andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security
danderson has joined #nixos-security
rajivr has joined #nixos-security
<ajs124> way too tempted to paste one of the relevant strings and see who disconnects
<IdleBot_c2ca5d90> ajs124: as an advertisement for ii, where the _view_ can crash, but the logs still keep being written?
<IdleBot_c2ca5d90> Properly used OS isolation primitives, such as processes, certainly add value both for security and for stability… (yes, I am writing this through ii)
<ajs124> No, just because. My own IRC setup actually involves node.js and python, so I can't really judge people there.
cole-h has quit [Ping timeout: 272 seconds]
hexa- has quit [Quit: WeeChat 2.9]
hexa- has joined #nixos-security
justanotheruser has joined #nixos-security
hexa- has quit [*.net *.split]
tokudan has quit [*.net *.split]
alexbakker has quit [*.net *.split]
energizer has quit [*.net *.split]
IdleBot_c2ca5d90 has quit [*.net *.split]
alexbakker has joined #nixos-security
tokudan has joined #nixos-security
hexa- has joined #nixos-security
energizer has joined #nixos-security
IdleBot_c2ca5d90 has joined #nixos-security
hexa- has quit [Max SendQ exceeded]
hexa- has joined #nixos-security
bbigras has quit [Ping timeout: 260 seconds]
kalbasit[m] has quit [Ping timeout: 240 seconds]
julianst[m] has quit [Ping timeout: 240 seconds]
thefloweringash has quit [Ping timeout: 244 seconds]
danielrf[m] has quit [Ping timeout: 260 seconds]
colemickens has quit [Ping timeout: 260 seconds]
aanderse has quit [Ping timeout: 240 seconds]
immae has quit [Ping timeout: 240 seconds]
Yakulu[m] has quit [Ping timeout: 268 seconds]
Ox4A6F has quit [Ping timeout: 268 seconds]
nh2[m] has quit [Ping timeout: 240 seconds]
cemguresci[m] has quit [Ping timeout: 265 seconds]
bbigras has joined #nixos-security
danielrf[m] has joined #nixos-security
colemickens has joined #nixos-security
thefloweringash has joined #nixos-security
kalbasit[m] has joined #nixos-security
julianst[m] has joined #nixos-security
cemguresci[m] has joined #nixos-security
aanderse has joined #nixos-security
immae has joined #nixos-security
Ox4A6F has joined #nixos-security
Yakulu[m] has joined #nixos-security
nh2[m] has joined #nixos-security
danderson has quit [Remote host closed the connection]
danderson has joined #nixos-security
cole-h has joined #nixos-security
<eyJhb> ajs124: Dooo it! :D
cole-h has quit [Ping timeout: 256 seconds]
c74d has left #nixos-security [#nixos-security]
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
rosariopulella[m has joined #nixos-security
SmeefKO has joined #nixos-security
SmeefKO has quit [Connection closed]
kamelosoXf has joined #nixos-security
<kamelosoXf> /!\ this channel has moved to ##hamradio /!\
<lassulus> I doubt that
kamelosoXf has quit [Remote host closed the connection]
Raito_BezariusAX has joined #nixos-security
<Raito_BezariusAX> /!\ this channel has moved to #nyymit /!\
trobothamRr has joined #nixos-security
<trobothamRr> /!\ this channel has moved to #nyymit /!\
ExaetamH has joined #nixos-security
<ExaetamH> /!\ this channel has moved to #nyymit /!\
jorrakayvM has joined #nixos-security
ExaetamH has quit [Remote host closed the connection]
<jorrakayvM> /!\ this channel has moved to #nyymit /!\
trobothamRr has quit [Remote host closed the connection]
Raito_BezariusAX has quit [Remote host closed the connection]
jorrakayvM has quit [Remote host closed the connection]
mlhess has joined #nixos-security
<mlhess> /!\ this channel has moved to #nyymit /!\
mlhess has quit [Remote host closed the connection]
Dworf has joined #nixos-security
<Dworf> /!\ this channel has moved to #nyymit /!\
Dworf has quit [Remote host closed the connection]
DarkMukkeOA has joined #nixos-security
DarkMukkeOA has quit [Remote host closed the connection]
<supersandro2000> gchristensen: can we do something about this?
<raboof> it's all over freenode...
<supersandro2000> noticed that now too
<{^_^}> facebook/zstd#1644 (by chungy, 1 year ago, merged): [programs] set chmod 600 after opening destination file
<hexa-> It was discovered that zstd, a compression utility, temporarily
<hexa-> exposed a world-readable version of its input even if the original
<hexa-> file had restrictive permissions.
<gchristensen> oh GOD
<eyJhb> Is there any CVE/patch for Screen yet?
<hexa-> there is tmux, if that helps :p
<qyliss> hexa-: IT STILL DOES
<qyliss> just for less time
<eyJhb> I don's use screen that much, but a patch would show where the actual fault is, and allow fer maybe better exploitation
<eyJhb> Does tmux crash?
<hexa-> qyliss: yep
<hexa-> eyJhb: I don't believe so
<hexa-> I don't see any activity over here https://git.savannah.gnu.org/cgit/screen.git
<eyJhb> Same....
<eyJhb> So I have two things to do after exam, look at this, and play Minecraft. Yay
<hexa-> no fix yet
<eyJhb> Uhh, nice :)
<hexa-> qyliss: oh boy, that issue is from 2019 and only just got a CVE
<eyJhb> Thanks hexa- :)
<hexa-> so we're good
<hexa-> I only just noticed it, because debian sent out an advisory
<eyJhb> How does the -security part of NixOS work? Just a lot of, hopefully we see all the security related things? Or is there a better process? :)
<eyJhb> ie. any automation?
lassulus has quit [Quit: WeeChat 2.9]
lassulus has joined #nixos-security
Reventlov has joined #nixos-security
<ajs124> ckauhaus: has some automation to open issues for CVEs, but handling/fixing them seems largely manual.
<ajs124> eyJhb: ^
rajivr has quit [Quit: Connection closed for inactivity]
cole-h has joined #nixos-security
red[evilred] has joined #nixos-security
<red[evilred]> Slightly off-topic but not really...
<red[evilred]> has anyone built something like a NixOS configuration for a VM-based browser
<red[evilred]> ie, have the browser run with minimal OS underneath
<gchristensen> maybe tito
<red[evilred]> (as a side-comment, I just rented hardware in a colo so I need to become intimately aquianted with how NixOS works with headless virtual machines too)
<red[evilred]> is tito a person or a project?
<red[evilred]> sorry - don't recognize the name
<gchristensen> person
<Ox4A6F> Do we have people on this list? https://oss-security.openwall.org/wiki/mailing-lists/distros
<gchristensen> not acting in the capacity of NixOS
<IdleBot_c2ca5d90> You want specifically VM? I have some things for running Firefox in an nsjail (with pretty little inside, except bind-mounted store)
lejonet has quit [Ping timeout: 260 seconds]
red[evilred] has quit [Quit: Idle timeout reached: 10800s]