!UUqahLbShAYkkrXmKs:matrix.org

DevOS

38 Members
Seeking help and geeking out together on https://github.com/divnix/devos & https://github.com/divnix/digga10 Servers

Load older messages


SenderMessageTime
17 Aug 2021
@vherrmann:shmerver.de@vherrmann:shmerver.de(Just like most setups have millions of security issues)15:37:57
@timdeh:matrix.org@timdeh:matrix.orgno I'm not15:38:10
@timdeh:matrix.org@timdeh:matrix.orgI'm saying if I changed anything, it would be a cache miss15:38:23
@timdeh:matrix.org@timdeh:matrix.org(for you)15:38:33
@timdeh:matrix.org@timdeh:matrix.orgso if I take package A from DevOS and secretly modify a line, and upload the result in cachix, and then you come and download package A from DevOS, you will not download my modified version, because my version has a different hash, which without the source, you can't even calculate.15:39:32
18 Aug 2021
@blaggacao:matrix.orgDavid Arnold (blaggacao)
In reply to @vherrmann:shmerver.de
So its opt-out and not opt-in
The config settings you refer to are opt-in. You will be explicitly asked by the cli if you trust them, and if you want to record that decision for future invokations.
00:02:55
@ultranix:matrix.orgultranixthat would be.. opt in04:41:28
@vherrmann:shmerver.de@vherrmann:shmerver.delol, i forgot that05:17:58
@vherrmann:shmerver.de@vherrmann:shmerver.de:S05:27:45
@timdeh:matrix.org@timdeh:matrix.orgno worries 😅17:28:54
19 Aug 2021
@gromzly:fullthese.website@gromzly:fullthese.website joined the room.14:40:59
@blaggacao:matrix.orgDavid Arnold (blaggacao) I made the nix-patch overlay use the latest version of nix & that also should save us for a while w.r.t. the follows patch.... 23:29:24
@blaggacao:matrix.orgDavid Arnold (blaggacao)https://github.com/divnix/digga/commit/2c5953f284690a89bfd472418141e3afea2dcf5d23:29:25
20 Aug 2021
@blaggacao:matrix.orgDavid Arnold (blaggacao)So do we abolish the all profile tests then?01:17:20
@blaggacao:matrix.orgDavid Arnold (blaggacao)[Poll] Agree 0. yes 1. maybe01:17:45
@blaggacao:matrix.orgDavid Arnold (blaggacao)😁01:17:48
@blaggacao:matrix.orgDavid Arnold (blaggacao)0. yes01:18:00
@gtrunsec:matrix.org@gtrunsec:matrix.org001:18:19
@blaggacao:matrix.orgDavid Arnold (blaggacao)(you see I'm completely neutral) 😂😎01:18:25
@yusdacra:nixos.devyusdacra1. maybe01:19:18
@gtrunsec:matrix.org@gtrunsec:matrix.orgExtending the custom test experience is what we need to do01:23:30
@danielphan.2003:matrix.org@danielphan.2003:matrix.org0. yes03:48:11
@kraftnix:matrix.org@kraftnix:matrix.org1. maybe11:25:41
@timdeh:matrix.org@timdeh:matrix.orgIt was my original intention to create some mechanism to replace it with something which pulls in a single profile into a test environment, to avoid potential conflicts. I'd rather see something like that 👍️12:39:38
@kraftnix:matrix.org@kraftnix:matrix.orgi continue to use the profiles tests for simple configs like my laptops but have disabled for all my servers which have much more complex configurations, and instead use the custom tests for those servers.15:32:21
@timdeh:matrix.org@timdeh:matrix.org yubikey finally works with agenix in a reasonable fashion 15:54:47
@kraftnix:matrix.org@kraftnix:matrix.orgniice, i had the nasty moment a week ago when i had to rekey 50 secrets 😬, took a while...15:55:33
@timdeh:matrix.org@timdeh:matrix.orghmm, it even asked for pin on rekey? I never had that problem, it was only decrypt that was the issue for me15:56:16
@kraftnix:matrix.org@kraftnix:matrix.orgalthough it looks like "once" still isnt supported 😥15:56:48
@timdeh:matrix.org@timdeh:matrix.orgThe only caveat (which I outlined in the updated instructions) is that to get it to be ergonomic a PIN policy of 'never' is needed until proper agent support is implemented somehow15:56:55

Show newer messages


Back to Room ListRoom Version: 6