*** macz_ has quit IRC | 02:04 | |
*** priteau has quit IRC | 02:59 | |
*** gouthamr has quit IRC | 02:59 | |
*** gouthamr has joined #openstack-security | 03:01 | |
*** gouthamr has quit IRC | 03:01 | |
*** gouthamr has joined #openstack-security | 03:02 | |
*** gouthamr has quit IRC | 03:02 | |
*** star_cloud has quit IRC | 03:03 | |
*** gouthamr has joined #openstack-security | 03:03 | |
*** gouthamr has quit IRC | 03:03 | |
*** gouthamr has joined #openstack-security | 03:04 | |
*** gouthamr has quit IRC | 03:04 | |
*** gouthamr has joined #openstack-security | 03:04 | |
*** gouthamr has quit IRC | 03:04 | |
*** gouthamr has joined #openstack-security | 03:05 | |
*** gouthamr has quit IRC | 03:05 | |
*** gouthamr has joined #openstack-security | 03:06 | |
*** gouthamr has quit IRC | 03:06 | |
*** gouthamr has joined #openstack-security | 03:07 | |
*** gouthamr has quit IRC | 03:07 | |
*** gouthamr has joined #openstack-security | 03:11 | |
*** gouthamr has quit IRC | 03:11 | |
*** gouthamr has joined #openstack-security | 03:17 | |
*** gouthamr has quit IRC | 03:17 | |
*** gouthamr has joined #openstack-security | 03:22 | |
*** gouthamr has quit IRC | 03:22 | |
*** gouthamr has joined #openstack-security | 03:28 | |
*** gouthamr has quit IRC | 03:28 | |
*** gouthamr has joined #openstack-security | 03:32 | |
*** gouthamr has quit IRC | 03:32 | |
*** rcernin has quit IRC | 03:36 | |
*** gouthamr has joined #openstack-security | 03:38 | |
*** gouthamr has quit IRC | 03:38 | |
*** gouthamr has joined #openstack-security | 03:43 | |
*** gouthamr has quit IRC | 03:43 | |
*** gouthamr has joined #openstack-security | 03:49 | |
*** gouthamr has quit IRC | 03:49 | |
*** gouthamr has joined #openstack-security | 03:53 | |
*** gouthamr has quit IRC | 03:53 | |
*** gouthamr has joined #openstack-security | 03:59 | |
*** gouthamr has quit IRC | 03:59 | |
*** rcernin has joined #openstack-security | 04:16 | |
*** gouthamr has joined #openstack-security | 04:25 | |
*** gouthamr has quit IRC | 04:26 | |
*** gouthamr has joined #openstack-security | 05:00 | |
*** gouthamr has quit IRC | 05:00 | |
*** macz_ has joined #openstack-security | 05:10 | |
*** gyee has quit IRC | 05:15 | |
*** macz_ has quit IRC | 05:15 | |
*** gouthamr has joined #openstack-security | 05:26 | |
*** macz_ has joined #openstack-security | 05:48 | |
*** macz_ has quit IRC | 05:52 | |
*** gouthamr has joined #openstack-security | 06:00 | |
*** macz_ has joined #openstack-security | 06:09 | |
*** macz_ has quit IRC | 06:14 | |
*** macz_ has joined #openstack-security | 07:53 | |
*** macz_ has quit IRC | 07:57 | |
*** rcernin has quit IRC | 07:58 | |
*** rcernin has joined #openstack-security | 08:02 | |
*** rcernin has quit IRC | 08:07 | |
*** macz_ has joined #openstack-security | 08:14 | |
*** macz_ has quit IRC | 08:19 | |
*** rcernin has joined #openstack-security | 08:49 | |
*** rcernin has quit IRC | 08:53 | |
*** macz_ has joined #openstack-security | 08:55 | |
*** macz_ has quit IRC | 09:00 | |
*** macz_ has joined #openstack-security | 09:16 | |
*** macz_ has quit IRC | 09:21 | |
*** macz_ has joined #openstack-security | 09:58 | |
*** macz_ has quit IRC | 10:03 | |
*** macz_ has joined #openstack-security | 10:19 | |
*** macz_ has quit IRC | 10:24 | |
*** macz_ has joined #openstack-security | 10:40 | |
*** macz_ has quit IRC | 10:45 | |
*** macz_ has joined #openstack-security | 11:01 | |
*** macz_ has quit IRC | 11:05 | |
*** priteau has joined #openstack-security | 11:35 | |
*** macz_ has joined #openstack-security | 11:42 | |
*** macz_ has quit IRC | 11:47 | |
*** macz_ has joined #openstack-security | 12:24 | |
*** macz_ has quit IRC | 12:29 | |
*** macz_ has joined #openstack-security | 13:06 | |
*** macz_ has quit IRC | 13:10 | |
*** macz_ has joined #openstack-security | 13:27 | |
*** macz_ has quit IRC | 13:31 | |
*** macz_ has joined #openstack-security | 13:47 | |
*** macz_ has quit IRC | 13:52 | |
*** macz_ has joined #openstack-security | 14:29 | |
*** macz_ has quit IRC | 14:34 | |
*** macz_ has joined #openstack-security | 14:50 | |
*** macz_ has quit IRC | 14:54 | |
*** dave-mccowan has joined #openstack-security | 15:11 | |
*** macz_ has joined #openstack-security | 16:56 | |
*** macz_ has quit IRC | 17:01 | |
*** macz_ has joined #openstack-security | 17:17 | |
*** macz_ has quit IRC | 17:22 | |
*** macz_ has joined #openstack-security | 18:09 | |
*** macz_ has quit IRC | 18:14 | |
*** macz_ has joined #openstack-security | 18:30 | |
*** macz_ has quit IRC | 18:35 | |
*** xarlos has joined #openstack-security | 18:47 | |
fungi | gagehugo: ooh, i should have brought it up in the meeting, but google has been making a big splash about these new guidelines and they include a shout out to our work! https://github.com/google/oss-vulnerability-guide/blob/main/guide.md#acknowledgements | 19:58 |
---|---|---|
fungi | "Thank you to the wider security and open source communities whose work informed this guide, including the OpenStack Vulnerability Management Process..." | 19:58 |
fungi | (we got top billing) | 19:58 |
*** gyee has joined #openstack-security | 20:18 | |
gagehugo | awesome | 20:45 |
*** rcernin has joined #openstack-security | 23:03 | |
*** rcernin has quit IRC | 23:11 | |
*** rcernin has joined #openstack-security | 23:12 | |
* gouthamr applauds - that's pretty cool 8) | 23:18 | |
gouthamr | the VMT process has been so well thought about and documented | 23:19 |
gouthamr | thanks for your work on that \o/ | 23:19 |
portdirect | fungi - gagehugo is about to learn no good deed goes unpunished :) | 23:21 |
portdirect | sorry gagehugo - kinda put you on the spot here internally ;) | 23:21 |
gagehugo | sigh | 23:22 |
portdirect | but congrats fungi, gouthamr, gagehugo and everyone else whos worked on this - really nice work | 23:22 |
portdirect | while im here, can i moan about oslo.privsep? | 23:22 |
gouthamr | ^ barely did anything, i followed the process and bugged fungi a ton :) | 23:22 |
portdirect | or perhaps just my understanding of it | 23:22 |
portdirect | i see a few projects seem to be moving to it now | 23:23 |
fungi | moan freely | 23:23 |
portdirect | but in a containerised world - it may be scoreing an own goal (unless im missing somthing) | 23:23 |
portdirect | as we now need to add SYS_ADMIN to our containers, just so that they can drop the privileges we had to give them... | 23:24 |
fungi | seems like that should be something it can autodetect and turn into a noop, yeah | 23:24 |
fungi | like don't try to drop privileges if SYS_ADMIN isn't available | 23:25 |
fungi | that's generally a sign the deployer has already thought about this problem | 23:25 |
portdirect | confused me when i moved to victoria - and had to grant sys_admin to glance of all things :) | 23:26 |
fungi | i think it's probably worth a broader discussion on the ml. having to increase your permission exposure to satisfy a subsystem geared toward reducing that exposure is counterproductive | 23:27 |
portdirect | yeah - I'll collect my thoughts and get somthing out either tomorrow, or start of next week | 23:27 |
portdirect | thx | 23:27 |
fungi | though i can't immediately think of a reason why it shouldn't be fixable in oslo.privsep | 23:27 |
fungi | but it's been a long time since i looked in there | 23:28 |
portdirect | ^^ pretty sure somthing like what you suggested is whats required | 23:28 |
fungi | folks much more in tune with its internals than me will probably be quick to point out where my suggestion is naive ;) | 23:29 |
portdirect | if no SYS_ADMIN and/or a config to the effect of 'i_manage_my_own_capabilities_thank_you_please' | 23:29 |
fungi | i recall having the privilege-dropping discussion very early in the design for it, and i suggested folks look at the (then somewhat novel) privilege separation openbsd put in opensshd, but yeah that was a long time ago and since then we've got these nice wrapper controls around fine-grained privilege control in our systems | 23:31 |
fungi | so it's certainly reasonable to assume that an operator has taken advantage of those fine tools to craft their own privilege policies external to our software | 23:32 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!