Live data from Hacker News

Nix 2.24 is vulnerable to (remote) privilege escalation

puckipedia.com

61–70 of 81 posts

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#61
post #60

Earlier quoted context omitted.

Lix is a (nixpkgs-compatible) fork of Nix, led by Nix community members that don't get along with the core Nix team. At this point, the primary reason to switch to Lix would be if you trusted the Lix folks more than the core Nix team

Didn't get along is an understatement. They gaslit and destroyed the little bit of leadership structure of NixOS had through harassment and bullying.

Watch out, they may call you the problem when they're accidentally talking about themselves...

It's very bad and one can simply look through the Discourse and GitHub issues from earlier this year to discover the full extent of the problem. Watch how they turn a security issue into PR now, this is just a microcosm of the dishonesty.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#62
post #48
post #11

Earlier quoted context omitted.

that's a bit entitled. I'm coming over for dinner, I hope you're prepared.

This isn't "I'm entitled to free dinner", this is "your dinner guests are getting sick from food poisoning, and you're demanding I don't tell them".

it's free food.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#63
post #25

Earlier quoted context omitted.

> The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams. This is not true, there have been many vacant positions across several Nix teams because the original project…

> This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people. Might it have something to do with the culture of bullying and intimidation that you were responsible for on the Discourse? [1] https://discourse.nixos.org/t/lix-an-independent-variant-of-...

And this?

https://discourse.nixos.org/t/delroths-muting-in-the-moderat...

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#64
post #60

Earlier quoted context omitted.

Lix is a (nixpkgs-compatible) fork of Nix, led by Nix community members that don't get along with the core Nix team. At this point, the primary reason to switch to Lix would be if you trusted the Lix folks more than the core Nix team

Didn't get along is an understatement. They gaslit and destroyed the little bit of leadership structure of NixOS had through harassment and bullying.

I think you are referring to 4 out of 5 NixOS board members quitting

https://old.reddit.com/r/NixOS/comments/1dqn9os/4_out_of_5_n...

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#65
post #18

Earlier quoted context omitted.

> before the disclosure and had reached out to the reporter(0). First, the only link you provided doesn't look to be related to this issue. Edit: I see it bizarrely redirects to " https://discourse.nixos.org/t/iohk-hiring-devops-with-nix-ex... ". What happened to the minutes? Second, I understand that it's run by volunteers, that they might not have the humanpower they need, and so on - as a volunteer who spends a go…

Can't tell what happened to the earlier link but I've fixed the it. Puck was being malicious in releasing the information . There's no favourable way of describing disclosing a vulnerability on social media because the maintainers didn't meet your 7 day deadline. It's more of "we're forcing their hands since they haven't met our expectations yet" thing. There's so many ways they could've gotten a timely fix without "…

Calling the reporter malicious is not constructive and does not help Nix (even if you are right). From all I can tell, there was no request to extend the deadline or proactively coordinating disclosure when the reporter pushed for it. That would have been preferred and could have avoided this situation. I would hope for a later postmortem incorporating the lesson of more proactive communication with reporters.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#66

Earlier quoted context omitted.

[flagged]

I have not been following closely this back story, so I am not aware of such ban, or that (allegedly) Lix is Pierre Bourdon’s software. I am not affiliated with Nix (Cppnix) or Lix.

>I have not been following closely this back story, so I am not aware of such ban

https://news.ycombinator.com/item?id=41503923

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#67
post #25

Earlier quoted context omitted.

> The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams. This is not true, there have been many vacant positions across several Nix teams because the original project…

> This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people. Might it have something to do with the culture of bullying and intimidation that you were responsible for on the Discourse? [1] https://discourse.nixos.org/t/lix-an-independent-variant-of-...

I've clicked through a bunch of your references and am yet to see any of the "bullying" you keep talking about across the thread... Please be more concrete and on-point or this is just ad-hominems, insinuations and drama...

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#68
post #67
post #25

Earlier quoted context omitted.

> This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people. Might it have something to do with the culture of bullying and intimidation that you were responsible for on the Discourse? [1] https://discourse.nixos.org/t/lix-an-independent-variant-of-...

I've clicked through a bunch of your references and am yet to see any of the "bullying" you keep talking about across the thread... Please be more concrete and on-point or this is just ad-hominems, insinuations and drama...

I've clicked through a bunch of the references and definitely see lots of crybullying and clearly breaking the CoC. There was an example where the subject of this thread was temporarily banned.

Re: Nix 2.24 is vulnerable to (remote) privilege escalation

#69
post #62
post #48

Earlier quoted context omitted.

This isn't "I'm entitled to free dinner", this is "your dinner guests are getting sick from food poisoning, and you're demanding I don't tell them".

it's free food.

So it's okay to knowingly poison people and cover up the fact, as long as you don't charge them?
Post reply on HN