!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

758 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
18 Jun 2021
@Las:matrix.orgLas * I don't think there is any other solution18:37:10
@Las:matrix.orgLasit's just used like a normal library now18:37:19
@hexa:lossy.networkhexamight be true, I didn't have time to check18:37:48
@hexa:lossy.networkhexahave to grab some food before the supermarkets close now18:38:03
@Las:matrix.orgLas I made a PR BTW 18:39:01
@Las:matrix.orgLasUntested since I don't use connman18:39:07
@hexa:lossy.networkhexarequested two reviewers that previously did reviews/changes19:27:07
19 Jun 2021
@thecannon:matrix.orgCannon joined the room.00:19:14
@ncfavier:matrix.orgnf joined the room.06:47:24
@hexa:lossy.networkhexacrossposting here: https://github.com/NixOS/nixpkgs/pull/12745313:21:53
@hexa:lossy.networkhexareintroducing certifi with a 2019 version isn't a great idea, but it apparently is required for nixops to continue working13:22:26
@hexa:lossy.networkhexa I insist that it should be marked with knownVulnerablities and added a commit to that end, so that if it should go in, the problem would be glaringly obvious to any user. 13:23:02
@thecannon:matrix.orgCannon changed their display name from NixCannon to Cannon.15:51:54
@thecannon:matrix.orgCannon changed their profile picture.15:53:06
@thecannon:matrix.orgCannon left the room.16:14:01
@putch4r:matrix.orgputchar joined the room.17:16:08
@sandro:supersandro.deSandroWhy is NixOS/nixops-committers not a real team?18:27:20
@hexa:lossy.networkhexanot really a security related question, is it?18:29:08
@sandro:supersandro.deSandroI wanted to assign them to the PR above18:35:52
@hexa:lossy.networkhexatalk to one of the project owners then, domen, zimbatm18:44:26
20 Jun 2021
@leo:gaspard.ninjaEkleogmeh, can anyone describe me an actual threat model for shipping an expirated certificate store?18:58:09
@leo:gaspard.ninjaEkleogI mean we definitely shouldn't do it if we can avoid it, but IMO it's not at all worth a knownVulnerabilities18:58:34
@leo:gaspard.ninjaEkleog (haven't investigated this specific case though, just the text in knownVulnerabilities in the PR above) 18:59:22
@leo:gaspard.ninjaEkleogand using knownVulnerabilities too often makes people much more used to working around it so IMO unless there's another motivation not listed yet, adding knownVulnerabilities in this specific case would be a net negative for security for NixOS19:01:29
@leo:gaspard.ninjaEkleog(commented on the PR with more details so the conversation is actually logged somewhere)19:09:00
@hexa:lossy.networkhexaI don't think it's a good to eval at every step whether the mozilla trust store does a revert here and there19:12:16
@hexa:lossy.networkhexathere won't be any security bulletins about this19:12:30
@hexa:lossy.networkhexathe abstract threat model would be a reverted certificate gets accepted, because the revert happened between 2019..today19:13:14
@hexa:lossy.networkhexa * there likely won't be any security bulletins about this19:16:23
@hexa:lossy.networkhexa * there likely won't be any security bulletins about this, certainly no CVE19:16:33

Show newer messages


Back to Room ListRoom Version: 6