The Original Security-Vulnerability Mailing List Is Back — and Betting on Provenance Over Disclosure — type0 | type0