About Full-Disclosure
Unlike bugtraq, this list serves no one except the list members themselves
We don't believe in security by obscurity, and as far as we know, full
disclosure is the only way to ensure that everyone, not just the insiders
have access to the information we need to survive.
We will try to operate this list without moderation, as we feel moderation
is an impediment to communication.
Any information pertaining to vulnerabilities is acceptable, for instance
announcement and discussion thereof, exploit techniques and code, related
tools and papers, and other useful information.
and, forebodingly: Politics should be avoided at all costs.
There's also the original announcement on the SuSE Linux security mailing list[2] and a follow-up by Mr Cartwright with some further rationale[3].[0] https://web.archive.org/web/20050306210635/http://lists.nets...
[1] https://web.archive.org/web/20041205194605/http://lists.nets...
[2] http://marc.info/?l=suse-security&m=102639105014466&w=2
[3] http://marc.info/?l=full-disclosure&m=102965261426089&w=2
I feel like everyone wants to hate moderation but it's one of those things, that when used correctly, make a community good.
I'm on several mailing lists that have grown significantly over 3-7 years. I, along with most other founding members, left lists that didn't have any moderation as they inevitably grew into a community similar to what's described in this announcement.
But the mailing lists/forums that had moderate moderation, removing furry porn for example, have continued to grow and continue their initial cause. Good moderation is not censorship, I would even say that people disrupting the core purpose of a community censor more than a good moderator by burying worthwhile content below shit posts.
The ledger could provide some assurances that others have had access to a given set of messages, but that really only helps with the boring sort of arguments.
Full disclosure is a lightly moderated security mailing
list generally used for discussion about information
security and disclosure of vulnerabilities. The list
was created on 9 July 2002 by Len Rose and is
administered by John Cartwright.
The wikipage goes on to list some notable zero-day vulnerabilities.People seem to believe that happened because vulnerabilities started to obtain a market value, but:
* The serious high-end memory corruption vulnerabilities were (a) more common and (b) much simpler at FD's inception, making them more amenable to posting on a list; in 2014, a high-end vulnerability is likely to be complex enough to merit in-depth consideration on a blog instead.
* Table-stakes XSS vulnerabilities also tend to get written up in blogs (where they help establish a track record for researchers whose future employers aren't going to trawl through FD looking for them), and when they get bought, get bought by bug bounties. It is hard to argue that bug bounties are a bad thing; nobody benefits from a web vulnerability in a SaaS product other than the operator of the SaaS product.