21 May 2021 |
kevincox | Or just drop the "Discussion around" bit as it is redundant. | 23:09:28 |
hexa | yup, something like that would be good | 23:09:49 |
kevincox | I don't think I have permission and grahamc seems really busy but maybe we can get that set, or get some more mods when things cool down. | 23:11:10 |
| @grahamc:nixos.orgchanged room power levels. | 23:11:27 |
| hexa set the room topic to "Coordination and triage of security issues in nixpkgs". | 23:11:54 |
hexa | https://github.com/NixOS/nixpkgs/pull/123941 | 23:21:43 |
hexa | The homeserver.signing.key is currently world-readable 😢 | 23:22:08 |
hexa | We plan to get this merged and backported tomorrow-ish. | 23:22:45 |
hexa | * The homeserver.signing.key and media are currently world-readable 😢 | 23:39:07 |
hexa | * The homeserver.signing.key and media directory are currently world-readable 😢 | 23:39:28 |
hexa | Looks like upstream packaging suffers from a similar issue: https://github.com/matrix-org/synapse/issues/10008 | 23:52:56 |
hexa | https://github.com/matrix-org/synapse/issues/1528 | 23:53:15 |
andi- | In practice it isn't really exploitable as the folder is not world readable but that isn't a reason not to do it properly | 23:54:00 |
andi- | At least for our setup. No idea about theirs | 23:54:39 |
hexa | yup, the statedirectory is 0700 | 23:56:53 |
hexa | so not security strictly, but hygiene | 23:57:09 |
22 May 2021 |
| globin joined the room. | 00:05:30 |
| Room Avatar Renderer. | 00:32:52 |
andi- | samueldr: so what phrase do these symbols stand for? 4 letters... | 00:33:53 |
samueldr | andi | 00:34:05 |
samueldr | hexa | 00:34:29 |
hexa | why not hexa though? | 00:34:30 |
hexa | ahh, there it is | 00:34:35 |
samueldr | choose your poiso | 00:34:37 |
samueldr | * choose your poison | 00:34:39 |
hexa | choosing pois | 00:34:45 |
samueldr | fun fact: those are called grawlix | 00:34:57 |
andi- | Can I pick a swear word instead? | 00:35:04 |
samueldr | and it's here to represent what some think when thinking about CVEs and such! | 00:35:18 |
@grahamc:nixos.org | I've experimentally placed this in a Nix Teams subspace, let me know if this doesn't feel like a good fit. | 00:39:53 |