Security response team?

Jon South striker at
Wed Apr 7 09:15:17 GMT 2004

ratler at wrote:
 > Hey guys.
 > Some people have started to ask questions if we have a official security
 > response team, not like it works now where some of the devs just fix the
 > issue and maybe send a mail to our list it fixed.
 > What we need is a team, a few people from all the devs that share a PGP
 > key and new list where people can send us mail encrypted or not. For
 > example security at This way we can sign all our mails with
 > this key when responding to security problems and updates. This way users
 > can also verify that our updates are not fake and that it really comes
 > from us.
 > What do you guys think?
 > Sincerely
 > Stefan Wold

Hmm...Interesting idea, but isn't that normally only for distros that 
make/modify their packages? We do fairly few patches and other 
modifications to the installable modules ourselves.

However, it's a pretty noble idea, I guess it'd be best to be safe than 
sorry. I try to keep up with the current security issues myself and I 
subscribe to the Full-Disclosure mailing list which is one of the few 
ML's that gets a lot of the new exploits/bugs for software/hardware.

I am curious though, as to how we could fix problems with software as 
opposed to the software's developer fixing it themselves and us just 
updating the module. However, that leads to the question about what to 
do with software that no logner has a dev team to maintain them...

Just my 3.1459 cents.

- -Striker

P.S. - Are there (have there been) any known exploits for the lunar core 

