What is the UCB-Security Mailing List and How to Join

A knowledge base article about What is the UCB-Security Mailing List and How to Join provided by the UC Berkeley IT Service Hub - Knowledge Portal

Purpose of UCB-Security

The UCB-Security Mailing List (ucb-security@lists.berkeley.edu) is a private, non-archived list appropriate for many types of IT security discussions. This list is intended as a communication tool to share information and resources for IT staff responsible for the security of campus information systems. The UCB-Security should be used to:

All list members may post new topics and reply to current topics. We encourage relevant discussion to topics posted to the list by all list members.

Subscribing to UCB-Security

Eligibility

You are eligible to subscribe to UCB-Security if you are:

Exceptions to the above are possible and requests can be made through bConnected Google Groups (see below).

Submitting a Subscription Request

Email iso@berkeley.edu and request to be added.

List Policies

Use of this mailing list is covered by the Use of Electronic Mail section of the E-Berkeley Policy for [University of California, Berkeley] Campus Online Activities.

Micronet versus UCB-Security

UCB-Security should be used instead of Micronet for any security-related discussions. Micronet membership is not vetted, and the list itself is publicly archived and indexed by internet search engines. Attackers are increasingly studying the institutions they attack to learn weaknesses. This makes Micronet a bad choice for discussions that touch on security. This can include even announcing vulnerabilities in vendor or open-source packages, as this may spark a discussion about mitigation strategies for campus.

There should be no cross-posts to both UCB-Security and Micronet. Cross-posting is sending the same email at the same time to both lists. In the very unusual case where the same message should be sent to both lists, send the message twice, once to each list. However, if you find yourself tempted to post the same message to both lists, please reconsider whether this is truly necessary. If it is a security-related topic, it probably should be sent to UCB-Security alone. Otherwise, Micronet is probably the correct list.

Security topics that should NOT be discussed even on UCB-Security