca1ef074672ec2da3debd812
- twic 13y agoNo substitute for email, but VuXML is an interesting, machine-readable, and therefore potentially extremely useful way of distributing security advisories: http://www.vuxml.org/freebsd/ http://www.vuxml.org/freebsd/