!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

716 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
3 Feb 2024
@networkexception:chat.upi.li@networkexception:chat.upi.li changed their profile picture.11:53:46
@hexa:lossy.networkhexahttps://anydesk.com/en/public-statement14:25:06
@hexa:lossy.networkhexalatest version uses a new codesigning cert14:25:57
@hexa:lossy.networkhexaimage.png
Download image.png
14:27:03
@hexa:lossy.networkhexaI don't think they sign linux tarballs 🙂 14:27:11
@tgerbet:matrix.orgtgerbetNope they do not, at least not for what's used in nixpkgs package14:28:18
@tgerbet:matrix.orgtgerbetBut the package pin did not change in the last 5 months so we are probably fine (unless they were already compromised)14:30:31
@k900:0upti.meK900My kingdom for remote desktop software that doesn't suck 14:33:54
@hexa:lossy.networkhexawayland support when14:34:08
@mkg20001:mkg20001.iomkg20001
In reply to @hexa:lossy.network
wayland support when
rustdesk has that
15:01:06
@mclutzifer:matrix.org@mclutzifer:matrix.org joined the room.16:08:01
@pxc:gnulinux.club@pxc:gnulinux.club 17:24:52
@pxc:gnulinux.club@pxc:gnulinux.club left the room.17:40:01
@k900:0upti.meK900
In reply to @mkg20001:mkg20001.io
rustdesk has that
Have you seen Rustdesk
18:18:14
@archhost:matrix.org@archhost:matrix.org left the room.23:02:07
4 Feb 2024
@soispha:vhack.euBenedikt joined the room.07:45:18
@bytebandit:tac.lolDerivationDingus
In reply to @k900:0upti.me
Have you seen Rustdesk
I have deployed it before. It has been over a year though. So, I haven't used it since wayland support was added but I did really like it. I thought deploying wasn't too difficult, but it definitely had rough edges. Some of it was out of date docs but I definitely ran into some bugs as well.
For example: I ended up building it myself with my own domain hard-coded in, overwriting the default public one, because I couldn't get any of the supported ways to work consistently.
08:15:10
@vcunat:matrix.orgvcunatI'd suggest moving the discussion elsewhere. This channel should be just security triage.08:18:41
@bytebandit:tac.lolDerivationDingus
In reply to @vcunat:matrix.org
I'd suggest moving the discussion elsewhere. This channel should be just security triage.
Oof, my apologies. I thought I was in a different room.
08:19:15
@vcunat:matrix.orgvcunat * I'd suggest moving the discussion elsewhere (and e.g. linking from here). This channel should be just security triage.08:19:19
@vcunat:matrix.orgvcunat * I'd suggest moving the discussion elsewhere (and e.g. link it from here). This channel should be just security triage.08:19:24
@k900:0upti.meK900https://www.openwall.com/lists/oss-security/2024/01/30/709:18:33
@k900:0upti.meK900OH GOD09:18:36
@k900:0upti.meK900I finally read the writeup09:20:20
@k900:0upti.meK900Ugh wrong room09:20:32
@bjth:matrix.orgBryan Honof changed their profile picture.11:31:31
@vcunat:matrix.orgvcunatgnupg: some kind of 23.11 backport is needed? https://github.com/NixOS/nixpkgs/pull/284778#issuecomment-192575726214:15:28
@jtojnar:matrix.orgJan Tojnarlibxml2 again: https://github.com/NixOS/nixpkgs/pull/28630014:52:16
@jtojnar:matrix.orgJan Tojnar * UAF in libxml2 again: https://github.com/NixOS/nixpkgs/pull/28630014:52:36
@tgerbet:matrix.orgtgerbet
In reply to @vcunat:matrix.org
gnupg: some kind of 23.11 backport is needed?
https://github.com/NixOS/nixpkgs/pull/284778#issuecomment-1925757262
Cherry-picks done in https://github.com/NixOS/nixpkgs/pull/286302
14:53:55

Show newer messages


Back to Room ListRoom Version: 6