gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
Synthetica has quit [Quit: Connection closed for inactivity]
timokau[m] has quit [Remote host closed the connection]
timokau[m] has joined #nixos-security
n_db has quit [Remote host closed the connection]
pie_ has quit [Ping timeout: 258 seconds]
pie_ has joined #nixos-security
pie___ has joined #nixos-security
pie_ has quit [Ping timeout: 250 seconds]
<pie___> random xpost about firefox/thunderbird updates https://security.archlinux.org/ASA-201905-8
<flokli> uff
Synthetica has joined #nixos-security
<pie___> wonder if we could/should do something like SSL Observatory but for build reproductions
<pie___> (basically a database of input - output hashes?)
<andi-> What would that serve us? We have r13y.com that is alreayd a step in that direction. What that would be is basically a database that takes all the narinfo files and puts them in a database?
<ekleog> if we have a third “input-output correspondance signature” field (and maybe a fourth “signer” field) it'd make something really useful IMO
<ekleog> for the “distrust hydra” long-term objective
<ekleog> now, it's not at all a priority IMO
<pie___> dunno how to prevent malicious spam tho
<ekleog> not sure spam would be a big issue, with no amplification factor
<pie___> how do you differentiate valid and invalid data
<pie___> ok thats kind of orthogonal
<ekleog> yup
<ekleog> one will be assumed to trust only known signers
<ekleog> if someone downloads the data and trusts everyone, it's their problem
<pie___> i figured something somethign web of trust but does that really work
pie___ has quit [Ping timeout: 272 seconds]
justanotheruser has quit [Ping timeout: 272 seconds]
pie_ has joined #nixos-security
justanotheruser has joined #nixos-security
justanotheruser is now known as Mr_Notheruser
Mr_Notheruser has quit [Ping timeout: 252 seconds]
justanotheruser has joined #nixos-security
<Foxboron> pie__: My master thesis is about publishing rebuild submission of debian packages on a transparency log
<Foxboron> ekleogs approach is a bit similar to what we discussed at the reproducible builds summit regarding trusting rebuilders. Leave trust up to the user, but distribute a initial list.
<pie_> Foxboron, oh huh sounds hard
<pie_> is the thesis done yet?
<Foxboron> Delivery on saturday :p
<pie_> good luck \o/ :D
<Foxboron> thanks! Interesting topic :)
<Foxboron> Going to be playing a lot with these concepts in relation to Arch Linux when i'm done with this
justanotheruser has quit [Read error: Connection reset by peer]
Synthetica has quit [Quit: Connection closed for inactivity]