5 ms·
This is a very poor take. The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware,
by elorm 2y ago
This is a very poor take.
The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams.
They actually held a meeting about the security issue earlier in the day before the disclosure and had reached out to the reporter(0).
The sense of entitlement here is pretty much rank because any animosity between the Lix team and Nix teams going forward will only be to the detriment of the Lix team. Everyone's really tight at the moment and no one is paid for this much drama every couple of months.
https://discourse.nixos.org/t/2024-09-09-nix-team-meeting-minutes-176-175/51852 https://discourse.nixos.org/t/2024-09-09-nix-team-meeting-mi...
- johnklos 2y ago> before the disclosure and had reached out to the reporter(0). First, the only link you provided doesn't look to be related to this issue. Edit: I see it bizarrely redirects to "https://discourse.nixos.org/t/iohk-hiring-devops-with-nix-experience/2024 https://discourse.nixos.org/t/iohk-hiring-devops-with-nix-ex...". What happened to the minutes? Second, I understand that it's run by volunteers, that they might not have the humanpower they need, and so on - as a volunteer who spends a good bit of time working on an open source project, I get it - but if someone's about to go on vacation, they shouldn't just fire off an email with no information and leave. They should reply with information: "I'm leaving for vacation and we have no other people to handle this", or "I can't do anything myself for the next week, but let's cc someone else", or something. Also, when they finally did reach out, they didn't say it was being worked on, nor did they ask for an extension, nor give any kind of timeframe. Creating a point release means volunteers were working on things, and releasing it without the fix means they didn't take the security report seriously. Unless someone shows me something that doesn't point to a completely opaque process, I have to say I would likely've done the same thing. After all, if I reported something to an organization, and the organization didn't assure me they were working on it and offer some kind of time frame, and in the meanwhile released an update that didn't have a fix, I'd take that at face value: they just don't care about security (or don't understand the security implications, which is even worse - there's nothing wrong with being ignorant about a thing, but deciding to do nothing about a thing because of ignorance is inexcusable). So was puck being malicious by releasing this information? I don't think so. If I were a Nix user, I'd want to know about a security issue that might affect me, so I'd welcome this as someone trying to help Nix users. If it hurts the Nix organization, then tough cookies. They should've taken action and communicated better. Is the issue even fixed yet?
- elorm 2y agoCan't tell what happened to the earlier link but I've fixed the it. Puck was being malicious in releasing the information. There's no favourable way of describing disclosing a vulnerability on social media because the maintainers didn't meet your 7 day deadline. It's more of "we're forcing their hands since they haven't met our expectations yet" thing. There's so many ways they could've gotten a timely fix without "doing everyone a favour by not fully disclosing the entire 0 day." approach but like you said .... tough cookies all round. And to answer your final question, there's a patch available. https://github.com/NixOS/nixpkgs/pull/340885 https://github.com/NixOS/nixpkgs/pull/340885
- NotEvil 2y agoThat's not a patch. It's just downgrades the nix version to 23 in nixpkgs. It doesn't help people who are already using the vulnerable version and also new users cuz installers install latest versions
- grayhatter 2y ago> Puck was being malicious in releasing the information. [citation needed] > There's no favourable way of describing disclosing a vulnerability on social media because the maintainers didn't meet your 7 day deadline. personally I'm grateful he didn't sit on a remote privexc vulnerability for 90days when he was confident it wasn't going to be fixed. I think you're conflating public disclosure (security though obscurity) with real harm, compromise due to the bug. If Puck found it, others who would gladly sell it for coin on the black market, would have found it.
- 3np 2y agoCalling the reporter malicious is not constructive and does not help Nix (even if you are right). From all I can tell, there was no request to extend the deadline or proactively coordinating disclosure when the reporter pushed for it. That would have been preferred and could have avoided this situation. I would hope for a later postmortem incorporating the lesson of more proactive communication with reporters.
- RaitoBezarius 2y ago> The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams. This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people. When challenged about this inevitable situation of depleted labor, the answer of people involved in leadership was, "It's OK, we will have new people joining us anyway.". Lix has been trying to connect with the Nix maintenance team, with very timid results from the Nix side. We continue to hope this will lead to a better cooperation. Also, you say that they are "unpaid volunteers", the Nix maintenance team is composed of folks who have full-time responsibilities in VC companies who sells Nix-based products.
- myst1c 2y ago> This is not true, there have been many vacant positions across several Nix teams because the original project has been unable to keep these people. Might it have something to do with the culture of bullying and intimidation that you were responsible for on the Discourse? [1] https://discourse.nixos.org/t/lix-an-independent-variant-of-the-nix-package-manager/44975/26 https://discourse.nixos.org/t/lix-an-independent-variant-of-...
- srid 2y agoAnd this? https://discourse.nixos.org/t/delroths-muting-in-the-moderation-matrix-room/44090 https://discourse.nixos.org/t/delroths-muting-in-the-moderat...
- deleted 2y ago[deleted]
- 3np 2y agoI've clicked through a bunch of your references and am yet to see any of the "bullying" you keep talking about across the thread... Please be more concrete and on-point or this is just ad-hominems, insinuations and drama...
- saghm 2y ago> The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams. > The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. You may not be aware, but since a group of maintainers and contributors left earlier this year to form their own fork called "Lix," there have been many vacant positions across several Nix teams Normally I'm sympathetic to claims about people being entitled to work from open source projects, but in this instance, I don't think this is the case. If this were a request for a feature or a bug without significant security impact, expecting any sort of timeline at all would be unreasonable, but I don't see how not having enough people to work on a project would imply that users should be left vulnerable for longer. In my opinion, it's much more "entitled" to demand that a known security bug in your own code base be hidden from your users because you would prefer to keep working on whatever you're currently doing.
- grayhatter 2y ago> The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. If the nix volunteers aren't held to reasonable security defect reporting standards, why do you hold the vulnerability reporter to higher standards? I'd say, if the rule is volunteers are able to YOLO with other users' security so can the reporters right?