!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

686 Members
Coordination and triage of security issues in nixpkgs215 Servers

Load older messages


SenderMessageTime
21 May 2021
@hexa:lossy.networkhexa * The homeserver.signing.key and media are currently world-readable 😢 23:39:07
@hexa:lossy.networkhexa * The homeserver.signing.key and media directory are currently world-readable 😢 23:39:28
@hexa:lossy.networkhexaLooks like upstream packaging suffers from a similar issue: https://github.com/matrix-org/synapse/issues/1000823:52:56
@hexa:lossy.networkhexahttps://github.com/matrix-org/synapse/issues/152823:53:15
@andi:kack.itandi-In practice it isn't really exploitable as the folder is not world readable but that isn't a reason not to do it properly 23:54:00
@andi:kack.itandi-At least for our setup. No idea about theirs23:54:39
@hexa:lossy.networkhexayup, the statedirectory is 070023:56:53
@hexa:lossy.networkhexaso not security strictly, but hygiene23:57:09
22 May 2021
@robin.gloster:matrix.mayflower.deglobin joined the room.00:05:30
Room Avatar Renderer.00:32:52
@andi:kack.itandi- samueldr: so what phrase do these symbols stand for? 4 letters... 00:33:53
@samueldr:matrix.orgsamueldrandi00:34:05
@samueldr:matrix.orgsamueldrhexa00:34:29
@hexa:lossy.networkhexawhy not hexa though?00:34:30
@hexa:lossy.networkhexaahh, there it is00:34:35
@samueldr:matrix.orgsamueldrchoose your poiso00:34:37
@samueldr:matrix.orgsamueldr * choose your poison00:34:39
@hexa:lossy.networkhexachoosing pois00:34:45
@samueldr:matrix.orgsamueldrfun fact: those are called grawlix00:34:57
@andi:kack.itandi-Can I pick a swear word instead?00:35:04
@samueldr:matrix.orgsamueldrand it's here to represent what some think when thinking about CVEs and such!00:35:18
@grahamc:nixos.org@grahamc:nixos.orgI've experimentally placed this in a Nix Teams subspace, let me know if this doesn't feel like a good fit.00:39:53
@stick:matrix.orgprusnak joined the room.07:41:11
@cleverca22:matrix.orgcleverca22 joined the room.12:39:04
@andi:kack.itandi- removed their profile picture.13:26:11
@andi:kack.itandi- set a profile picture.13:34:00
@ryantm:matrix.orgryantm joined the room.13:38:39
@FRidh:matrix.orgFRidh joined the room.15:02:23
@robert:funklause.dedotlambda joined the room.15:27:06
@dualinverter:matrix.orgdualinverter joined the room.16:12:27

Show newer messages


Back to Room ListRoom Version: 6