Security advisories for OpenSSL should not be used for competitive advantage, according to the development project behind the widely used cryptography component. . The warning comes from the OpenSSL Project, which has published for the first time guidelines for how it internally handles security problems, part of an ongoing effort to strengthen the project following the Heartbleed security scare in April. The link for this article located at CSO Online is no longer available. . The OpenSSL Foundation cautions against leveraging security vulnerabilities for business gain, stressing the importance of ethical practices in security management.. OpenSSL Security, Vulnerability Ethics, Competitive Practices. . LinuxSecurity.com Team
We are pleased to announce a new project called oCERT, the Open Source Computer Emergency Response Team. The oCERT project is a public effort providing security handling support to Open Source projects affected by security incidents or vulnerabilities, just like national CERTs offer services for their respective countries. If you are a small project lacking security handling resources we can aid you in tracking down the extent and nature of potential compromises and security vulnerabilities and co-ordinate with all affected parties (like projects that ship your code). If you are a big project and/or Open Source vendor we can promptly communicate with you reports and vulnerabilities that might affect your codebase and infrastructure and help you out with your security requirements. Just because a project is open source does not ensure that it is totally secure. Check out the oCERT project for an attempt to help make open source security even better!. . Introducing oCERT, a new program aimed at improving the management of security issues and incident response for open source initiatives.. oCERT Project, Open Source Security, Incident Management, Vulnerability Handling, Security Support. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.