NixOS Marketing | 260 Members | |
| NixOS website + marketing team: https://nixos.org/community/teams/marketing.html | 57 Servers |
| Sender | Message | Time |
|---|---|---|
| 27 Nov 2024 | ||
| 01:52:07 | |
| and like, I know folks put effort into these pages at one time or another, so I don't want to just bulldoze that | 01:52:29 | |
| but uh, there's some prime real estate that could probably use redevelopment | 01:52:42 | |
| back to the security thing, my issues with the current team page are basically:
Of these, the easiest fix is the first--the second requires a bit more coordination and the third would be a big change over on the security team I think. So, I was just trying to pull on the first thread mainly. | 01:59:28 | |
| (and yes, I know that the "if you want to report..." does technically exist. never underestimate the ability of users to do the wrong thing when presented with something that isn't a flowchart with blinking lights and monosyllables. I include myself in that population.) | 02:00:44 | |
| There is trade-offs in reporting. We support encrypted reports through GPG and we just won't manage a shared key. We could make more use of the security@ alias for everything else though. | 02:01:26 | |
| I was thinking of a very specific workflow:
I'm not sure how that would interact with the GPG thing, but I'm also not really sure that GPG is as important as a redundant and auditable comms. | 02:05:02 | |
| ("normal channels" here being GPG email or what have you) | 02:05:39 | |
| I'm not sure that an audit trail is high on our list of priorities, and we generously cc reports between team members either way | 02:06:16 | |
| it is how we track whether a thing was actually replied to | 02:07:20 | |
| Wasn't one of the things from earlier this year folks not really knowing who was alerted when about 2.24 puckipedia thing? I don't have a lot of visibility into that, but audit logs of emails and touchpoints seem like they would've been helpful there when people were debugging later what went wrong. The thing about manual cc'ing is that it makes it's a manual process, and any manual process will get goofed up eventually--so, a mailing list or some other automated system would probably help. If I'm understanding you correctly, the biggest issue with a mailing list is the lack of PGP support for encrypted reports? Or did I misunderstand you? | 02:13:32 | |
| * Wasn't one of the things from earlier this year folks not really knowing who was alerted when about 2.24 puckipedia thing? I don't have a lot of visibility into that, but audit logs of emails and touchpoints seem like they would've been helpful there when people were debugging later what went wrong. The thing about manual cc'ing is that it makes ia manual process, and any manual process will get goofed up eventually--so, a mailing list or some other automated system would probably help. If I'm understanding you correctly, the biggest issue with a mailing list is the lack of PGP support for encrypted reports? Or did I misunderstand you? | 02:13:57 | |
| * Wasn't one of the things from earlier this year folks not really knowing who was alerted when about 2.24 puckipedia thing? I don't have a lot of visibility into that, but audit logs of emails and touchpoints seem like they would've been helpful there when people were debugging later what went wrong. The thing about manual cc'ing is that it makes a manual process, and any manual process will get goofed up eventually--so, a mailing list or some other automated system would probably help. If I'm understanding you correctly, the biggest issue with a mailing list is the lack of PGP support for encrypted reports? Or did I misunderstand you? | 02:14:05 | |
| a list adds complexity, it can be done, but it is not a must | 02:15:13 | |
| and if you asked puck she would probably tell you that these issues had nothing to do with the security team | 02:16:05 | |
| * and if you asked puck she would probably tell you that these issues had nothing to do with this security team | 02:16:09 | |
| ¯\_(ツ)_/¯ everybody sees a different part of the elephant lol | 02:17:00 | |
| And then another question...looking at the github, I see a label for "status:wait-for-upstream"...is that for "there's nothing we as packagers can do on this except wait for the package to fix it"? | 02:17:06 | |
| we did eventually package schleuder some time ago to look into an encrypted mailing list, but the priorities are just elsewhere right now | 02:17:19 | |
| yes, means "nothing" we can do downstream | 02:17:46 | |
| and schleuder would be...infra team, not security team, I'm guessing? | 02:18:08 | |
| * | 02:18:31 | |
| lol | 02:18:44 | |
| what're the current priorities re: infra? there's the ofborg decommissioning/move out of equinix, right? | 02:20:10 | |
| replacing all that we loose at EOY to some degree | 02:21:34 | |
| and long-term planning for a more sustainable future | 02:21:53 | |
| upgrade hydra for more parallel build capacity | 02:22:15 | |
| was there any progress/attempt at getting a little more time so y'all don't have to rush around the holidays? | 02:22:22 | |
| and get the s3 bucket size and cost under control | 02:22:38 | |
| (doing all this work with Christmas, New Years, and CCC coming up probably sucks and is stressful) | 02:22:49 | |