Earlier quoted context omitted.
> This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people. Might it have something to do with the culture of bullying and intimidation that you were responsible for on the Discourse? [1] https://discourse.nixos.org/t/lix-an-independent-variant-of-...
And this? https://discourse.nixos.org/t/delroths-muting-in-the-moderat...
Nix 2.24 is vulnerable to (remote) privilege escalation
71–80 of 81 posts
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#72Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#73Earlier quoted context omitted.
Can't tell what happened to the earlier link but I've fixed the it. Puck was being malicious in releasing the information . There's no favourable way of describing disclosing a vulnerability on social media because the maintainers didn't meet your 7 day deadline. It's more of "we're forcing their hands since they haven't met our expectations yet" thing. There's so many ways they could've gotten a timely fix without "…
Calling the reporter malicious is not constructive and does not help Nix (even if you are right). From all I can tell, there was no request to extend the deadline or proactively coordinating disclosure when the reporter pushed for it. That would have been preferred and could have avoided this situation. I would hope for a later postmortem incorporating the lesson of more proactive communication with reporters.
https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs...
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#74Earlier quoted context omitted.
Calling the reporter malicious is not constructive and does not help Nix (even if you are right). From all I can tell, there was no request to extend the deadline or proactively coordinating disclosure when the reporter pushed for it. That would have been preferred and could have avoided this situation. I would hope for a later postmortem incorporating the lesson of more proactive communication with reporters.
That the Nix team didn’t cooperate is a trivially disprovable excuse being pushed by people surrounding the fork. https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs...
> > is there any update on the root escalation vulnerability in 2.24?
> Eelco is working on it, there's a patch on the GitHub advisory, we plan to get it out on Monday, but no promises yet if everything will get done by then
This is what I mean is not sufficient in terms of disclosure coordination... Doesn't seem like anyone was necessarily acting in bad faith, just mutual frustration and room for improvement on professionalism on all sides. Though I'd hold NixOS maintainers to a higher expectation of professionalism than random independent security researchers. The important thing is that people draw the right lessons. "The X people suck" isn't a valuable lesson for any value of X. And if you're seeing bad intent on the reporter and them trying to prove a point; well yeah, maybe, and point proven? Processes should cover for these eventualities.
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#75Earlier quoted context omitted.
That the Nix team didn’t cooperate is a trivially disprovable excuse being pushed by people surrounding the fork. https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs...
Can we please stop this polarizing drama, from both sides? I never said that anyone wasn't cooperating. Quoting your link: > > is there any update on the root escalation vulnerability in 2.24? > Eelco is working on it, there's a patch on the GitHub advisory, we plan to get it out on Monday, but no promises yet if everything will get done by then This is what I mean is not sufficient in terms of disclosure coordinatio…
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#76Earlier quoted context omitted.
I have not been following closely this back story, so I am not aware of such ban, or that (allegedly) Lix is Pierre Bourdon’s software. I am not affiliated with Nix (Cppnix) or Lix.
Why call it "Cppnix"?
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#77Earlier quoted context omitted.
Can we please stop this polarizing drama, from both sides? I never said that anyone wasn't cooperating. Quoting your link: > > is there any update on the root escalation vulnerability in 2.24? > Eelco is working on it, there's a patch on the GitHub advisory, we plan to get it out on Monday, but no promises yet if everything will get done by then This is what I mean is not sufficient in terms of disclosure coordinatio…
The thing is, the reporter is not a random independent security researcher. She's a core team member of Lix, the fork, and is no stranger to the Nix community. This incident directly relates to the wider conflict between the two projects. That's why people are upset.
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#78Earlier quoted context omitted.
> This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people. Might it have something to do with the culture of bullying and intimidation that you were responsible for on the Discourse? [1] https://discourse.nixos.org/t/lix-an-independent-variant-of-...
I've clicked through a bunch of your references and am yet to see any of the "bullying" you keep talking about across the thread... Please be more concrete and on-point or this is just ad-hominems, insinuations and drama...
> For example, you were able to dedicate two hours twice a week to attending meetings that you were not welcome at. A lot of people were not able to do that; they did not have the time or energy levels to be able to afford that in the first place.
> What I’m trying to say here is: yes, your situation sucked, and it should not have been necessary. But imagine how much more this might have sucked for other people who did not even have the affordances that you had to cope with this(...)
Then the other person:
> Your projects had multiple issues that were clear and apparent to outsiders that leaked outside your team and had to become a Nixpkgs problem (as I had to become against my own will a Nix maintainer in Nixpkgs). You never acted on that, you never took the necessary actions to show that you (:= your team) know how to manage an open source project.
(...)
> I feel you on the sadness. I am sorry you feel like this. Likewise, I remember what it was for me for the past year to feel like shit when I received this message
This is pretty classic abusive breaking someone down to build them up and tell them how the abuser was much worse off, and the reports from several meetings are much worse. Hitlists of people to remove from the project, that sort of thing. The power games going on are frankly sick, and the most unprofessional thing I have ever heard of in an open source project.
All I'm saying: try to get the other side's perspective. I think there are many people tired of this behavior. When it is presented with a one-sided perspective, the solution seems obvious, but this hostility has colored the past few months of interaction in the Nix community.
[1] https://discourse.nixos.org/t/objection-to-minority-represen...
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#79Earlier quoted context omitted.
The thing is, the reporter is not a random independent security researcher. She's a core team member of Lix, the fork, and is no stranger to the Nix community. This incident directly relates to the wider conflict between the two projects. That's why people are upset.
So you're saying out loud that the person reporting the issue matters. It shouldn't matter who tells you that you have a security issue.
Again,
https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs...
What I meant is crystal clear if you read what I was replying to. Please don't take it out of context to spin a story. You did it in your original comment, and you did it again right here.
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#80Earlier quoted context omitted.
So you're saying out loud that the person reporting the issue matters. It shouldn't matter who tells you that you have a security issue.
Nobody ever said it isn't okay to report security issues. This is about dumping 0 days on social media when you know fully well that the other side is cooperating and working on a fix. The who in this case matters because the reporter knew how the Nix community works, knew it was hostile thing to do, and did it anyways. Again, https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs... What I meant is crystal cle…
Ignoring that, I agree that it's a dick move, but it's like our famous "well, technically" memes - the delivery might matter, but in the case of security issues, it really doesn't matter as much as the actual content.
"You have an issue, and I'm going to be a dick and release it in a week."
Yes, that would be a dick move, but someone acting like a dick doesn't mean that the Nix team shouldn't address the issue within that week, even if it does feel like extortion.
Also, those matrix links say nothing. I'm not sure what we're supposed to do with them, but I'm not downloading software to see whatever it is you want to share.