!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

367 Members
Discussions around Security | Triaging happens in #security:nixos.org124 Servers

Load older messages


SenderMessageTime
6 Jul 2022
@linus:schreibt.jetzt@linus:schreibt.jetzt(I really don't know enough about PGP to be sure of any of this...)14:03:11
@stigo:matrix.orgstigoyes i think that's right, in the gnupg case it seems to be like a signature can be turned into a "zip bomb"14:05:04
@hexa:lossy.networkhexathis is how I understood it as well14:11:17
@hexa:lossy.networkhexathe author of the patch kindly demonstrated that on oss-sec14:11:25
@stigo:matrix.orgstigo You can test it with curl -O https://seclists.org/oss-sec/2022/q3/att-9/decomp-3.bin && gpg --verify decomp-3.bin /dev/null 14:12:25
@stigo:matrix.orgstigo(slower if you import the pubkey https://seclists.org/oss-sec/2022/q3/att-9/test-key_cert.bin it seems)14:14:04
@stigo:matrix.orgstigo * You can test it with #POC# curl -O https://seclists.org/oss-sec/2022/q3/att-9/decomp-3.bin && gpg --verify decomp-3.bin /dev/null 14:16:15
@stigo:matrix.orgstigohm, maybe more fun with some very large rsa keys14:24:14
7 Jul 2022
@stigo:matrix.orgstigo https://github.com/NixOS/nixpkgs/pull/180336 broke tests in gpgme, can't look at it today, too much work to do. 08:49:42
@hexa:lossy.networkhexaNot a good day for me either, sorry 09:32:39
@linus:schreibt.jetzt@linus:schreibt.jetzt hexa: vcunat (thanks!) seems to have taken care of it :) 09:36:16
@vcunat:matrix.orgvcunatWell, I unblocked the builds, but I haven't really verified whether the test detected some real unexpected consequence.09:38:15
@vcunat:matrix.orgvcunatAnd perhaps notify some appropriate place around upstream or around the patch?09:38:50
@stigo:matrix.orgstigoIt's unclear what upstream thinks of this patch/bug -> https://seclists.org/oss-sec/2022/q3/2712:11:10
@stigo:matrix.orgstigo
In reply to @vcunat:matrix.org
And perhaps notify some appropriate place around upstream or around the patch?
Pinged the patch author on #180336, just in case
12:49:42
@hexa:lossy.networkhexacool.12:54:20
@hexa:lossy.networkhexahttps://element.io/blog/element-launches-chatterbox/14:14:06
@hexa:lossy.networkhexalooks like they're selling that feature14:16:27
@dandellion:dodsorf.asDandellionhttps://github.com/vector-im/chatterbox it's foss, they're selling homeserver hosting as usual (just lower rates for the guest users through the livechat thing)16:15:48
@k900:0upti.meK900Oh, it's Hydrogen16:18:06
@hexa:lossy.networkhexagraham was looking for something besides email to bootstrap encrypted disclosure16:18:57
@hexa:lossy.networkhexawondering if that could be that16:19:03
@dandellion:dodsorf.asDandellionI think element needs an easier way to do pgp style key verification stuff in that case16:20:05
@hexa:lossy.networkhexaespecially predistributing the key independently16:20:33
@hexa:lossy.networkhexaand having an option to verify that16:20:47
@hexa:lossy.networkhexamight be cumbersome, but.16:20:57
@dandellion:dodsorf.asDandellionThat is a thing for the device specific ones FWIW16:21:08
@hexa:lossy.networkhexa * especially predistributing the public key independently16:21:08
@dandellion:dodsorf.asDandellionand used to be the only way16:21:14
@dandellion:dodsorf.asDandellionI don't think it is a thing for the cross signing master key thing16:21:35

There are no newer messages yet.


Back to Room ListRoom Version: 9