gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
ris has quit [Ping timeout: 264 seconds]
justanotheruser has joined #nixos-security
rajivr has joined #nixos-security
V has quit [Quit: V]
V has joined #nixos-security
justanotheruser has quit [Ping timeout: 272 seconds]
justanotheruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 240 seconds]
justanotheruser has joined #nixos-security
tilpner has joined #nixos-security
<pie_> <evanjs> SHA-1 algorithm for less than USD$50K. For this reason, we will be
<pie_> <evanjs> Yaaaaaay
<pie_> <evanjs> On another note: "It is now possible[1] to perform chosen-prefix attacks against the
<pie_> <evanjs> near-future release."
<pie_> <evanjs> disabling the "ssh-rsa" public key signature algorithm by default in a
<pie_> is this recent and related to gchristensen yesterday? https://sha-mbles.github.io/
<pie_> "We have computed the very first chosen-prefix collision for SHA-1. In a nutshell, this means a complete and practical break of the SHA-1 hash function, with dangerous practical implications if you are still using this hash function. To put it in another way: all attacks that are practical on MD5 are now also practical on SHA-1."
<qyliss> no that's from ages ago
<qyliss> The press coverage they link to is all from January
<pie_> oh
<gchristensen> that is from january, but today we we have a new and exciting vulnerability ready for someone to take point on :)
<pie_> i imagine
tldr32- has joined #nixos-security
tldr32 has quit [Ping timeout: 244 seconds]
ris has joined #nixos-security
rajivr has quit [Quit: Connection closed for inactivity]
justanotheruser has quit [Ping timeout: 260 seconds]
lejonet has quit [Ping timeout: 240 seconds]
justanotheruser has joined #nixos-security
__Sander__ has joined #nixos-security
anselmolsm has joined #nixos-security
lejonet has joined #nixos-security
__Sander__ has quit [Quit: Konversation terminated!]
justan0theruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 240 seconds]