!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

723 Members
Coordination and triage of security issues in nixpkgs219 Servers

Load older messages


SenderMessageTime
17 Dec 2023
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their profile picture.04:46:28
@hexa:lossy.networkhexahttps://groups.google.com/g/golang-announce/c/-n5WqVC18LQ22:13:51
@hexa:lossy.networkhexarelease planned for tomorrow22:14:13
18 Dec 2023
@sandro:supersandro.deSandro That's an out of tree module, so patch-galore.... 13:01:55
@vengmark2:matrix.org@vengmark2:matrix.org joined the room.20:19:35
@vengmark2:matrix.org@vengmark2:matrix.org

Hi, I hope this is the appropriate channel to mention the Terrapin Attack. It seems the relevant paragraphs are these:

If you feel uncomfortable waiting for your SSH implementation to provide a patch, you can workaround this vulnerability by temporarily disabling the affected chacha20-poly1305@openssh.com and -etm@openssh.com MAC algorithms in the configuration of your SSH server (or client), and use unaffected algorithms like AES-GCM instead.

Fair word of warning: If configured improperly or your client does not support these algorithms, you may loose access to your server.

Maybe we could remove references to those algos?

20:28:17
@k900:0upti.meK900 #NixOS Security Discussion 20:29:41
@vengmark2:matrix.org@vengmark2:matrix.org left the room.20:31:20
19 Dec 2023
@jdemille:tchncs.deJulia DeMille joined the room.02:04:02
20 Dec 2023
@bb_wtt.jpeg:matrix.orgbb_wtt.jpeg joined the room.11:58:48
@julian:nekover.se@julian:nekover.se changed their display name from June to June 📞 5863.23:32:03
21 Dec 2023
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) changed their display name from fernsehmuell to fernsehmuell (DECT 3376 (fern)).13:00:47
@julian:nekover.se@julian:nekover.se changed their display name from June 📞 5863 to June.14:12:41
@tammi:greyseal.euTammi (ey/em) joined the room.18:30:03
22 Dec 2023
@medliviz:matrix.orgmedliviz joined the room.12:31:42
@-jb:matrix.org@-jb:matrix.org changed their profile picture.15:13:42
@lily:lily.flowersLily FosterI'm still waiting on builds to finish and I gotta step away from the computer for a few hours, but I've opened https://github.com/NixOS/nixpkgs/pull/276074 for a gstreamer security bump15:58:48
@blitz:chat.x86.lolblitz joined the room.16:12:48
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion (TZ: UTC-5) to Insurgo aka tlaurion (Holdays! Expect delays in answers!).20:31:15
23 Dec 2023
@julian:nekover.se@julian:nekover.se changed their display name from June to June 📞 5863.01:54:45
@raitobezarius:matrix.orgraitobezarius changed their display name from raitobezarius to raitobezarius (DECT 2128).22:22:05
24 Dec 2023
@tammi:greyseal.euTammi (ey/em) changed their display name from Tammi (she/ey) to Tammi (ey/em).14:03:45
@tammi:greyseal.euTammi (ey/em) changed their profile picture.14:03:51
25 Dec 2023
@lab-cat:ag-link.xyz@lab-cat:ag-link.xyz changed their display name from lab-cat to lab-cat (DECT 3655).00:02:52
@patryk4815:matrix.orgpatryk4815 joined the room.01:37:59
@julian:nekover.se@julian:nekover.se changed their display name from June 📞 5863 to June [@37C3 -> DECT 5863].03:32:27
@julian:nekover.se@julian:nekover.se changed their display name from June [@37C3 -> DECT 5863] to June 📞 5863.03:33:15
@julienmalka:matrix.orgJulien changed their display name from Julien to Julien - DECT 4575.20:03:34
26 Dec 2023
@sugi:matrix.besaid.desugi changed their display name from sugi to sugi 📞8658.00:57:31
@tim:stratum0.orgdadada changed their display name from dadada to dadada (7562).17:34:34

Show newer messages


Back to Room ListRoom Version: 6