unrahul | I still can't believe that I assumed log initialization was in init.. | 00:00 |
---|---|---|
unrahul | i think i dreamt that up | 00:00 |
unrahul | :o | 00:00 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Modifying checks to use test objects https://review.openstack.org/340602 | 00:23 |
*** ccneill has quit IRC | 00:29 | |
*** deblike has quit IRC | 00:36 | |
*** vinaypotluri has quit IRC | 01:11 | |
*** tmcpeak has quit IRC | 01:22 | |
*** zul has quit IRC | 01:50 | |
*** zul_ has joined #openstack-security | 02:01 | |
*** zul has joined #openstack-security | 02:02 | |
*** zul_ has quit IRC | 02:10 | |
*** browne has quit IRC | 02:17 | |
*** dave-mccowan has quit IRC | 02:20 | |
*** diazjf has joined #openstack-security | 02:21 | |
*** elmiko is now known as _elmiko | 02:24 | |
*** deblike has joined #openstack-security | 02:32 | |
*** vinaypotluri has joined #openstack-security | 02:43 | |
*** deblike has quit IRC | 02:53 | |
*** tmcpeak has joined #openstack-security | 03:21 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding missing section to documentation about gen_config https://review.openstack.org/340574 | 03:23 |
*** markvoelker has joined #openstack-security | 03:32 | |
*** markvoelker_ has joined #openstack-security | 03:35 | |
*** markvoelker has quit IRC | 03:38 | |
*** diazjf has quit IRC | 03:39 | |
*** markvoelker has joined #openstack-security | 03:46 | |
*** markvoelker_ has quit IRC | 03:49 | |
*** tmcpeak has quit IRC | 04:25 | |
*** d0ugal has quit IRC | 05:01 | |
*** markvoelker_ has joined #openstack-security | 05:16 | |
*** markvoelker has quit IRC | 05:19 | |
*** woodburn has quit IRC | 05:21 | |
*** sdake_ has joined #openstack-security | 05:25 | |
*** liverpooler has joined #openstack-security | 05:36 | |
*** markvoelker_ has quit IRC | 05:45 | |
*** rcernin has joined #openstack-security | 05:58 | |
*** d0ugal has joined #openstack-security | 06:04 | |
*** unrahul has quit IRC | 06:32 | |
*** d0ugal has quit IRC | 06:43 | |
*** sdake_ has quit IRC | 06:49 | |
*** tesseract- has joined #openstack-security | 07:00 | |
*** pcaruana has joined #openstack-security | 07:00 | |
*** vinaypotluri has quit IRC | 07:21 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/340793 | 09:00 |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/340793 | 09:26 |
*** d0ugal has joined #openstack-security | 10:03 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/340834 | 10:10 |
*** sdake has joined #openstack-security | 11:07 | |
*** sdake_ has joined #openstack-security | 11:08 | |
*** sdake has quit IRC | 11:13 | |
*** sdake_ has quit IRC | 12:16 | |
*** markvoelker has joined #openstack-security | 12:34 | |
*** edmondsw has joined #openstack-security | 12:58 | |
*** _elmiko is now known as elmiko | 13:01 | |
*** cleong has joined #openstack-security | 13:17 | |
*** dave-mccowan has joined #openstack-security | 13:21 | |
*** d0ugal_ has joined #openstack-security | 13:30 | |
*** d0ugal has quit IRC | 13:33 | |
*** d0ugal_ is now known as d0ugal | 13:35 | |
*** d0ugal is now known as Guest65715 | 13:36 | |
*** Guest65715 has quit IRC | 13:36 | |
*** d0ugal_ has joined #openstack-security | 13:36 | |
*** sdake_ has joined #openstack-security | 13:41 | |
*** d0ugal_ has quit IRC | 13:44 | |
*** d0ugal has joined #openstack-security | 13:44 | |
*** mvaldes has joined #openstack-security | 13:46 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/340834 | 13:46 |
*** vponomaryov has joined #openstack-security | 13:56 | |
vponomaryov | Hello everyone, can someone please spill the light on the security bug fixes proposals, I have read doc https://security.openstack.org/#vulnerability-management but it is unclear when security bug can be "remediated" and "published". | 13:59 |
vponomaryov | and is it correct to say that if project that has vulnerability is not in the list http://governance.openstack.org/reference/tags/vulnerability_managed.html then drivers of that project decide on their own? | 14:06 |
*** markvoelker has quit IRC | 14:11 | |
*** sigmavirus has quit IRC | 14:15 | |
*** _sigmavirus24 has joined #openstack-security | 14:16 | |
*** _sigmavirus24 is now known as sigmavirus | 14:19 | |
*** sigmavirus has joined #openstack-security | 14:19 | |
*** aastha has joined #openstack-security | 14:26 | |
*** woodburn has joined #openstack-security | 14:27 | |
*** tmcpeak has joined #openstack-security | 14:28 | |
*** jmckind has joined #openstack-security | 14:30 | |
*** markvoelker has joined #openstack-security | 14:30 | |
*** tmcpeak has quit IRC | 14:34 | |
*** diazjf has joined #openstack-security | 14:39 | |
*** vinaypotluri has joined #openstack-security | 14:39 | |
*** diazjf has quit IRC | 14:45 | |
*** diazjf has joined #openstack-security | 14:54 | |
*** yaya has joined #openstack-security | 15:11 | |
*** ametts has joined #openstack-security | 15:21 | |
*** jmckind_ has joined #openstack-security | 15:23 | |
*** jmckind has quit IRC | 15:26 | |
*** yaya has quit IRC | 15:27 | |
*** sdake_ has quit IRC | 15:36 | |
*** sdake_ has joined #openstack-security | 15:36 | |
*** diazjf has left #openstack-security | 15:37 | |
gmurphy | vponomaryov: so if the project does not have a vulnerability managed governance tag typically the disclosure process is not driven by the vmt | 15:37 |
gmurphy | we can help you get a cve assigned | 15:37 |
gmurphy | and if the issue is still private we can also give you a list of key stakeholders that get pre-disclosure about security issues. | 15:38 |
gmurphy | an example of a team that has disclosed their own vulnerabilities is designate with this - http://www.openwall.com/lists/oss-security/2015/07/28/7 | 15:38 |
gmurphy | there have been a couple of others as well. | 15:39 |
gmurphy | i'm just trying to think now which ones they were… | 15:39 |
gmurphy | anyway if you have any questions feel free to reach out to myself, tristanC, fungi or notmorgan | 15:40 |
*** mdong has joined #openstack-security | 15:55 | |
*** pcaruana has quit IRC | 16:00 | |
*** yaya has joined #openstack-security | 16:03 | |
*** rcernin has quit IRC | 16:03 | |
vponomaryov | gmurphy: thank you for information | 16:03 |
gmurphy | no problem. | 16:03 |
*** jmckind_ has quit IRC | 16:04 | |
vponomaryov | gmurphy: yes, issue is still private | 16:04 |
vponomaryov | gmurphy: in "manila UI" project | 16:05 |
*** unrahul has joined #openstack-security | 16:07 | |
*** liverpooler has quit IRC | 16:08 | |
*** sdake_ has quit IRC | 16:09 | |
*** tesseract- has quit IRC | 16:09 | |
gmurphy | ok. so i think fungi is the best person to talk to regarding the pre-disclosure part ( if you want to do that as a part of your disclosure ) | 16:10 |
*** jmckind has joined #openstack-security | 16:10 | |
gmurphy | or maybe tristanC. i'm not so familiar with how the new mailing list works that they setup | 16:10 |
*** dave-mccowan has quit IRC | 16:10 | |
*** sdake_ has joined #openstack-security | 16:10 | |
*** liverpooler has joined #openstack-security | 16:10 | |
*** deblike has joined #openstack-security | 16:11 | |
unrahul | vinaypotluri: do we have the meeting ? | 16:19 |
unrahul | vidyo is giving me issues | 16:20 |
unrahul | mdong: do we have the meeting today? | 16:21 |
vponomaryov | murphy: ok, will try to reach out to them | 16:21 |
*** sdake_ has quit IRC | 16:24 | |
*** d0ugal has quit IRC | 16:24 | |
unrahul | mdong: so. it got disconnected again.. | 16:25 |
unrahul | i guess thats it.. | 16:25 |
unrahul | :) | 16:25 |
*** jmckind has quit IRC | 16:25 | |
vinaypotluri | i have issues with vidyo too | 16:25 |
vinaypotluri | unrahul where are you guys sitting ? | 16:26 |
*** jmckind has joined #openstack-security | 16:26 | |
unrahul | i guess the meeting is over.. | 16:26 |
unrahul | it was crashing all over the place | 16:26 |
unrahul | so tht s fine | 16:26 |
mdong | +1 | 16:27 |
*** ninag has joined #openstack-security | 16:27 | |
*** jmckind has quit IRC | 16:28 | |
*** catintheroof has joined #openstack-security | 16:28 | |
*** jmckind has joined #openstack-security | 16:28 | |
*** jmckind has quit IRC | 16:29 | |
*** jmckind has joined #openstack-security | 16:30 | |
*** ninag has quit IRC | 16:32 | |
*** jmckind has quit IRC | 16:35 | |
*** jmckind has joined #openstack-security | 16:36 | |
*** sdake_ has joined #openstack-security | 16:40 | |
*** jmckind has quit IRC | 16:41 | |
*** yaya has quit IRC | 16:42 | |
*** mvaldes has quit IRC | 17:02 | |
*** yaya has joined #openstack-security | 17:15 | |
*** sdake_ has quit IRC | 17:17 | |
*** jmckind has joined #openstack-security | 17:19 | |
*** hwpplayer1 has joined #openstack-security | 17:35 | |
*** dave-mccowan has joined #openstack-security | 17:39 | |
*** yaya has quit IRC | 17:46 | |
*** browne has joined #openstack-security | 17:58 | |
*** mvaldes has joined #openstack-security | 18:03 | |
*** yaya has joined #openstack-security | 18:09 | |
*** liverpooler has quit IRC | 18:11 | |
*** sdake_ has joined #openstack-security | 18:11 | |
*** hwpplayer1 has left #openstack-security | 18:26 | |
*** agireud has quit IRC | 18:30 | |
*** agireud has joined #openstack-security | 18:31 | |
*** sdake_ has quit IRC | 18:32 | |
*** sdake_ has joined #openstack-security | 18:33 | |
*** sdake_ has quit IRC | 19:08 | |
*** sdake_ has joined #openstack-security | 19:26 | |
*** FredStockton has joined #openstack-security | 19:31 | |
*** sdake_ has quit IRC | 20:01 | |
*** dave-mccowan has quit IRC | 20:05 | |
*** dave-mccowan has joined #openstack-security | 20:07 | |
*** markvoelker has quit IRC | 20:49 | |
*** markvoelker has joined #openstack-security | 21:00 | |
*** julian1 has joined #openstack-security | 21:02 | |
*** Trident has joined #openstack-security | 21:13 | |
browne | anybody security talks for the summit? | 21:19 |
browne | anybody doing security talks for the summit? | 21:19 |
*** mdong has quit IRC | 21:20 | |
*** julian1 has quit IRC | 21:20 | |
*** rcernin has joined #openstack-security | 21:21 | |
*** mdong has joined #openstack-security | 21:21 | |
*** jmckind has quit IRC | 21:30 | |
*** cleong has quit IRC | 21:43 | |
*** deblike has quit IRC | 21:43 | |
*** FredStockton has left #openstack-security | 21:44 | |
*** ametts has quit IRC | 21:49 | |
*** dave-mccowan has quit IRC | 21:54 | |
*** markvoelker has quit IRC | 21:59 | |
*** markvoelker has joined #openstack-security | 22:04 | |
gmurphy | browne: i know sicarie was thinking about a couple | 22:08 |
gmurphy | something around the security guide for one of them i think | 22:09 |
*** sicarie has joined #openstack-security | 22:09 | |
gmurphy | speaking of which sicarie you doing some security talks for the summit? | 22:09 |
sicarie | yeah, i’m floating a few | 22:10 |
sicarie | sec-guide, privacy and a 101 | 22:10 |
gmurphy | i think you should do a brown bag session | 22:10 |
sicarie | I couldn’t figure out how to submit those | 22:10 |
sicarie | i’d rather do the secguide one as a brownbag | 22:11 |
gmurphy | would be good to drum up more interest in the security documentation side of things i think | 22:11 |
sicarie | yeah, that’s the aim | 22:11 |
sicarie | i am going to sit down in the next day or two and look at what all should really be done in the short term | 22:11 |
*** yaya has quit IRC | 22:13 | |
sicarie | i don’t have backscroll on my client - anyone else planning anything? | 22:16 |
sicarie | good talk | 22:18 |
*** mvaldes has quit IRC | 22:19 | |
gmurphy | hahah | 22:30 |
gmurphy | that's my line | 22:30 |
gmurphy | i'm thinking of submitting something random | 22:30 |
gmurphy | been thinking a bunch about osquery lately. was thinking about writing a bunch of query packs for osqueryd around openstack specific things. | 22:31 |
gmurphy | specifically looking for indicators of compromise or unauthorized changes to the environment | 22:31 |
gmurphy | sicarie: what do you think about that? | 22:32 |
sicarie | That would be cool | 22:33 |
gmurphy | maybe. although i probably should actually do the thing before i submit a talk about it | 22:33 |
gmurphy | or not | 22:33 |
sicarie | you could always just get all hand-waivey if you need to | 22:34 |
*** rcernin has quit IRC | 22:35 | |
gmurphy | the submission process is kind of involved this year… | 22:35 |
gmurphy | provide links and stuff | 22:36 |
*** zul has quit IRC | 22:36 | |
sicarie | ruh-roh, I haven’t looked at it yet | 22:36 |
*** zul has joined #openstack-security | 22:37 | |
*** markvoelker has quit IRC | 23:00 | |
*** markvoelker has joined #openstack-security | 23:06 | |
*** catintheroof has quit IRC | 23:09 | |
*** sicarie has quit IRC | 23:10 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Modifying checks to use test objects https://review.openstack.org/340602 | 23:29 |
*** mdong has quit IRC | 23:40 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Modifying checks to use test objects https://review.openstack.org/340602 | 23:48 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!