8 ms·
> the organization that was given plenty of time One week doesn't seem like "plenty of time" to me. The guy who ack'd the initial report and created the vulner
by jaculabilis 2y ago
> the organization that was given plenty of time
One week doesn't seem like "plenty of time" to me. The guy who ack'd the initial report and created the vulnerability tracker in GitHub was on vacation.
- hkmaxpro 2y agoReporter’s defense: https://lobste.rs/s/ixb3v7/nix_2_24_is_vulnerable_remote_privilege#c_v6ogj5 https://lobste.rs/s/ixb3v7/nix_2_24_is_vulnerable_remote_pri...
- johnklos 2y agoSomeone who writes a response to a security vulnerability report, includes nobody else in the discussion, then leaves for vacation within 15 minutes of sending that report is irresponsible. Giving someone a week to respond is not unreasonable. If nobody responds in a week, it can safely be assumed that they don't take security seriously, and the responsible thing is to let the community know. Spin it how you like, but the "we're too important to respond" shtick is old and tired.
- exe34 2y agothat's a bit entitled. I'm coming over for dinner, I hope you're prepared.
- saghm 2y agoThis isn't "I'm entitled to free dinner", this is "your dinner guests are getting sick from food poisoning, and you're demanding I don't tell them".
- elorm 2y agoThis is a very poor take. The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams. They actually held a meeting about the security issue earlier in the day before the disclosure and had reached out to the reporter(0). The sense of entitlement here is pretty much rank because any animosity between the Lix team and Nix teams going forward will only be to the detriment of the Lix team. Everyone's really tight at the moment and no one is paid for this much drama every couple of months. https://discourse.nixos.org/t/2024-09-09-nix-team-meeting-minutes-176-175/51852 https://discourse.nixos.org/t/2024-09-09-nix-team-meeting-mi...
- johnklos 2y ago> before the disclosure and had reached out to the reporter(0). First, the only link you provided doesn't look to be related to this issue. Edit: I see it bizarrely redirects to "https://discourse.nixos.org/t/iohk-hiring-devops-with-nix-experience/2024 https://discourse.nixos.org/t/iohk-hiring-devops-with-nix-ex...". What happened to the minutes? Second, I understand that it's run by volunteers, that they might not have the humanpower they need, and so on - as a volunteer who spends a good bit of time working on an open source project, I get it - but if someone's about to go on vacation, they shouldn't just fire off an email with no information and leave. They should reply with information: "I'm leaving for vacation and we have no other people to handle this", or "I can't do anything myself for the next week, but let's cc someone else", or something. Also, when they finally did reach out, they didn't say it was being worked on, nor did they ask for an extension, nor give any kind of timeframe. Creating a point release means volunteers were working on things, and releasing it without the fix means they didn't take the security report seriously. Unless someone shows me something that doesn't point to a completely opaque process, I have to say I would likely've done the same thing. After all, if I reported something to an organization, and the organization didn't assure me they were working on it and offer some kind of time frame, and in the meanwhile released an update that didn't have a fix, I'd take that at face value: they just don't care about security (or don't understand the security implications, which is even worse - there's nothing wrong with being ignorant about a thing, but deciding to do nothing about a thing because of ignorance is inexcusable). So was puck being malicious by releasing this information? I don't think so. If I were a Nix user, I'd want to know about a security issue that might affect me, so I'd welcome this as someone trying to help Nix users. If it hurts the Nix organization, then tough cookies. They should've taken action and communicated better. Is the issue even fixed yet?
- soraminazuki 2y ago> If nobody responds in a week, it can safely be assumed that they don't take security seriously, and the responsible thing is to let the community know. That's an if that did not happen: > Eelco is working on it, there's a patch on the GitHub advisory, we plan to get it out on Monday, but no promises yet if everything will get done by then https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKsyTUyCN9V_QvL21_rIt2zahFvw3KNujN8aI https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs...
- abhinavk 2y agoMore context: > The vulnerability report doesn’t mention it directly, but the discussion thread about it on Fedi gives some more context on that deadline: the reporter has had several previous vulnerability reports completely ignored by the Nix development team, including one open since February and still untriaged. The Nix development team received and acknowledged this new Nix 2.24 vulnerability on August 30th (so, > 9 days ago) and they seem to have mostly sat on it until today (the reporter received no further comms), to the extent that a new point release of Nix was released a few days after the vuln was reported and did not contain a fix. Source: https://lobste.rs/s/ixb3v7/nix_2_24_is_vulnerable_remote_privilege#c_qbpdlv https://lobste.rs/s/ixb3v7/nix_2_24_is_vulnerable_remote_pri... The first one from Feb: https://matrix-client.matrix.org/_matrix/media/v3/download/puck.moe/d3352f2cf9d9a0e84b9d551121335a043cc9971898783d711c266638be5a2e67?allow_redirect=true https://matrix-client.matrix.org/_matrix/media/v3/download/p... It's a community project run by volunteers but I don't think such response ("Impact: blabla") to a vulnerability gives a good impression to your users.
- myst1c 2y agoThis is a "both things are true" situation. There is a group working to smear Nix, Eelco, and everyone related to the project who are now playing the innocent victims and pretending they didn't sign a letter that started with the words "Eelco Dolstra’s leadership is corrosive to the Nix project." This is where people citing GH issue templates that contain "blabla" reinforces the narrative that the people who were working with Puck to solve the issue before she dropped a zero-day in public are somehow irresponsible. It is just that - a narrative. Everyone cannot stop staring at the sheer amount of narcissism on display in support of this narrative. The grain of truth is that it's probably not Puck's fault, and the security disclosure process could also be improved since it's evident a ball was accidentally dropped somewhere. More points of constant contact involved in solving these problems are good for everyone.