<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: oCERT &#8211; Responsing to Flaws in Open Source Software</title>
	<atom:link href="http://www.darknet.org.uk/2008/05/ocert-responsing-to-flaws-in-open-source-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/05/ocert-responsing-to-flaws-in-open-source-software/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/05/ocert-responsing-to-flaws-in-open-source-software/#comment-123101</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Mon, 19 May 2008 12:08:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=846#comment-123101</guid>
		<description>@Rob Holland,

I assume you are associated in some way with oCERT. A great idea and I hope it gathers some momentum. I am interested as to how you are intending to get vulnerabilities reported to you. 
Are you only interested in 0-day?
Is it worth listing this as a sourceforge project?

There is more and more open source product out there so I expect that your site will expand very rapidly. It is a shame that you only have (at the time of writing) four reports in the past two months.

Good luck to you!</description>
		<content:encoded><![CDATA[<p>@Rob Holland,</p>
<p>I assume you are associated in some way with oCERT. A great idea and I hope it gathers some momentum. I am interested as to how you are intending to get vulnerabilities reported to you.<br />
Are you only interested in 0-day?<br />
Is it worth listing this as a sourceforge project?</p>
<p>There is more and more open source product out there so I expect that your site will expand very rapidly. It is a shame that you only have (at the time of writing) four reports in the past two months.</p>
<p>Good luck to you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Holland</title>
		<link>http://www.darknet.org.uk/2008/05/ocert-responsing-to-flaws-in-open-source-software/#comment-123062</link>
		<dc:creator>Rob Holland</dc:creator>
		<pubDate>Fri, 16 May 2008 07:49:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=846#comment-123062</guid>
		<description>Matt, yes, we&#039;ll help those who need it develop fixes or improve their infrastructure security.</description>
		<content:encoded><![CDATA[<p>Matt, yes, we&#8217;ll help those who need it develop fixes or improve their infrastructure security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jinesh</title>
		<link>http://www.darknet.org.uk/2008/05/ocert-responsing-to-flaws-in-open-source-software/#comment-123045</link>
		<dc:creator>Jinesh</dc:creator>
		<pubDate>Wed, 14 May 2008 07:07:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=846#comment-123045</guid>
		<description>Wow, that a gr8 news for small open source projects. Actually it is a 1 more step taken by google to trouble micro$oft.</description>
		<content:encoded><![CDATA[<p>Wow, that a gr8 news for small open source projects. Actually it is a 1 more step taken by google to trouble micro$oft.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matt</title>
		<link>http://www.darknet.org.uk/2008/05/ocert-responsing-to-flaws-in-open-source-software/#comment-123038</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Tue, 13 May 2008 16:51:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=846#comment-123038</guid>
		<description>I am still not getting the full idea of this project. Will the teams at oCERT.org be responsible for patching and deploying fixes for security holes, or are they just a contact for the Open Source projects? It seems as though for the bigger projects, oCERT will just pass information about reports and vulnerabilities, but for the little guys, they will help with the fixing. Am I getting this right?</description>
		<content:encoded><![CDATA[<p>I am still not getting the full idea of this project. Will the teams at oCERT.org be responsible for patching and deploying fixes for security holes, or are they just a contact for the Open Source projects? It seems as though for the bigger projects, oCERT will just pass information about reports and vulnerabilities, but for the little guys, they will help with the fixing. Am I getting this right?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
