!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

363 Members
Discussions around Security | Triaging happens in #security:nixos.org126 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
3 Oct 2024
@elvishjerricco:matrix.orgElvishJerriccothough I think lanzaboote fills that condition22:35:26
@raitobezarius:matrix.orgraitobezariusThere's a PR that fixes the measurements which just need a rebase, yes22:36:26
@raitobezarius:matrix.orgraitobezariusI may have spoons at some point22:36:37
4 Oct 2024
@ajcxz0:matrix.org@ajcxz0:matrix.org left the room.01:00:46
5 Oct 2024
@elvishjerricco:matrix.orgElvishJerricco Jan Tojnar: Hey, did you have anything worth sharing on the luks gnome keyring thing? I know you didn't get very far but I'm bored and want to take a look into it tonight :P 01:16:22
@emilazy:matrix.orgemilyoh, I never reached out to Arch about that… :(01:16:43
@elvishjerricco:matrix.orgElvishJerricco ok, so the pam_gdm auth module gets the key out of the keyring and sets the authtok. Then pam_gnome_keyring reads that, forks off the daemon, which switches to your user, and the authtok is piped in to child from parent. Or if the daemon was already running, it just sends the authtok over the control socket. 03:16:40
@elvishjerricco:matrix.orgElvishJerriccoso there is definitely at least a moment where the password is being piped to a process owned by your user03:16:56
@emilazy:matrix.orgemilydid you find jtojnar's WIP NixOS test thing?03:17:00
@emilazy:matrix.orgemilyhttps://gist.github.com/jtojnar/d1c98d5d803cee3998f68e2e1761c8f803:17:25
@elvishjerricco:matrix.orgElvishJerriccoI didn't. Figured I'd rather get familiar with how it works before testing anything out03:17:28
@emilazy:matrix.orgemily(doesn't work, but maybe it's useful to you)03:17:31
@elvishjerricco:matrix.orgElvishJerriccothanks03:17:53
@emilazy:matrix.orgemilyrelevant comment about timing / multiple sessions https://matrix.to/#/!NBBFPbiuttRgTqbrcY:nixos.org/$-nf3vPAiCozFLiNCXkzyvCjEZ9W57MT7dOBOLu9ee_U?via=nixos.org&via=matrix.org&via=nixos.dev03:18:05
@emilazy:matrix.orgemilyand pointer to earlier discussion from there03:18:10
@elvishjerricco:matrix.orgElvishJerricco yea, so my guess is that there is some vulnerability here, that's probably quite difficult to take advantage of 03:18:26
@elvishjerricco:matrix.orgElvishJerricco part of it depends on when exactly pam_sm_open_session happens. 03:21:29
@elvishjerricco:matrix.orgElvishJerriccoBut I think you can make that not matter by having a non-gdm session open before gdm-autologin happens03:27:53
@elvishjerricco:matrix.orgElvishJerriccowhich is probably plausible with systemd user lingering03:28:04
@elvishjerricco:matrix.orgElvishJerriccooh that was easier than I thought03:55:46
@elvishjerricco:matrix.orgElvishJerricco emily: you around? 03:55:49
@magic_rb:matrix.redalder.orgmagic_rb changed their profile picture.22:18:06
6 Oct 2024
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/346797 could probably use more opinions/discussion (for once I lean slightly against)12:47:22
@sofo:matrix.org@sofo:matrix.org left the room.15:28:06
@winter:catgirl.cloudWinteryeah i don't like this... i'll write up something17:53:22
@emilazy:matrix.orgemilyi think we have decent consensus to not mark it right now at this point17:57:03
7 Oct 2024
@lehmanator:tchncs.deSam Lehman changed their profile picture.14:24:09
9 Oct 2024
@nickcao:nichi.coNick Caofirefox RCE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/14:12:28
@Valodim:stratum0.orgValodimwhew14:20:57

Show newer messages


Back to Room ListRoom Version: 9