| 21 May 2021 |
| Josh joined the room. | 20:06:58 |
| toonn joined the room. | 20:15:08 |
toonn | Ah, this is about general security/crypto, not specifically NixOS security updates? | 21:42:18 |
Synthetica | No, it's about NixOS security updates if I'm correct | 21:43:19 |
hexa | Yes, the security of NixOS/nixpkgs | 21:53:49 |
toonn | Oh, cool anyway. Was fooled by the blockchain memes. | 21:53:52 |
hexa | sorry :) | 21:54:02 |
| maralorn left the room. | 21:54:41 |
kevincox | It is a probably good idea to decide on a topic and post it. | 23:03:41 |
hexa | do you have a proposal? | 23:06:10 |
hexa | I don't think linking vulnerability roundup issues is really valuable | 23:06:38 |
kevincox | Well I barely no what this room is about. Discussing security patches? Announcing security patches? | 23:07:04 |
kevincox | Discussions about security posture in general? All of the above? | 23:07:30 |
hexa | triage | 23:07:31 |
hexa | triage of security issues in nixpkgs | 23:08:02 |
hexa | coordination | 23:08:07 |
kevincox | "Discussion around triage and coordination of security issues in nixpkgs."
? | 23:08:40 |
kevincox | Or just drop the "Discussion around" bit as it is redundant. | 23:09:28 |
hexa | yup, something like that would be good | 23:09:49 |
kevincox | I don't think I have permission and grahamc seems really busy but maybe we can get that set, or get some more mods when things cool down. | 23:11:10 |
| @grahamc:nixos.orgchanged room power levels. | 23:11:27 |
| hexa set the room topic to "Coordination and triage of security issues in nixpkgs". | 23:11:54 |
hexa | https://github.com/NixOS/nixpkgs/pull/123941 | 23:21:43 |
hexa | The homeserver.signing.key is currently world-readable 😢 | 23:22:08 |
hexa | We plan to get this merged and backported tomorrow-ish. | 23:22:45 |
hexa | * The homeserver.signing.key and media are currently world-readable 😢 | 23:39:07 |
hexa | * The homeserver.signing.key and media directory are currently world-readable 😢 | 23:39:28 |
hexa | Looks like upstream packaging suffers from a similar issue: https://github.com/matrix-org/synapse/issues/10008 | 23:52:56 |
hexa | https://github.com/matrix-org/synapse/issues/1528 | 23:53:15 |
andi- | In practice it isn't really exploitable as the folder is not world readable but that isn't a reason not to do it properly | 23:54:00 |