On Wed, Jul 20, 2005 at 11:53:25PM -0700, Robert Menschel wrote:
> Hello Duncan,
> 
> Wednesday, July 20, 2005, 9:07:15 PM, you wrote:
> 
> >> The SARE list is private and invitation only for exactly these reasons.
> 
> DF> I'm *really worried* about proposals that involve mailing lists that
> DF> have only private archives and require moderator approval for
> DF> subscription. It just doesn't feel right for an open source project.
> 
> Agreed.  But you do secure the security-bug submissions from
> publicly accessible lists and archives...

Leaking rules to the public don't compromise users systems! Obviously
there is a tradeoff.

> DF> It's quite possible that this drives people away. In fact I'm quite
> DF> sure people are less likely to get involved if they have to somehow
> DF> prove that they aren't a spammer in order to subscribe.
> 
> Yes, but you also don't want spammers wrecking the system, making it
> useless.  There's a viable balance somewhere...

Agreed.

-- 
Duncan Findlay

Attachment: signature.asc
Description: Digital signature

Reply via email to