Re: cloud computing provider disclosures
An oss-security reply says cloud providers' early fix access shortens disclosure windows and catches pre-release bugs.
Jeremy Stanley replied on the oss-security list that giving public cloud operators early access to fixes lets them schedule mitigation with coordinated advisories. He said operators have repeatedly found logic and testing gaps in pre-advisory patches that developers missed in review. The post discusses disclosure process rather than a specific vulnerability.
- Early fix access lets cloud operators patch alongside advisories.
- Operators have found pre-release logic and testing gaps developers missed.
Posted by Jeremy Stanley on Oct 05 [...] [...] While this is true to some extent, getting early access to fixes helps reduce the window between public disclosure and risk mitigation by allowing their operators to schedule this work to coincide with a coordinated advisory publication. Also I've lost count of the number of times a public cloud operator has spotted a logic or testing gap in the pre-advisory copies of fixes which were missed by the developers in review...
This source does not provide full text. Read it at seclists.org.