/srv/irclogs.ubuntu.com/2024/01/13/#ubuntu-security.txt

=== user03 is now known as gchound
sarnoldtomreyn: I can't access https://launchpad.net/bugs/2046565 I get the "lost something?" page. are you sure you've got the right visibility flags and subscriptions on it?01:09
tomreynsarnold: i can access it when logged in. i filed a "private security" bug. apparently only brian-murray §may be notified" about it.01:11
tomreyn"may be notified"01:11
tomreyn"other bug subscribers" appears to be empty. whom should i subscribe?01:11
tomreynon the top it says "Only the security group can see this information."01:12
sarnoldI wonder if i"m not in the security team? heh01:12
tomreyni guess visibility may be limited because it's not an ubuntu project?01:13
sarnoldyeah, that's probably it01:13
tomreynhttps://i.imgur.com/tKNMqGJ.png01:13
sarnoldit's weird because we can see some openstack stuff but maybe not all of it?01:13
sarnoldif this is apport, please also subscribe ubuntu-security01:14
tomreynit's not an apport generated bug report01:14
tomreyni just subscribed the ubuntu security team01:15
tomreynhttps://launchpad.net/~ubuntu-security01:15
sarnoldaha, thanks01:17
tomreynthe 'errors' software is managed by https://launchpad.net/~daisy-pluckers - three busy people whom i assumed to have received a copy of my report (but maybe they did not because it is flagged security?)01:17
tomreyni also e-mailed them and the apparent (based on the topic here) security team handler on duty about it01:17
sarnoldprobably just brian, hehe01:18
sarnoldtomreyn: thanks for the ping :)01:20
tomreynso.. i suggest discussing internally how to ensure that private security bugs reported against (somewhat) important infrastructural software are received by someone who is able to act upon them01:20
tomreyni'm sorry this boring bug ended up in your hands :)01:20
tomreynand i appreciate your response.01:21
sarnoldyeah, reporting to *one* person is a bit weaksauce01:23
tomreynsince brian is not a member of the security team i'm not even sure he received it01:25
sarnoldI think he probably did -- at least I subscribe other folks to bugs all the time :)01:26
tomreynvery well. (but, yes, more recipients might be better.)01:40
sarnolddefinitely01:42
=== chris14_ is now known as chris14
=== user03 is now known as gchound
=== JanC is now known as Guest9721
=== JanC_ is now known as JanC

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!