Live data from Hacker News

Nix 2.24 is vulnerable to (remote) privilege escalation

puckipedia.com

21–30 of 81 posts

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#21

lix [1] might be less affected. Pierre Bourdon noticed that lix refactored surrounding code 4 months ago [2], and a comment claims that this Lix commit at least patched a different vulnerability GHSA-wf4c-57rh-9pjg [3]. To use lix instead of nix, set `nix.package = pkgs.lix` in your NixOS/home-manager configurations. [1]: https://lix.systems/ [2]: https://mastodon.delroth.net/@delroth/113110218127456491 [3]: https://…

[flagged]

using "yikes" outside of reddit to concern troll is bad manners.

i appreciate sharing alternative forks that fix problems.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#22
post #7

Earlier quoted context omitted.

What's the difference between Nix and Lix? The website is still not entirely clear. I mean as an user, why would I want to use it (besides avoiding this vulnerability)

Lix is a (nixpkgs-compatible) fork of Nix, led by Nix community members that don't get along with the core Nix team. At this point, the primary reason to switch to Lix would be if you trusted the Lix folks more than the core Nix team

Lix claims to have a more welcoming community, but I too often see prominent members gloating about every Nix bugs and implementation details on Mastodon and elsewhere so YMMV.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#23

Earlier quoted context omitted.

I have not been following closely this back story, so I am not aware of such ban, or that (allegedly) Lix is Pierre Bourdon’s software. I am not affiliated with Nix (Cppnix) or Lix.

Why call it "Cppnix"?

Because it's written in C++ and the fork plans to rewrite in Rust?

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#24
post #14
post #9

Earlier quoted context omitted.

Someone who writes a response to a security vulnerability report, includes nobody else in the discussion, then leaves for vacation within 15 minutes of sending that report is irresponsible. Giving someone a week to respond is not unreasonable. If nobody responds in a week, it can safely be assumed that they don't take security seriously, and the responsible thing is to let the community know. Spin it how you like, bu…

This is a very poor take. The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams. They actually held a meeting about the security issue earlier in the day before the di…

> The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams.

This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people. When challenged about this inevitable situation of depleted labor, the answer of people involved in leadership was, "It's OK, we will have new people joining us anyway.".

Lix has been trying to connect with the Nix maintenance team, with very timid results from the Nix side. We continue to hope this will lead to a better cooperation.

Also, you say that they are "unpaid volunteers", the Nix maintenance team is composed of folks who have full-time responsibilities in VC companies who sells Nix-based products.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#25
post #14

Earlier quoted context omitted.

This is a very poor take. The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams. They actually held a meeting about the security issue earlier in the day before the di…

> The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams. This is not true, there have been many vacant positions across several Nix teams because the original project…

> This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people.

Might it have something to do with the culture of bullying and intimidation that you were responsible for on the Discourse?

[1] https://discourse.nixos.org/t/lix-an-independent-variant-of-...

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#26
post #18

Earlier quoted context omitted.

> before the disclosure and had reached out to the reporter(0). First, the only link you provided doesn't look to be related to this issue. Edit: I see it bizarrely redirects to " https://discourse.nixos.org/t/iohk-hiring-devops-with-nix-ex... ". What happened to the minutes? Second, I understand that it's run by volunteers, that they might not have the humanpower they need, and so on - as a volunteer who spends a go…

Can't tell what happened to the earlier link but I've fixed the it. Puck was being malicious in releasing the information . There's no favourable way of describing disclosing a vulnerability on social media because the maintainers didn't meet your 7 day deadline. It's more of "we're forcing their hands since they haven't met our expectations yet" thing. There's so many ways they could've gotten a timely fix without "…

That's not a patch. It's just downgrades the nix version to 23 in nixpkgs.

It doesn't help people who are already using the vulnerable version and also new users cuz installers install latest versions

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#27
post #2

I don't get why someone who responded to this calls this something other than responsible disclosure. puck clearly writes, "at this point the disclosure timeline has passed". It's on Nix to meet the disclosure timeline. Missing that is Nix being irresponsible, not puck. I see this often, and it's not a good look when people would rather punish the reporter of an issue rather than the organization that was given plent…

If you know that much about the ongoing disagreements, you know very well that the volunteers weren’t given “plenty of time.” The author deliberately chose a short deadline and admits that. That deadline wasn’t known to Nix core team members because it wasn’t mentioned where the main discussion took place. This is all public information available in the linked Mastodon thread. If you’re going to choose a short deadli…

The deadline was literally publicly available in the public matrix channel which anyone can read even without a matrix account. The reporter also said they were willing to extend the deadline, if the nix team reached out. They didn’t and chose to ignore the publicly available messages. Given past experiences (it’s not the first vulnerability that was outright ignored) I think it’s fair to say “you have a week to respond, otherwise I’m dropping the vuln”. If only they responded and said “hey, we’re working on this but we need more time” nothing would’ve happened. But they didn’t.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#28
post #2

I don't get why someone who responded to this calls this something other than responsible disclosure. puck clearly writes, "at this point the disclosure timeline has passed". It's on Nix to meet the disclosure timeline. Missing that is Nix being irresponsible, not puck. I see this often, and it's not a good look when people would rather punish the reporter of an issue rather than the organization that was given plent…

I reported to Alpine that the security tracker has an incorrect approach of correlating packages and CVEs. At the time the security tracker had incorrect data for over 6 months without anyone caring about it.

I forked it on their gitlab, patched it, and merge requested it.

Nothing happened 3 years later, still the same. And they still doxx me from time to time. Mostly on github and shitter, so I don't see it early enough anyways to react to it.

Assholes are always gonna be assholes online. The only way to deal with this is to walk away and not care about those toxic communities. There's better places on the internet and your time is just wasted effort in those chan-like areas.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#29

It seems like a binary cache can already get root on your system - it is serving you binaries to run, often as root. Don't authorize a binary cache you don't trust.

> It seems like a binary cache can already get root on your system

No, rootless Nix is pretty well supported.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#30
post #2

I don't get why someone who responded to this calls this something other than responsible disclosure. puck clearly writes, "at this point the disclosure timeline has passed". It's on Nix to meet the disclosure timeline. Missing that is Nix being irresponsible, not puck. I see this often, and it's not a good look when people would rather punish the reporter of an issue rather than the organization that was given plent…

I reported to Alpine that the security tracker has an incorrect approach of correlating packages and CVEs. At the time the security tracker had incorrect data for over 6 months without anyone caring about it. I forked it on their gitlab, patched it, and merge requested it. Nothing happened 3 years later, still the same. And they still doxx me from time to time. Mostly on github and shitter, so I don't see it early en…

> And they still doxx me from time to time. Mostly on github and shitter, so I don't see it early enough anyways to react to it.

I'm somewhat glad I'm not the only one with problems like this in the Alpine community.

Post reply on HN