*** tmcpeak has joined #openstack-security | 00:01 | |
*** nkinder has joined #openstack-security | 00:09 | |
*** Gue______ has joined #openstack-security | 00:10 | |
*** markvoelker has joined #openstack-security | 00:50 | |
*** JAHoagie has quit IRC | 00:53 | |
*** markvoelker has quit IRC | 00:55 | |
openstackgerrit | Darren Chan proposed openstack/security-doc: Removed the password autocomplete section https://review.openstack.org/169191 | 01:29 |
---|---|---|
*** markvoelker has joined #openstack-security | 01:51 | |
*** markvoelker has quit IRC | 01:56 | |
*** Gue______ has quit IRC | 02:12 | |
*** tmcpeak has quit IRC | 02:40 | |
*** markvoelker has joined #openstack-security | 02:52 | |
*** markvoelker has quit IRC | 02:56 | |
*** jamielennox is now known as jamielennox|away | 03:47 | |
*** markvoelker has joined #openstack-security | 03:53 | |
*** markvoelker has quit IRC | 03:57 | |
*** dave-mccowan has quit IRC | 04:08 | |
*** bopoh-a has joined #openstack-security | 04:18 | |
*** elo1 has joined #openstack-security | 04:26 | |
*** elo1 has quit IRC | 04:51 | |
*** markvoelker has joined #openstack-security | 04:53 | |
*** markvoelker has quit IRC | 04:58 | |
*** markvoelker has joined #openstack-security | 05:54 | |
*** markvoelker has quit IRC | 05:58 | |
*** markvoelker has joined #openstack-security | 06:55 | |
*** aswadr has joined #openstack-security | 06:58 | |
*** markvoelker has quit IRC | 06:59 | |
*** tkelsey has joined #openstack-security | 07:28 | |
*** tkelsey has quit IRC | 07:30 | |
*** markvoelker has joined #openstack-security | 07:56 | |
*** markvoelker has quit IRC | 08:00 | |
*** asrangne has joined #openstack-security | 08:54 | |
*** aswadr has quit IRC | 08:56 | |
*** asrangne__ has joined #openstack-security | 08:56 | |
*** markvoelker has joined #openstack-security | 08:56 | |
*** asrangne has quit IRC | 09:00 | |
*** markvoelker has quit IRC | 09:01 | |
*** JAHoagie has joined #openstack-security | 09:06 | |
*** JAHoagie has quit IRC | 09:11 | |
*** markvoelker has joined #openstack-security | 09:57 | |
*** markvoelker has quit IRC | 10:02 | |
*** tmcpeak has joined #openstack-security | 10:03 | |
*** markvoelker has joined #openstack-security | 10:58 | |
*** markvoelker has quit IRC | 11:03 | |
*** bopoh-a has quit IRC | 11:42 | |
*** bopoh-a has joined #openstack-security | 11:43 | |
*** bopoh-a has left #openstack-security | 11:43 | |
*** markvoelker has joined #openstack-security | 11:59 | |
*** markvoelker has quit IRC | 12:03 | |
*** dave-mccowan has joined #openstack-security | 12:21 | |
openstackgerrit | Tim Kelsey proposed stackforge/anchor: Updating domain validator to pass if given an empty list https://review.openstack.org/170048 | 12:47 |
*** markvoelker has joined #openstack-security | 12:59 | |
*** markvoelker has quit IRC | 13:04 | |
*** bknudson has joined #openstack-security | 13:06 | |
*** JAHoagie has joined #openstack-security | 13:06 | |
*** openstackgerrit has quit IRC | 13:07 | |
*** openstackgerrit has joined #openstack-security | 13:07 | |
*** JAHoagie has quit IRC | 13:11 | |
*** singlethink has joined #openstack-security | 13:21 | |
*** JAHoagie has joined #openstack-security | 13:24 | |
*** markvoelker has joined #openstack-security | 13:37 | |
openstackgerrit | Tim Kelsey proposed stackforge/anchor: Updating domain validator to pass if given an empty list https://review.openstack.org/170048 | 13:40 |
*** JAHoagie has quit IRC | 14:16 | |
*** sicarie has joined #openstack-security | 14:25 | |
*** dwyde has joined #openstack-security | 14:44 | |
*** edmondsw has joined #openstack-security | 14:47 | |
*** voodookid has joined #openstack-security | 14:55 | |
*** JAHoagie has joined #openstack-security | 14:57 | |
*** JAHoagie has quit IRC | 15:09 | |
*** asrangne__ has quit IRC | 15:12 | |
*** dwyde has quit IRC | 15:16 | |
sicarie | elmiko: ping | 15:16 |
elmiko | sicarie: pong | 15:18 |
sicarie | I saw you took a look at https://review.openstack.org/#/c/169191/ | 15:18 |
elmiko | yea, the bug made sense to me | 15:19 |
sicarie | Do we want to carve out the whole section? | 15:20 |
elmiko | hmm, let me look again | 15:20 |
sicarie | Or would guidance (such as what tmcpeak put in the bug) be better? | 15:20 |
elmiko | i think the advice in the bug is valuable to understanding the issue, so i'd be +1 for adding something about it to the section | 15:21 |
sicarie | Or we could just rip it out (as there is most likely corporate or admin preference around what to do there on a per-environment basis) | 15:22 |
*** dwyde has joined #openstack-security | 15:22 | |
sicarie | I'm curious as to what others thing because we just had this come up internally | 15:22 |
elmiko | that's a good point | 15:24 |
elmiko | i guess, how much did you want to excise from the dashboard section? | 15:24 |
sicarie | Anything that makes it better | 15:24 |
sicarie | Of straight-up removing, I was only looking at the ridiculously long config file | 15:25 |
sicarie | I'd prefer to rewrite/restate what's there and see if it still applies (as I think a significant portion of it will) | 15:25 |
elmiko | that probably makes the most sense, much of what is here looks good to me, and it's stuff i would want to be aware of when setting up the dashboard | 15:26 |
*** JAHoagie has joined #openstack-security | 15:26 | |
elmiko | for example, cross-site scripting, cookies, and the like | 15:26 |
sicarie | tmcpeak: thoughts on your bug (and the proposed fix)? | 15:26 |
sicarie | So with this section I'd advocate for keeping the heading and outlining pros and cons of pw managers with caveat if you're going to allow it, to disable browser and allow desktop | 15:29 |
*** JAHoagie has quit IRC | 15:30 | |
tmcpeak | yo | 15:30 |
sicarie | You recently submitted bug https://bugs.launchpad.net/openstack-manuals/+bug/1438418 on browers password managers | 15:31 |
openstack | Launchpad bug 1438418 in openstack-manuals "OpenStack Security Guide Bad Advice for Saved Password" [Medium,In progress] - Assigned to Darren Chan (dazzachan) | 15:31 |
sicarie | And the proposed fix removes the section completely: https://review.openstack.org/#/c/169191/2/security-guide/ch_dashboard.xml | 15:31 |
tmcpeak | one sec | 15:32 |
tmcpeak | let me check it out | 15:32 |
sicarie | for sure | 15:32 |
sicarie | What's your opinion on removing (as proposed) vs discussing pros/cons of password managers (in general), and then saying "if you do allow pw managers, disable browser and allow desktop"? | 15:33 |
tmcpeak | I'm definitely in favor of putting forward information | 15:33 |
tmcpeak | pros and cons seems like a good approach | 15:34 |
tmcpeak | yanking out this section is better than nothing, pros and cons is even better | 15:34 |
sicarie | Cool | 15:34 |
elmiko | +1 | 15:34 |
sicarie | sweet! | 15:34 |
sicarie | I'll review the bug | 15:34 |
sicarie | Thanks! | 15:34 |
elmiko | makes sense to let the yank go through, then add a new patch | 15:34 |
tmcpeak | yep | 15:35 |
sicarie | elmiko: good call | 15:35 |
openstackgerrit | Merged openstack/security-doc: Removed the password autocomplete section https://review.openstack.org/169191 | 15:42 |
openstackgerrit | Tim Kelsey proposed stackforge/anchor: Added tests to bring coverage up to 100% of validators https://review.openstack.org/171257 | 15:45 |
*** dwyde has quit IRC | 16:43 | |
*** tkelsey has joined #openstack-security | 16:49 | |
*** dwyde has joined #openstack-security | 16:51 | |
*** dave-mccowan has quit IRC | 16:58 | |
*** JAHoagie has joined #openstack-security | 17:00 | |
*** tmcpeak has quit IRC | 17:00 | |
*** dave-mccowan has joined #openstack-security | 17:26 | |
*** bdpayne has joined #openstack-security | 17:26 | |
*** bpokorny has joined #openstack-security | 17:27 | |
*** tmcpeak has joined #openstack-security | 17:29 | |
*** dwyde has quit IRC | 17:34 | |
*** dwyde has joined #openstack-security | 17:36 | |
*** JAHoagie has quit IRC | 17:41 | |
*** JAHoagie has joined #openstack-security | 17:51 | |
*** bpokorny_ has joined #openstack-security | 17:59 | |
*** bpokorn__ has joined #openstack-security | 17:59 | |
*** tkelsey has quit IRC | 18:00 | |
*** bpokorny has quit IRC | 18:01 | |
*** jamielennox|away is now known as jamielennox | 18:01 | |
*** bpokorny_ has quit IRC | 18:03 | |
*** bdpayne has quit IRC | 18:08 | |
*** dwyde has quit IRC | 18:10 | |
*** JAHoagie has quit IRC | 18:15 | |
*** subscope_ has joined #openstack-security | 18:16 | |
*** bpokorny has joined #openstack-security | 18:17 | |
*** bpokorn__ has quit IRC | 18:20 | |
*** dwyde has joined #openstack-security | 18:40 | |
*** JAHoagie has joined #openstack-security | 19:09 | |
*** subscope_ has quit IRC | 19:22 | |
*** openstackgerrit has quit IRC | 19:22 | |
*** openstackgerrit has joined #openstack-security | 19:22 | |
*** subscope_ has joined #openstack-security | 19:37 | |
*** dwyde has quit IRC | 19:44 | |
*** tkelsey has joined #openstack-security | 19:46 | |
*** tkelsey has quit IRC | 19:50 | |
*** dwyde has joined #openstack-security | 19:59 | |
*** bdpayne has joined #openstack-security | 20:19 | |
*** subscop__ has joined #openstack-security | 20:20 | |
*** subscope_ has quit IRC | 20:23 | |
*** subscop__ has quit IRC | 20:25 | |
*** bdpayne has quit IRC | 20:54 | |
*** bpokorny_ has joined #openstack-security | 21:11 | |
*** bpokorny has quit IRC | 21:14 | |
*** openstackgerrit has quit IRC | 21:37 | |
*** openstackgerrit has joined #openstack-security | 21:37 | |
*** dwyde has quit IRC | 21:45 | |
*** tkelsey has joined #openstack-security | 21:47 | |
*** singleth1nk has joined #openstack-security | 21:48 | |
*** tkelsey has quit IRC | 21:51 | |
*** singlethink has quit IRC | 21:53 | |
*** edmondsw has quit IRC | 22:02 | |
*** bdpayne has joined #openstack-security | 22:03 | |
*** dwyde has joined #openstack-security | 22:05 | |
*** singleth1nk has quit IRC | 22:05 | |
*** bpokorny has joined #openstack-security | 22:17 | |
*** sicarie has left #openstack-security | 22:20 | |
*** bpokorny_ has quit IRC | 22:21 | |
*** bknudson has quit IRC | 22:33 | |
*** jeanmanuel has joined #openstack-security | 22:42 | |
*** dwyde has quit IRC | 22:42 | |
jeanmanuel | hola perros muertos | 22:42 |
*** jeanmanuel has left #openstack-security | 22:43 | |
*** bknudson has joined #openstack-security | 22:56 | |
*** bknudson1 has joined #openstack-security | 22:58 | |
*** voodookid has quit IRC | 22:59 | |
*** tmcpeak has quit IRC | 22:59 | |
*** bknudson has quit IRC | 23:00 | |
*** dave-mccowan has quit IRC | 23:04 | |
*** tmcpeak has joined #openstack-security | 23:21 | |
*** bdpayne has quit IRC | 23:49 | |
*** bdpayne has joined #openstack-security | 23:51 | |
*** bdpayne has quit IRC | 23:52 | |
*** bdpayne has joined #openstack-security | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!