!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

747 Members
Coordination and triage of security issues in nixpkgs228 Servers

Load older messages


SenderMessageTime
13 Jul 2021
@gilganix:matrix.org-(๐•‚eloฯ„)- changed their display name from -(NIX/โ„ฯ„)- to -(๐•‚eloฯ„)-.14:47:11
@gilganix:matrix.org-(๐•‚eloฯ„)- changed their profile picture.14:48:03
@gilganix:matrix.org-(๐•‚eloฯ„)- changed their profile picture.14:48:29
14 Jul 2021
@pepe:matrix.giugl.ioErPepone joined the room.09:19:44
15 Jul 2021
@devalot:matrix.orgPeter Jones joined the room.18:23:13
17 Jul 2021
@nixinator:nixos.devnixinator joined the room.00:50:35
@bifrost:matrix.orgBifrost Bot joined the room.16:50:46
18 Jul 2021
@tommy:matrix.252.noTommy joined the room.14:04:18
@aanderse:nixos.devaanderse joined the room.15:56:13
@aanderse:nixos.devaanderse changed their display name from Aaron Andersen to aanderse.15:58:45
@disrupt_the_flow:matrix.orgdisrupt_the_flow joined the room.20:21:43
19 Jul 2021
@cjbayliss:matrix.orgcjbayliss (they/them) changed their display name from cjbayliss to cjbayliss (they/them).03:10:54
@andi:kack.itandi- Has anyone run NixOS with noexec on / and /home while /run/current-system/sw and /nix/store are not nonexec? Does that work? I could imagine that user profiles would break even though they go through several layers of indirection and just point to /nix/store. 09:38:11
@linus.heckemann:matrix.mayflower.deLinux Hackerman andi-: /run shouldn't even need to be noexec, since it's just symlinks into the store. I think eyJhb uses noexec extensively, but isn't in here 09:43:16
@linus.heckemann:matrix.mayflower.deLinux Hackerman * andi-: /run could probably even be noexec too, since it's just symlinks into the store. I think eyJhb uses noexec extensively, but isn't in here 09:43:41
@linus.heckemann:matrix.mayflower.deLinux Hackermanjust not /run/wrappers09:43:44
@tnias:stratum0.orgtnias andi- : maybe this blogpost is relevant https://christine.website/blog/paranoid-nixos-2021-07-18 09:53:57
@andi:kack.itandi-
In reply to @tnias:stratum0.org
andi- : maybe this blogpost is relevant https://christine.website/blog/paranoid-nixos-2021-07-18
Read it and not to discredit the author but I don't see what is paranoid about that setup. It sounds like every other nixos machine I've seen for many years?
09:54:34
@andi:kack.itandi-If I were paranoid I'd probably also not trust tailscale but that is just me...09:55:24
@tnias:stratum0.orgtnias Paranoid is probably for clicks. Looks like a "normal" hardening guide. I just saw the noexec while skimming over it, thats why i posted it. 10:20:15
@disrupt_the_flow:matrix.orgdisrupt_the_flow
In reply to @tnias:stratum0.org
andi- : maybe this blogpost is relevant https://christine.website/blog/paranoid-nixos-2021-07-18
Not a bad read but far from a good guide.
10:46:04
@andi:kack.itandi-I like that someone is doing all the blogging that I'll never get to so I try to not criticise these posts too much :)10:47:04
@disrupt_the_flow:matrix.orgdisrupt_the_flow
In reply to @andi:kack.it
I like that someone is doing all the blogging that I'll never get to so I try to not criticise these posts too much :)
I don't agree. I believe criticism is a good thing. For example this specific blog. Says paranoid yet it uses systemd even if it used it's sandbox. Doesn't mention kernel hardening. Doesn't mention sandboxing such as bubblewrap.
10:50:18
@disrupt_the_flow:matrix.orgdisrupt_the_flowMentioning that those and more steps are missing with some good references is an acceptable and needed criticism.10:51:17
@andi:kack.itandi-
In reply to @disrupt_the_flow:matrix.org
I don't agree. I believe criticism is a good thing. For example this specific blog. Says paranoid yet it uses systemd even if it used it's sandbox. Doesn't mention kernel hardening. Doesn't mention sandboxing such as bubblewrap.
I should extend my reasoning: I also don't have the energy & motivation to get into discussing these blog posts. I have to do things that a) pay my bills & b) keep my interested in stuff as otherwise why am I alive?
This isn't the place where we should criticise the post. Perhaps the Lobsters comments? I don't know.
10:51:58
@andi:kack.itandi-
In reply to @disrupt_the_flow:matrix.org
I don't agree. I believe criticism is a good thing. For example this specific blog. Says paranoid yet it uses systemd even if it used it's sandbox. Doesn't mention kernel hardening. Doesn't mention sandboxing such as bubblewrap.
* I should extend my reasoning: I also don't have the energy & motivation to get into discussing these blog posts. I have to do things that a) pay my bills & b) keep me interested in stuff as otherwise why am I alive?
This isn't the place where we should criticise the post. Perhaps the Lobsters comments? I don't know.
10:52:16
@disrupt_the_flow:matrix.orgdisrupt_the_flowThat's one problem of Linux hardening guides I believe. I think Patrick(founder of whonix)has written a small article on that. If I'll find it I'll post it.10:52:38
@disrupt_the_flow:matrix.orgdisrupt_the_flow
In reply to @andi:kack.it
I should extend my reasoning: I also don't have the energy & motivation to get into discussing these blog posts. I have to do things that a) pay my bills & b) keep me interested in stuff as otherwise why am I alive?
This isn't the place where we should criticise the post. Perhaps the Lobsters comments? I don't know.
Yes I see. No I'm not really criticizing it or discussing it. Just saying my tldr opinion.
10:54:01
@disrupt_the_flow:matrix.orgdisrupt_the_flow andi- https://forums.whonix.org/t/the-problem-with-security-guides-and-how-we-can-fix-it/8563 11:03:54
@j-k:matrix.orgj-k joined the room.15:00:54

Show newer messages


Back to Room ListRoom Version: 6