*** ptd has joined #openstack-security | 00:59 | |
*** dmccowan has quit IRC | 02:46 | |
*** elo1 has joined #openstack-security | 03:22 | |
*** elo1 has quit IRC | 03:24 | |
*** elo1 has joined #openstack-security | 03:26 | |
*** ved_lad has joined #openstack-security | 04:59 | |
*** ved_lad has quit IRC | 05:04 | |
*** ved_lad has joined #openstack-security | 05:07 | |
*** ved_lad has quit IRC | 05:42 | |
*** voodookid has joined #openstack-security | 05:49 | |
*** voodookid has quit IRC | 05:59 | |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/116183 | 06:06 |
---|---|---|
openstackgerrit | A change was merged to openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/116183 | 06:56 |
*** jamielennox is now known as jamielennox|away | 08:29 | |
*** zz_naotok has quit IRC | 08:50 | |
*** zz_naotok has joined #openstack-security | 08:51 | |
*** ptd has quit IRC | 10:29 | |
*** dmccowan has joined #openstack-security | 12:33 | |
*** dmccowan_ has joined #openstack-security | 12:39 | |
*** dmccowan has quit IRC | 12:40 | |
*** dmccowan_ is now known as dmccowan | 12:40 | |
openstackgerrit | Stanislaw Pitucha proposed a change to openstack/security-doc: OSSN-0023 Keystone logs tokens at INFO levels https://review.openstack.org/114971 | 12:55 |
*** paulmo has joined #openstack-security | 13:10 | |
*** nkinder has quit IRC | 13:19 | |
*** bknudson has quit IRC | 13:24 | |
*** bknudson has joined #openstack-security | 13:48 | |
*** dmccowan has quit IRC | 13:57 | |
*** nkinder has joined #openstack-security | 14:07 | |
*** dmccowan has joined #openstack-security | 14:11 | |
*** voodookid has joined #openstack-security | 14:40 | |
*** bknudson has quit IRC | 14:52 | |
*** elo1 has quit IRC | 15:01 | |
*** bknudson has joined #openstack-security | 15:36 | |
openstackgerrit | Stanislaw Pitucha proposed a change to openstack/security-doc: OSSN-0023 Keystone logs tokens at INFO levels https://review.openstack.org/114971 | 15:36 |
*** tmcpeak has joined #openstack-security | 15:57 | |
*** openstackgerrit has quit IRC | 16:34 | |
*** bknudson has quit IRC | 16:54 | |
*** bdpayne has joined #openstack-security | 16:55 | |
*** rlpple has joined #openstack-security | 17:07 | |
*** elo1 has joined #openstack-security | 17:11 | |
*** openstackgerrit has joined #openstack-security | 17:30 | |
*** bknudson has joined #openstack-security | 17:58 | |
*** rlpple has quit IRC | 18:34 | |
*** gabriela2 has joined #openstack-security | 18:54 | |
*** elo1 has quit IRC | 18:59 | |
gabriela2 | hello | 18:59 |
*** nkinder has quit IRC | 19:01 | |
*** gabriela2 has left #openstack-security | 19:06 | |
*** gabriela3 has joined #openstack-security | 19:35 | |
*** ChanServ sets mode: +b *!~GABRIELA@186.89.124.204 | 19:35 | |
*** gabriela3 was kicked by ChanServ (User is banned from this channel) | 19:35 | |
*** dmccowan has quit IRC | 19:52 | |
*** gabriela2 has joined #openstack-security | 20:02 | |
*** gabriela2 has left #openstack-security | 20:16 | |
*** voodookid has quit IRC | 20:24 | |
*** voodookid has joined #openstack-security | 20:25 | |
tmcpeak | umm, should we just block 186.* ? :\ | 20:38 |
bdpayne | so the op CR hasn't merged yet | 20:38 |
bdpayne | once we get there, I can be proactive about killing the nicks as they appear | 20:39 |
bdpayne | I'd rather now block IP ranges unless we really need to | 20:39 |
bdpayne | due to potential false positive issues | 20:39 |
tmcpeak | right | 20:39 |
tmcpeak | yeah, I think blocking whole ranges is bad | 20:39 |
tmcpeak | bdpayne: btw, met Paul | 20:39 |
tmcpeak | damn smart dude | 20:39 |
bdpayne | ah cool... you went to the OWASP thing? | 20:39 |
bdpayne | yeah, he's good people :-) | 20:40 |
tmcpeak | yeah, actually both presentations were pretty good | 20:40 |
tmcpeak | there was his, which was super cool, good demo, and then a dude from Netflix Security team | 20:40 |
bdpayne | you saw that Paul commented on the Horizon XSS issue as well? | 20:40 |
tmcpeak | yeah, his comment was *on point* | 20:40 |
bdpayne | heh | 20:41 |
tmcpeak | I was talking to him about getting some time at the summit to get it all sorted out | 20:41 |
tmcpeak | I think it would be well worth it | 20:41 |
tmcpeak | once we get stuff sorted out we could start running some XSS scanning tool in the gate test, and some of the anti patterns gmurphy had mentioned in bandit | 20:43 |
bdpayne | yeah, that would be nice | 20:44 |
bdpayne | the trick is getting the right people together to make it happen | 20:45 |
tmcpeak | right, he's definitely one of them, gmurphy would be good as well, and then the people that have +2 for Horizon | 20:45 |
bdpayne | unfortunately, I don't believe that Paul is going to Paris | 20:45 |
tmcpeak | aww bummer | 20:46 |
tmcpeak | any chance we could video chat him in? | 20:46 |
tmcpeak | he's Django core dev, so he'd be very very helpful to have for it | 20:46 |
bdpayne | yeah, if something really comes together on this effort, I may be able to change that | 20:47 |
bdpayne | but, it would need to formalize quickly | 20:47 |
tmcpeak | cool | 20:47 |
tmcpeak | well have a chat with him, he'd probably know the people to pull together | 20:47 |
tmcpeak | IMO it's well worth getting this solved once and for all | 20:47 |
bdpayne | if it doesn't happen in paris, depending on where the necessary devs live, we may be able to have a mini bay-area meetup to hack out a solution shortly after the summit | 20:51 |
tmcpeak | oh yeah, good idea | 20:51 |
bdpayne | in fact, that could be better (if the devs are out here) anyway, because the summit is always so busy | 20:51 |
tmcpeak | yeah, I think you're right | 20:51 |
tmcpeak | carving off time at the summit might be tough | 20:51 |
*** dmccowan has joined #openstack-security | 21:02 | |
*** nkinder has joined #openstack-security | 21:11 | |
*** elo1 has joined #openstack-security | 21:57 | |
*** bdpayne_ has joined #openstack-security | 22:00 | |
*** bdpayne has quit IRC | 22:00 | |
*** Spitfire55 has joined #openstack-security | 22:01 | |
*** Spitfire55 has quit IRC | 22:06 | |
*** elo1 has quit IRC | 22:25 | |
openstackgerrit | Jim Hoagland proposed a change to openstack/security-doc: Improve wording of Object Storage chapter para https://review.openstack.org/115152 | 22:34 |
*** bdpayne_ has quit IRC | 22:37 | |
*** bdpayne has joined #openstack-security | 22:37 | |
*** bdpayne_ has joined #openstack-security | 22:39 | |
openstackgerrit | Jim Hoagland proposed a change to openstack/security-doc: Improve wording of Object Storage chapter para https://review.openstack.org/115152 | 22:42 |
*** bdpayne has quit IRC | 22:42 | |
*** voodookid has quit IRC | 22:53 | |
*** voodookid has joined #openstack-security | 23:35 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!