Re: Status of draft-christey-wysopal-vuln-disclosure-00.txt

Bruce Schneier <schneier@counterpane.com> Mon, 30 December 2002 19:56 UTC

Received: from ran.ietf.org (ran.ietf.org [10.27.6.60]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA00769; Mon, 30 Dec 2002 14:56:27 -0500 (EST)
Received: from majordomo by ran.ietf.org with local (Exim 4.10) id 18T60D-00038E-00 for ietf-list@ran.ietf.org; Mon, 30 Dec 2002 14:55:09 -0500
Received: from odin.ietf.org ([10.27.2.28] helo=ietf.org) by ran.ietf.org with esmtp (Exim 4.10) id 18SrLd-0005E6-00 for ietf@ran.ietf.org; Sun, 29 Dec 2002 23:16:17 -0500
Received: from conn.mc.mpls.visi.com (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA07508 for <ietf@ietf.org>; Sun, 29 Dec 2002 23:09:58 -0500 (EST)
Received: from vaio.counterpane.com (208-42-60-60.dynamic-dsl.visi.com [208.42.60.60]) by conn.mc.mpls.visi.com (Postfix) with ESMTP id 9F3918125; Sun, 29 Dec 2002 22:13:06 -0600 (CST)
Message-Id: <5.1.0.14.2.20021229221313.00b1e620@shell.visi.com>
X-Sender: schneier@shell.visi.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Sun, 29 Dec 2002 22:13:14 -0600
To: Chris Wysopal <cwysopal@atstake.com>, Florian Weimer <fw@deneb.enyo.de>, Valdis.Kletnieks@vt.edu, jasonc@science.org, coley@mitre.org, dee3@torque.pothole.com, ietf@ietf.org, kre@munnari.OZ.AU, info@knowngoods.org, cert@cert.org, Clinton Kreitner <kreitner@home.com>, Alan Paller <AlanPaller@aol.com>, Hal Pomeranz <hal@deer-run.com>
From: Bruce Schneier <schneier@counterpane.com>
Subject: Re: Status of draft-christey-wysopal-vuln-disclosure-00.txt
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: owner-ietf@ietf.org
Precedence: bulk

The document had a bunch of problems, and there were parts I disagreed 
with, but it is clear to me that some sort of "best practices" needs to be 
agreed to in this area.  I also agree that this sort of document should not 
be coordinated through the IETF, and was glad to see it withdrawn as a 
potential standard.

Bruce