All of lore.kernel.org
 help / color / mirror / Atom feed
* [kernel-hardening] Secure Open Source Project Guide
@ 2013-01-31 15:34 Corey Bryant
  2013-01-31 18:37 ` Kees Cook
  0 siblings, 1 reply; 14+ messages in thread
From: Corey Bryant @ 2013-01-31 15:34 UTC (permalink / raw)
  To: kernel-hardening
  Cc: Anthony Liguori, Frank Novak, George Wilson, Joel Schopp,
	Kevin Wolf, Warren Grunbok II

In light of events like this http://lwn.net/Articles/535149/ "China, 
GitHub and the man-in-the-middle (Greatfire)", we are thinking that a 
guide for securing open source projects is needed.  For example, 
recommending pull requests or commits be PGP signed are a few things 
we've discussed that could defend against a MITM attack inserting 
malicious code.

Does anyone have any thoughts as to where we could publish such a guide? 
  Perhaps the Linux Foundation?

I believe we have the resources on this mailing list to work through the 
details and put together a succinct guide that we could take to a wider 
audience.

-- 
Regards,
Corey Bryant

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2013-02-06  7:02 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2013-01-31 15:34 [kernel-hardening] Secure Open Source Project Guide Corey Bryant
2013-01-31 18:37 ` Kees Cook
2013-01-31 19:30   ` Anthony Liguori
2013-02-01 14:33     ` Corey Bryant
2013-02-05 18:34     ` Corey Bryant
2013-02-05 23:09       ` Solar Designer
2013-01-31 21:10   ` Corey Bryant
2013-01-31 23:18     ` Peter Huewe
2013-02-01 14:36       ` Corey Bryant
2013-02-01 14:17     ` Solar Designer
2013-02-01 14:41       ` Corey Bryant
2013-02-01 15:08         ` Solar Designer
2013-02-05 18:37           ` Corey Bryant
2013-02-06  7:02           ` Shawn

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.