!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

759 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
27 Jun 2021
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm left the room.17:17:55
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm joined the room.17:49:57
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm left the room.19:28:16
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm joined the room.19:39:59
@andreas.schraegle:helsinki-systems.deajs124 Thanks for your work hexa!
And sorry I couldn't get around to looking at the dovecot change ris_. I'll try to my best to keep dovecot in a better state from 21.05 on, but I'm obviously thankful for any help.
21:04:22
@r_i_s:matrix.orgris_not a problem at all21:04:46
@r_i_s:matrix.orgris_i'm just happy whenever a package has nixos tests, makes me so much more confident working with unfamiliar packages21:06:05
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm left the room.22:11:35
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm joined the room.22:11:42
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm left the room.23:49:48
28 Jun 2021
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm joined the room.00:06:40
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm left the room.19:28:18
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm joined the room.19:28:21
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm left the room.20:03:35
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm joined the room.22:09:53
29 Jun 2021
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm left the room.03:50:40
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm joined the room.05:52:08
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/12717221:09:38
@hexa:lossy.networkhexafixes a long-standing exiv2 security issue, but needs backporting. I tried adapting the patches once and failed, I don't want to try again, so I slapped the backport label on it.21:10:12
@hexa:lossy.networkhexa0.27.3 is also what we have in 20.09, so in theory we could bump it there as well21:10:33
@hexa:lossy.networkhexain other news: 25h support for 20.09 left on my clock (CEST)21:10:57
30 Jun 2021
@mingovanburne:matrix.orgmingovanburne joined the room.03:53:18
1 Jul 2021
@kunrooted:matrix.orgkunrootedasked on FP Slack, will ask in here as well11:18:33
@kunrooted:matrix.orgkunrooted okay so let's assume we have Situation like this:
we have two users, Adam and Eve, while Adam has root access/is root himself. Can Eve 'infect' his /nix/store with malicious Code? Also, how one can tell which packages in /nix/store belong to who? I think that replacing a binary is indeed possible, but it requires root access, so it would def. be a Post exploitation thing. What other security nightmares can we face except the atomic Upgrades and possibilities of supply chain attacks when it comes to /nix/store itself? Really, how one can tell which user can use which package? Is there a way to do so? Can Eve in given Situation 'inject' malicious Code into Adam's /nix/store?
11:18:36
@synthetica:matrix.orgSyntheticaIf you have root you can basically do anything, so...11:19:23
@kunrooted:matrix.orgkunrootedAnd how can I tell which user has an Access to certain packages? 11:20:02
@balsoft:balsoft.rubalsoftNix store is a large cache11:20:11
@roosemberth:orbstheorem.chRoosThe nix store is world readable. 11:20:20
@balsoft:balsoft.rubalsoftEverybody has write access11:20:23
@balsoft:balsoft.rubalsoft* Everybody has read access11:20:26

Show newer messages


Back to Room ListRoom Version: 6