mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-15 14:16:14 -06:00
[GH-ISSUE #528] security issues disclosure #371
Labels
No labels
LTS merge
LTS merge
bug
bug
converted-to-discussion
doc-todo
documentation
duplicate
enhancement
file-transfer
firecfg
firejail-in-firejail
firetools
graphics
help wanted
information_old
installation
invalid
modif
moved
needinfo
networking
notabug
notourbug
old-version
overlayfs
packaging
profile-request
pull-request
question
question_old
removal
runtime-permissions
sandbox-ipc
security
stale
wiki
wiki
wontfix
wordpress
workaround
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/firejail#371
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @vn971 on GitHub (May 20, 2016).
Original GitHub issue: https://github.com/netblue30/firejail/issues/528
There is currently no official way to disclose security issues in firejail. Since firejail is SUID and is a security tool, a disclosure channel might become very appropriate in time.
The goal of a security disclosure channel is to make fixing patches closer in time to deployment time. (By removing the gap where an issue is publicly known but no patch exist yet.)
Example solution:
an official email and GPG public key so that people can send encrypted mails.
@netblue30 commented on GitHub (May 20, 2016):
Send an email to netblue30@yahoo.com , no GPG, just keep it simple. Maybe I can open an email list where I disclose important security fixes so people can update the software.
@vn971 commented on GitHub (May 20, 2016):
For the time being, OK. If firejail grows, I'd still advise to use GPG. It's the "Enigmail" plugin if you use thunderbird, for example.
Anyway, closing the ticket for now.
@vn971 commented on GitHub (May 20, 2016):
"Firejail-security mailing list" sounds good, especially if it's not a google one.
@netblue30 commented on GitHub (May 23, 2016):
Can you suggest a mailing list? The only one I used so far was google.
@reinerh commented on GitHub (May 23, 2016):
Sourceforge has mailing lists. But I guess you no longer want to use it.
@netblue30 commented on GitHub (May 23, 2016):
For sure I can use it, it is already there, I just have to enable it. Thanks.
@vn971 commented on GitHub (May 23, 2016):
Offtopic: I did send a report to the official mail address, the same day this issue was opened.
@vn971 commented on GitHub (May 23, 2016):
Note that "disclosure" and "news announcement" are very different things.
I wanted to address "disclosure" in this issue, meaning letting the main developer know about issues (but not letting others know, yet).
@requiredregistration commented on GitHub (May 23, 2016):
there is no need for mailing lists and forums. we have the issues tracker here.
e-mail cryptography is important and it would be good to have your setup ready for it. you will still be able to receive non-encrypted e-mails. read this for a quick start.
in the 'release notes' we will learn about solved security problems.
@vn971 commented on GitHub (Aug 2, 2016):
@netblue30 any updates on the security issue I wrote to netblue30@yahoo.com ?
I've had some inconveniences because of this today, will be happy to hear any news. Did you get the e-mail / acknowledged what I write?
@netblue30 commented on GitHub (Aug 3, 2016):
OOPS! I've just found it, sorry for that. The message is form May 20, with ~/deletme. Is this right?
@vn971 commented on GitHub (Aug 3, 2016):
@netblue30 Yup, that's the one. ("deleteme".)
@netblue30 commented on GitHub (Aug 3, 2016):
I have no idea how I managed to miss it, I'll bring in a fix shortly, thanks!
@vn971 commented on GitHub (Aug 4, 2016):
@netblue30 no problem. I guess you have lots of tickets/comments each weak. Will be waiting, thanks.
@netblue30 commented on GitHub (Aug 5, 2016):
Fixed. It was the ugliest bug so far, thanks!
@vn971 commented on GitHub (Aug 5, 2016):
@netblue30 hey, I want a badge then: "found the ugliest bug so far". Just kiddin.:)
Thanks!
@vn971 commented on GitHub (Aug 5, 2016):
Or maybe "mails a new issue every friday". (I've created one other now.)
@netblue30 commented on GitHub (Aug 7, 2016):
Just take a look in the README file :)