Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:96664 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 63641 invoked from network); 30 Oct 2016 22:13:33 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 30 Oct 2016 22:13:33 -0000 Authentication-Results: pb1.pair.com header.from=taoguangchen@icloud.com; sender-id=pass Authentication-Results: pb1.pair.com smtp.mail=taoguangchen@icloud.com; spf=pass; sender-id=pass Received-SPF: pass (pb1.pair.com: domain icloud.com designates 17.133.188.43 as permitted sender) X-PHP-List-Original-Sender: taoguangchen@icloud.com X-Host-Fingerprint: 17.133.188.43 pv35p18im-ztdg05091101.me.com Received: from [17.133.188.43] ([17.133.188.43:39696] helo=pv35p18im-ztdg05091101.me.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 47/D7-25911-B8076185 for ; Sun, 30 Oct 2016 17:13:32 -0500 Received: from process-dkim-sign-daemon.pv35p18im-ztdg05091101.me.com by pv35p18im-ztdg05091101.me.com (Oracle Communications Messaging Server 7.0.5.38.0 64bit (built Feb 26 2016)) id <0OFV00D00S5HDE00@pv35p18im-ztdg05091101.me.com> for internals@lists.php.net; Sun, 30 Oct 2016 22:13:28 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icloud.com; s=4d515a; t=1477865608; bh=TZ2AGMIwrDkx5SAuTsSDz3Ek7yFCk08VJeZRJ2B/K6I=; h=Content-type:MIME-version:Subject:From:Date:Message-id:To; b=QeIlCQ2+1BYmoE0nmcEo6IB4jcqvXWdTB25iSJkpy/DWZS0NO2N8SDB/3ymxNvVV+ dE3bHgwBs0roLo6rnVJ90aX3GjaIST8eHaIoEz7fGDqdA0zZeZ1Qgj7WBQhp4Vz9gO YYYlfcYwPBgaytHlyM0yQHj3BYeIDX2urF/uruVf2sPjwOG/pvMnHLkjNoKv17SKLG VsmGXhDEpwhkfkeYANboZYqHst3+FN28mn61++ZM+qPzA0lXBqc52NaZ4eqY3DEbEv By3GJdmUfBMkcMg/oJ4bKXtXUpb1jDyTwe2FzQh4mMQjxRrrLoTIgC6S1ZoqySuLYz hCItdX2th/4Kg== Received: from [192.168.199.166] (no-data [60.26.56.10]) by pv35p18im-ztdg05091101.me.com (Oracle Communications Messaging Server 7.0.5.38.0 64bit (built Feb 26 2016)) with ESMTPSA id <0OFV00HXDSE9AQ20@pv35p18im-ztdg05091101.me.com>; Sun, 30 Oct 2016 22:13:28 +0000 (GMT) X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:,, definitions=2016-10-30_08:,, signatures=0 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 clxscore=1034 suspectscore=0 malwarescore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1603290000 definitions=main-1610300404 Content-type: multipart/alternative; boundary=Apple-Mail-107264E6-4BD7-4A46-9C71-1C71F36023A6 MIME-version: 1.0 (1.0) X-Mailer: iPhone Mail (14B72) In-reply-to: Date: Mon, 31 Oct 2016 06:13:19 +0800 Cc: Anatol Belski , PHP Internals Content-transfer-encoding: 7bit Message-ID: <27E2A6F1-BCE2-491F-A9D3-8F77C2E84A03@icloud.com> References: <3a5408bc-b71d-920c-45e4-b9be02350b6c@gmail.com> <01a901d22e06$ca4e3450$5eea9cf0$@belski.net> To: Stanislav Malyshev Subject: Re: [PHP-DEV] Security issue handling From: taoguangchen@icloud.com (=?GB2312?B?s8LBwQ==?=) --Apple-Mail-107264E6-4BD7-4A46-9C71-1C71F36023A6 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Hi, >> OFC it'd be ideal to have some karma holders to participate. And >> another option, which is IMHO eligible - we could invite several >> reporters. There is already a couple of people, who regularly report >> security issues and keep them confident until they're publicly >> disclosed. IMHO it is a good base for trust. > > The reporter is asked to review the patch anyway. I don't think I feel > comfortable inviting other reporters - unless I know who they are, which > right now is not true for most of them. I'm gladly willing to help with some security issues if you need and want. --Apple-Mail-107264E6-4BD7-4A46-9C71-1C71F36023A6--