Live data from Hacker News

Nix 2.24 is vulnerable to (remote) privilege escalation

puckipedia.com

51–60 of 81 posts

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#51
post #43

Earlier quoted context omitted.

I think it is https://github.com/NixOS/nix/commit/12fa019ae558641df0a23a79...

How can such a simple code change fixes such a big vulnerability?

Or maybe it's https://github.com/NixOS/nix/commit/35575873813f60fff26f27a6...

the commit log is tad unclear and the GHSA writer didn't bother themselves with linking the offending code

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#52

Earlier quoted context omitted.

I have not been following closely this back story, so I am not aware of such ban, or that (allegedly) Lix is Pierre Bourdon’s software. I am not affiliated with Nix (Cppnix) or Lix.

Why call it "Cppnix"?

It helps disambiguate Nixlang from the codebase that includes the Nix CLI and the Nix daemon, for one. It's also an unambiguous designation for the original Nix implementation, as opposed to Lix and Tvix.

A Lix user might well reasonably say they 'use Nix' because they use Nixlang. Thus some people are Nix users but not CppNix users. As Tvix matures, the same will be true of Tvix users.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#53

Earlier quoted context omitted.

That's just flat out false. Both parties admit that the author and Nix maintainers were in touch regarding this vulnerability. Public accounts and meeting minutes prove that Nix maintainers were preparing a fix. The short deadline was only mentioned once, again separate from where the main discussion took place. There are dozens of Nix Matrix channels and so many messages being exchanged there every day. It's easy to…

We must have different definitions of “being in touch”. Sending an email and going on vacation, then actively ignoring incoming messages isn’t being in touch. And I don’t blame the person from the Nix team who went on vacation, but not forwarding the researcher to anyone else is solely on the nix team. They responded to the message in the matrix channel which included the deadline so they were well aware of it. If th…

This message was sent last Sunday in a public Matrix discussion involving the author.

> Eelco is working on it, there's a patch on the GitHub advisory, we plan to get it out on Monday, but no promises yet if everything will get done by then

https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs...

In what world is this "not being in touch," "actively ignoring messages," or "not forwarding the researcher to anyone else"? Also, Nix maintainers clearly state in the Mastodon thread that they weren't "aware" of the deadline. Very different definitions of words indeed.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#54
post #9

Earlier quoted context omitted.

> the organization that was given plenty of time One week doesn't seem like "plenty of time" to me. The guy who ack'd the initial report and created the vulnerability tracker in GitHub was on vacation.

Someone who writes a response to a security vulnerability report, includes nobody else in the discussion, then leaves for vacation within 15 minutes of sending that report is irresponsible. Giving someone a week to respond is not unreasonable. If nobody responds in a week, it can safely be assumed that they don't take security seriously, and the responsible thing is to let the community know. Spin it how you like, bu…

> If nobody responds in a week, it can safely be assumed that they don't take security seriously, and the responsible thing is to let the community know.

That's an if that did not happen:

> Eelco is working on it, there's a patch on the GitHub advisory, we plan to get it out on Monday, but no promises yet if everything will get done by then

https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs...

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#55
post #35

Earlier quoted context omitted.

Lix claims to have a more welcoming community, but I too often see prominent members gloating about every Nix bugs and implementation details on Mastodon and elsewhere so YMMV.

More welcoming how, by stabbing the heart of Eelco with shitty demands? Very welcoming.

If you look elsewhere in this thread, many of the bullies are doing PR for Lix and trying to use this situation to their advantage. What no one is disclosing to people is that their fork of nixpkgs (ForkOS) is nearly done, so pointing people to it is going to be almost entirely in their benefit. But, why would sociopaths tell people that when they can just publicly embarrass people instead?

The amount of gaslighting here is frankly astounding. There were some good developers who went over to Lix but also a few pathological liars and primary school bullies. People don't know half of the abuse going on.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#56
post #23

Earlier quoted context omitted.

Because it's written in C++ and the fork plans to rewrite in Rust?

> fork plans to rewrite in Rust Lmao. Won't ever happen.

https://git.lix.systems/lix-project/lix/src/branch/main/src/...

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#57
post #34

Earlier quoted context omitted.

Also there's too many things called Nix. There's the overall project, the language, and the primary interpretation. It's also why you'll sometimes see nixlang to refer to the language.

Thought was the norm using capitalized for language and lower case for the tooling. So Nix/nix, like AWK/awk and Go/go.

Then there is also golang

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#58
post #51

Earlier quoted context omitted.

How can such a simple code change fixes such a big vulnerability?

Or maybe it's https://github.com/NixOS/nix/commit/35575873813f60fff26f27a6... the commit log is tad unclear and the GHSA writer didn't bother themselves with linking the offending code

Thanks, that one seems likely.

Hmm, though this seems to affect the case-hack thingy only, which seems like a macos-specific feature...

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#59

Earlier quoted context omitted.

[flagged]

using "yikes" outside of reddit to concern troll is bad manners. i appreciate sharing alternative forks that fix problems.

Tone policing outside of Mastodon to concern troll is bad manners.

I don't appreciate tankies sharing their nonsense after getting kicked out of a community.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#60
post #7

Earlier quoted context omitted.

What's the difference between Nix and Lix? The website is still not entirely clear. I mean as an user, why would I want to use it (besides avoiding this vulnerability)

Lix is a (nixpkgs-compatible) fork of Nix, led by Nix community members that don't get along with the core Nix team. At this point, the primary reason to switch to Lix would be if you trusted the Lix folks more than the core Nix team

Didn't get along is an understatement. They gaslit and destroyed the little bit of leadership structure of NixOS had through harassment and bullying.
Post reply on HN