!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

366 Members
Discussions around Security | Triaging happens in #security:nixos.org128 Servers

Load older messages


SenderMessageTime
10 Oct 2024
@emilazy:matrix.orgemilyactually I don't know how to do that while eval is in progress00:08:50
@cf11:0x2c.org@cf11:0x2c.org left the room.05:03:51
@f0x:pixie.townf0xhmm, it seems like the firefox -bin packages aren't updated yet?10:58:46
@hexa:lossy.networkhexawdym updated?10:59:45
@hexa:lossy.networkhexathey were merged 18 hours ago, we're probably just waiting for hydra, as always11:00:02
@hexa:lossy.networkhexathey are in the latest channel bump for nixos-24.05 for example11:02:10
@hexa:lossy.networkhexanot sure why the pr tracker claims otherwise11:02:25
@hexa:lossy.networkhexaimage.png
Download image.png
11:02:27
@hexa:lossy.networkhexa cc Alyssa Ross 11:02:49
@hexa:lossy.networkhexahttps://nixpk.gs/pr-tracker.html?pr=34754011:02:59
@vcunat:matrix.orgvcunatI think it moved around 2h ago.11:03:31
@vcunat:matrix.orgvcunat * I think the channel moved around 2h ago.11:03:37
@hexa:lossy.networkhexayeah11:03:38
@vcunat:matrix.orgvcunatSounds too long for caching here.11:04:05
@f0x:pixie.townf0xah, I noticed it on search.nixos.org, so probably just hydra then?11:06:19
@hexa:lossy.networkhexaimage.png
Download image.png
11:06:56
@f0x:pixie.townf0xoh I got confused by the differences in versions across releases, it's just firefox-devedition-bin that's still on 131.0b911:09:11
@hexa:lossy.networkhexa oh, we have those as well? sigh 11:09:34
@hexa:lossy.networkhexaI didn't know11:09:49
@p4cmanus3r:matrix.orgp4cmanus3r joined the room.13:26:30
@qyliss:fairydust.spaceAlyssa Ross
In reply to @hexa:lossy.network
cc Alyssa Ross
fixed
16:03:52
@qyliss:fairydust.spaceAlyssa Ross(thanks for telling me)16:04:30
@qyliss:fairydust.spaceAlyssa Rossperformance will be degraged for approximately three hours while it recovers16:06:29
@qyliss:fairydust.spaceAlyssa Ross(the yellow question mark btw means that checking that branch failed, which usually means something has gone wrong on the backend)16:10:19
11 Oct 2024
@tollb1:matrix.orgtollb1 joined the room.13:21:06
12 Oct 2024
@elvishjerricco:matrix.orgElvishJerricco Jan Tojnar, emily: So what do we want to do about the gdm-autologin LUKS exfiltration thing? I have a working demo of the problem. 17:35:53
@emilazy:matrix.orgemilywe should decide on a fix for ourselves and write up an advisory of the vulnerability and send it to oss-security, cc'ing the arch security team, probably requesting a CVE too however that's done17:36:46
@elvishjerricco:matrix.orgElvishJerriccoIt's worth noting that it's a very niche problem, in the sense that the autologin'd user is almost certainly owned by the same human being who just entered the LUKS password in the first place.17:37:05
@elvishjerricco:matrix.orgElvishJerriccobut yea I don't think that will affect the severity rating of it17:37:18
@emilazy:matrix.orgemilythere are still viable threat models & niche security vulnerabilities should still be reported17:37:27

Show newer messages


Back to Room ListRoom Version: 9