*** tmcpeak has quit IRC | 00:08 | |
*** bdpayne has quit IRC | 00:40 | |
openstackgerrit | KATO Tomoyuki proposed a change to openstack/security-doc: Add typographic convention for reader substitutions in examples https://review.openstack.org/110173 | 00:59 |
---|---|---|
*** bdpayne has joined #openstack-security | 02:11 | |
*** mxin has joined #openstack-security | 05:18 | |
*** bdpayne has quit IRC | 05:36 | |
*** mxin has quit IRC | 05:48 | |
*** voodookid has joined #openstack-security | 05:55 | |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/110212 | 06:04 |
*** voodookid has quit IRC | 06:13 | |
openstackgerrit | A change was merged to openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/110212 | 06:40 |
openstackgerrit | A change was merged to openstack/security-doc: Merge further chapters https://review.openstack.org/110084 | 07:20 |
openstackgerrit | A change was merged to openstack/security-doc: Move some sections one level up https://review.openstack.org/110114 | 07:58 |
*** bdpayne has joined #openstack-security | 09:35 | |
*** hikaru has joined #openstack-security | 09:36 | |
*** hikaru has quit IRC | 09:37 | |
*** hikaru has joined #openstack-security | 09:38 | |
*** bdpayne has quit IRC | 09:40 | |
*** marzif has joined #openstack-security | 10:23 | |
*** bdpayne has joined #openstack-security | 11:29 | |
*** bdpayne has quit IRC | 11:34 | |
*** bdpayne has joined #openstack-security | 12:30 | |
*** bdpayne has quit IRC | 12:35 | |
*** paulmo has joined #openstack-security | 12:57 | |
*** bdpayne has joined #openstack-security | 13:31 | |
*** bdpayne has quit IRC | 13:35 | |
*** bknudson has joined #openstack-security | 13:41 | |
*** mxin has joined #openstack-security | 14:04 | |
openstackgerrit | KATO Tomoyuki proposed a change to openstack/security-doc: Add typographic convention for reader substitutions in examples https://review.openstack.org/110173 | 14:13 |
*** bdpayne has joined #openstack-security | 14:29 | |
*** voodookid has joined #openstack-security | 14:31 | |
*** bdpayne has quit IRC | 14:34 | |
*** tmcpeak has joined #openstack-security | 14:34 | |
*** sicarie has joined #openstack-security | 15:04 | |
tmcpeak | wow, here's a good one: http://arstechnica.com/security/2014/07/android-crypto-blunder-exposes-users-to-highly-privileged-malware/ | 15:21 |
*** bdpayne_ has joined #openstack-security | 15:32 | |
*** bdpayne_ has quit IRC | 15:36 | |
*** Jangoo has joined #openstack-security | 15:37 | |
voodookid | tmcpeak: word. People seem to forget that keeping stuff hidden is only part of the goal of crypto. Verification is also huge. | 15:38 |
tmcpeak | voodookid: yeah, that's a huge blunder for a critical piece of Android security | 15:39 |
voodookid | I also say this as someone who would have boned that code up even more than others. I have amazing ability to honk that stuff up. | 15:40 |
tmcpeak | voodookid: LOL, yeah security is hard. But this is the kind of thing that code reviews and detailed threat modeling should catch | 15:45 |
tmcpeak | voodookid: my guess is that Bluebox Security discovered it by one of those processes | 15:45 |
voodookid | word | 15:48 |
paulmo | Huh, so they aren't walking the cert chain? *boggle* | 15:49 |
tmcpeak | paulmo: yeah! | 15:49 |
tmcpeak | paulmo: at least in some cases | 15:49 |
voodookid | My thing, unless you are a dedicated, experienced crypto developer, rely on audited libraries. Do not do it yourself if you can help it | 15:49 |
paulmo | I've seen that before unfortunately. | 15:50 |
tmcpeak | voodookid: yeah, roll your own crypto = fail | 15:50 |
paulmo | Even experts usually want years of peer review on new algorithms. | 15:50 |
voodookid | "I wrote this verification routine!" Nope, you need to go sit in the corner and use someone elses. | 15:51 |
voodookid | "But I wrote a thing to handle MD5!" Nope, it probably breaks, use someone elses | 15:51 |
voodookid | *sigh* I had a version of this discussion like a week ago for an internal project | 15:52 |
*** ved_lad has joined #openstack-security | 15:58 | |
*** ved_lad has quit IRC | 15:58 | |
*** ved_lad has joined #openstack-security | 15:58 | |
*** hikaru has quit IRC | 16:05 | |
tmcpeak | voodookid: +1 for use someone elses | 16:08 |
tmcpeak | voodookid: where do you work btw, if you don't mind me asking | 16:08 |
voodookid | a managed service provider. We run other people's IT | 16:09 |
voodookid | I tend to do a lot of security admin, network stuff, but more and more working on code review to head off problems. I am trying to shrink the number of vulnerabilities my scanners are picking up before it even goes on to the network | 16:10 |
tmcpeak | voodookid: ahh cool | 16:12 |
voodookid | I forgot where I saw it, but someone had a talk at a conference and teh gist of it was that we are never going to teach developers to be more security minded, instead security people need to get into development and be the experts at it. | 16:13 |
voodookid | so I have been working on it | 16:13 |
tmcpeak | yeah, I've found that the majority of people don't have the wacky mindset it takes to be good at security. Probably easier to get security people involved in the development process than the other way around | 16:16 |
voodookid | I think people who get into development/programming first are just trying to get it done efficiently and as quickly as possible. SEcurity means it gets slowed down (at first, you can automate it if you know what you are doing) | 16:24 |
tmcpeak | true | 16:30 |
*** bdpayne has joined #openstack-security | 16:30 | |
*** ved_lad has quit IRC | 16:33 | |
*** Jangoo has quit IRC | 16:41 | |
*** marzif has quit IRC | 16:54 | |
*** bdpayne has quit IRC | 16:54 | |
*** tmcpeak has quit IRC | 17:08 | |
*** bdpayne has joined #openstack-security | 17:20 | |
*** nkinder is now known as nkinder_away | 17:21 | |
*** gmurphy has quit IRC | 17:26 | |
*** gmurphy has joined #openstack-security | 17:29 | |
*** tmcpeak has joined #openstack-security | 17:32 | |
*** tmcpeak has quit IRC | 17:36 | |
*** tmcpeak has joined #openstack-security | 17:45 | |
*** ved_lad has joined #openstack-security | 18:06 | |
openstackgerrit | Andreas Jaeger proposed a change to openstack/security-doc: Security Guide: Instance migrations: Some cleaning up https://review.openstack.org/109670 | 18:12 |
bdpayne | hyakuhei or nkinder_away, could one of you review ^^ ? | 18:34 |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/security-doc: Updated from global requirements https://review.openstack.org/110421 | 18:46 |
*** gmurphy has quit IRC | 18:50 | |
*** gmurphy has joined #openstack-security | 18:57 | |
*** gabriela1 has joined #openstack-security | 19:01 | |
*** gabriela1 has left #openstack-security | 19:01 | |
*** ved_lad has quit IRC | 19:08 | |
*** gabriela1 has joined #openstack-security | 19:10 | |
*** gabriela1 has left #openstack-security | 19:11 | |
openstackgerrit | A change was merged to openstack/security-doc: Updated from global requirements https://review.openstack.org/110421 | 19:20 |
openstackgerrit | A change was merged to openstack/security-doc: Add typographic convention for reader substitutions in examples https://review.openstack.org/110173 | 19:23 |
*** openstackgerrit has quit IRC | 19:48 | |
*** gabriela1 has joined #openstack-security | 20:14 | |
*** ved_lad has joined #openstack-security | 20:16 | |
*** gabriela1 has left #openstack-security | 20:39 | |
*** mxin has quit IRC | 20:53 | |
*** openstackgerrit has joined #openstack-security | 20:58 | |
*** bknudson has quit IRC | 22:30 | |
*** tmcpeak has quit IRC | 23:09 | |
*** voodookid has quit IRC | 23:17 | |
*** bknudson has joined #openstack-security | 23:20 | |
*** bknudson has quit IRC | 23:25 | |
*** voodookid has joined #openstack-security | 23:29 | |
*** bdpayne has quit IRC | 23:31 | |
*** bknudson has joined #openstack-security | 23:34 | |
*** ved_lad_ has joined #openstack-security | 23:38 | |
*** bdpayne has joined #openstack-security | 23:39 | |
*** ved_lad has quit IRC | 23:39 | |
*** sicarie has quit IRC | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!