oss-security gets relatively little use? You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.
oss-security gets relatively little use? You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.
It gets little use in the sense that only a small fraction of vulnerabilities are reported there, and there are very few non-advisory discussions (often by the same 2-3 people).
It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.
So where's the residue of vulnerabilities that don't get sent there? You know of anything better?
Some hate mailing lists, not understanding how valuable the format and medium is. So they deride out of reflex, I suppose.
Mailing lists are a lot like democracy. Imperfect, but nothing else is less-Imperfect.
I had to create an inbox filter for oss-security to go into a different label/folder to make my email usable.