NixOS Marketing | 260 Members | |
| NixOS website + marketing team: https://nixos.org/community/teams/marketing.html | 58 Servers |
| Sender | Message | Time |
|---|---|---|
| 27 Nov 2024 | ||
| Hi! I was redirected here to discuss things. I've made some PRs, some merged, some stalled, some pending, some closed. I'm happy to follow process, but I'd also like to be able to productively use my time and Github issues seems like a perfectly reasonable way of working out in the open (and discoverability for Matrix is suboptimal for discussion and decisonmaking when compared with forge tooling). The PRs in question I'd like feedback on on pushing forward:
Thanks! | 01:26:00 | |
Download image.png | 01:38:26 | |
| security is already down here | 01:38:30 | |
| we already get lots of useful reports | 01:38:34 | |
| implementing well-known security is what is currently missing | 01:40:16 | |
| https://en.wikipedia.org/wiki/Security.txt | 01:41:03 | |
| https://datatracker.ietf.org/doc/html/rfc9116 | 01:41:15 | |
| you kinda went in without a concrete plan | 01:41:41 | |
| prior art was linked early on and not acted upon | 01:42:01 | |
| I was asking for a plan, and the information you just gave me--which would've been helpful to have on a comment on that PR--is a big help. Thank you! | 01:42:05 | |
| There's another philosophical question which is: would it be a good idea to put security right on the navbar? My personal bet is yes, because:
| 01:45:33 | |
Uh … what? | 01:46:31 | |
| I don't mind whether it is down there or up there, but the start page mentions security a bit too much | 01:47:15 | |
Download image.png | 01:47:18 | |
| moving it up would improve the tab order | 01:47:36 | |
| Sure, and we could probably stand to ditch a tab or two as well...it is a little busy. | 01:48:02 | |
| (and again, I'm not wed to this, just kicking around an idea) | 01:48:19 | |
| Hmmm, at some point we maybe should consider some kind of drop down menu for the main nav, otherwise this would clog up a lot | 01:49:01 | |
Download image.png | 01:49:27 | |
| so that's what we have right now | 01:49:31 | |
| Yup | 01:51:25 | |
| 01:52:07 | |
| and like, I know folks put effort into these pages at one time or another, so I don't want to just bulldoze that | 01:52:29 | |
| but uh, there's some prime real estate that could probably use redevelopment | 01:52:42 | |
| back to the security thing, my issues with the current team page are basically:
Of these, the easiest fix is the first--the second requires a bit more coordination and the third would be a big change over on the security team I think. So, I was just trying to pull on the first thread mainly. | 01:59:28 | |
| (and yes, I know that the "if you want to report..." does technically exist. never underestimate the ability of users to do the wrong thing when presented with something that isn't a flowchart with blinking lights and monosyllables. I include myself in that population.) | 02:00:44 | |
| There is trade-offs in reporting. We support encrypted reports through GPG and we just won't manage a shared key. We could make more use of the security@ alias for everything else though. | 02:01:26 | |
| I was thinking of a very specific workflow:
I'm not sure how that would interact with the GPG thing, but I'm also not really sure that GPG is as important as a redundant and auditable comms. | 02:05:02 | |
| ("normal channels" here being GPG email or what have you) | 02:05:39 | |
| I'm not sure that an audit trail is high on our list of priorities, and we generously cc reports between team members either way | 02:06:16 | |