!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

363 Members
Discussions around Security | Triaging happens in #security:nixos.org126 Servers

Load older messages


SenderMessageTime
9 Oct 2024
@emilazy:matrix.orgemilyimage.png
Download image.png
21:39:41
@emilazy:matrix.orgemilyall it needs is a stale bot response for the perfect GitHub comedy21:39:44
@fabianhjr:matrix.orgFabián Herediahttps://x.com/vxunderground/status/1844122743727673366 Allegedly web.archive.org compromised22:35:58
@fabianhjr:matrix.orgFabián HerediaCurrently appears to be only a defacement of the landing page22:36:10
@emilazy:matrix.orgemilyoh good22:37:06
@fabianhjr:matrix.orgFabián Heredia
  • DDoS
22:37:57
@fabianhjr:matrix.orgFabián Heredia * plus a DDoS since yesterday22:38:13
@emilazy:matrix.orgemilywhat do we think about https://github.com/NixOS/nixpkgs/pull/347601, give it a day or just merge now?23:02:02
@emilazy:matrix.orgemilywe should probably poke channels once we merge the Tor Browser etc. backports23:02:15
@emilazy:matrix.orgemilyso I'm inclined to slap the warning on now23:02:19
@emilazy:matrix.orgemilyand consider removal if they don't move fast23:02:27
@emilazy:matrix.orgemilymaking the judgement call to merge, since it's an actively-exploited RCE23:08:03
@emilazy:matrix.orgemily librewolf{,-bin} had update PRs from 3 weeks ago that nobody acted on 23:12:51
@emilazy:matrix.orgemilythankfully not security23:13:16
@fabianhjr:matrix.orgFabián Heredia
In reply to @fabianhjr:matrix.org
https://x.com/vxunderground/status/1844122743727673366

Allegedly web.archive.org compromised

Update: vx-underground claims data breach impacting user data

https://x.com/vxunderground/status/1844158531210973555

23:42:58
@fabianhjr:matrix.orgFabián Herediaalso lol if true on the motivation of the DDoS. XD23:44:28
@emilazy:matrix.orgemilyI finished all the merges and backports of the Firefoxes (that we know of)23:57:36
@emilazy:matrix.orgemilycan someone poke the unstable and 24.05 channel evals?23:57:41
10 Oct 2024
@tomberek:matrix.orgtomberek joined the room.00:00:14
@fabianhjr:matrix.orgFabián Herediarelease-24.05 evaled 2hrs ago00:04:49
@fabianhjr:matrix.orgFabián Herediatrunk an hour ago, trunk-combined 4h ago00:05:13
@emilazy:matrix.orgemilyyeah00:05:38
@emilazy:matrix.orgemilybut we probably want to get Tor Browser fixes out to users ASAP00:05:44
@emilazy:matrix.orgemilyhexa bumped the channel when doing the Firefox PRs originally00:05:52
@emilazy:matrix.orgemilya Tor Browser RCE is kind of worst-case.00:06:13
@fabianhjr:matrix.orgFabián Herediahow long ago was the tor bump merged?00:06:52
@fabianhjr:matrix.orgFabián Herediaseems like 24.05 is only doing the tests and might advance soonish00:07:10
@emilazy:matrix.orgemilythe most recent one was librewolf 24.05 backport 9 minutes ago. most recent for master was exactly 1hr ago00:08:08
@emilazy:matrix.orgemilylet me check the commit trunk is evaluating00:08:28
@emilazy:matrix.orgemilyuh00:08:45

Show newer messages


Back to Room ListRoom Version: 9