*** macza has quit IRC | 00:07 | |
*** dave-mccowan has quit IRC | 00:49 | |
*** dave-mccowan has joined #openstack-security | 00:51 | |
gagehugo | fungi lhinds: I won't be around for the security IRC meeting tomorrow, had something come up | 01:12 |
---|---|---|
*** dave-mccowan has quit IRC | 01:15 | |
*** freerunner has joined #openstack-security | 02:46 | |
*** rcernin has quit IRC | 05:05 | |
*** rcernin has joined #openstack-security | 05:07 | |
*** jaosorior has joined #openstack-security | 05:15 | |
*** Bhujay has joined #openstack-security | 05:20 | |
*** Bhujay has quit IRC | 05:21 | |
*** Bhujay has joined #openstack-security | 05:21 | |
*** Bhujay has quit IRC | 06:07 | |
*** Bhujay has joined #openstack-security | 06:07 | |
*** Bhujay has quit IRC | 06:08 | |
*** Bhujay has joined #openstack-security | 06:08 | |
*** Bhujay has quit IRC | 06:10 | |
*** Bhujay has joined #openstack-security | 06:10 | |
*** Bhujay has quit IRC | 06:11 | |
*** Bhujay has joined #openstack-security | 06:11 | |
*** Bhujay has quit IRC | 06:13 | |
*** Bhujay has joined #openstack-security | 06:13 | |
*** Bhujay has quit IRC | 06:14 | |
*** Bhujay has joined #openstack-security | 06:14 | |
*** Bhujay has quit IRC | 06:16 | |
*** Bhujay has joined #openstack-security | 06:16 | |
*** Bhujay has quit IRC | 06:17 | |
*** Bhujay has joined #openstack-security | 06:17 | |
*** Bhujay has quit IRC | 06:19 | |
*** Bhujay has joined #openstack-security | 06:19 | |
*** Bhujay has quit IRC | 06:20 | |
*** Bhujay has joined #openstack-security | 06:20 | |
*** Bhujay has quit IRC | 06:22 | |
*** Bhujay has joined #openstack-security | 06:22 | |
*** Bhujay has quit IRC | 06:23 | |
*** Bhujay has joined #openstack-security | 06:23 | |
*** Luzi has joined #openstack-security | 06:43 | |
*** threestrands has quit IRC | 07:17 | |
*** rcernin has quit IRC | 07:20 | |
*** pcaruana has joined #openstack-security | 07:36 | |
*** Bhujay has quit IRC | 08:13 | |
*** Bhujay has joined #openstack-security | 08:56 | |
*** lhinds has quit IRC | 09:31 | |
*** lhinds has joined #openstack-security | 09:34 | |
*** ssbarnea|rover has joined #openstack-security | 10:34 | |
ssbarnea|rover | i wonder if this counts as a security issue: https://review.openstack.org/#/q/owner:lijunjie%2540cloudin.cn+status:open | 10:36 |
*** Bhujay has quit IRC | 10:37 | |
ssbarnea|rover | this could easily count as a DoS attack on openstack test infrastructure as such changes would keep our infra busy for a very long time, delaying testing and merges of more important patches. | 10:38 |
ssbarnea|rover | probably this is not a real attack, but is not an unique example, seen lots of similar ones and almost always from China users (based on names or emails). | 10:39 |
*** v12aml has joined #openstack-security | 10:52 | |
*** Bhujay has joined #openstack-security | 10:53 | |
*** openstackgerrit has joined #openstack-security | 10:56 | |
openstackgerrit | Alexandra Settle proposed openstack/security-doc master: add info about expired tokens validation https://review.openstack.org/614871 | 10:56 |
fungi | sean-k-mooney: sorry, i missed your question from tuesday until just now... which bug? | 12:33 |
*** Bhujay has quit IRC | 12:34 | |
*** Bhujay has joined #openstack-security | 12:35 | |
*** Bhujay has quit IRC | 12:36 | |
*** Bhujay has joined #openstack-security | 12:36 | |
fungi | ssbarnea|rover: it's not a real attack as 1. the individuals in question are almost certainly unaware of the test impact of their actions (just looking to contribute and don't know how to be productive), 2. zuul/gerrit admins can easily dequeue and/or abandon their changes if needed, and 3. if we ask them to stop and they don't then we can disable their accounts and reach out to their employers | 12:37 |
*** Bhujay has quit IRC | 12:37 | |
fungi | recently the majority of those seem to have been coming from employees of 99cloud (a china-based company), yes | 12:38 |
ssbarnea|rover | so a message should be enough. | 12:39 |
fungi | yes, we've had the first contact sig reaching out to individuals like that and trying to find them more productive work | 12:39 |
ssbarnea|rover | maybe they boss set a quota for number of reviews? or they want to boos https://www.stackalytics.com stats :D | 12:40 |
*** Bhujay has joined #openstack-security | 12:40 | |
fungi | that's been one of the more cynical assertions, yes | 12:40 |
fungi | you certainly wouldn't be the first to suggest that possibility anyway | 12:40 |
ssbarnea|rover | wow, it seems to be working, they are no3 :D | 12:40 |
*** Bhujay has quit IRC | 12:42 | |
ssbarnea|rover | fungi: we can close the subject. i have practical things to fix. | 12:42 |
fungi | indeed ;) | 12:42 |
*** irclogbot_2 has quit IRC | 12:48 | |
*** irclogbot_2 has joined #openstack-security | 12:58 | |
*** irclogbot_2 has quit IRC | 13:12 | |
*** irclogbot_2 has joined #openstack-security | 13:27 | |
*** edmondsw_ has joined #openstack-security | 13:27 | |
*** edmondsw has quit IRC | 13:29 | |
*** edmondsw_ is now known as edmondsw | 13:29 | |
*** irclogbot_2 has quit IRC | 13:35 | |
*** irclogbot_2 has joined #openstack-security | 13:49 | |
*** Luzi has quit IRC | 15:33 | |
*** jaosorior has quit IRC | 15:56 | |
*** dave-mccowan has joined #openstack-security | 16:28 | |
*** macza has joined #openstack-security | 16:28 | |
*** dave-mccowan has quit IRC | 16:31 | |
*** robbbe has joined #openstack-security | 17:44 | |
*** robbbe has quit IRC | 19:19 | |
*** pcaruana has quit IRC | 20:09 | |
*** irclogbot_2 has quit IRC | 20:37 | |
*** irclogbot_2 has joined #openstack-security | 20:48 | |
openstackgerrit | Merged openstack/security-doc master: add info about expired tokens validation https://review.openstack.org/614871 | 20:52 |
*** openstackgerrit has quit IRC | 20:56 | |
*** threestrands has joined #openstack-security | 21:36 | |
*** rcernin has joined #openstack-security | 22:02 | |
*** threestrands has quit IRC | 23:04 | |
*** threestrands has joined #openstack-security | 23:56 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!