--- Log opened Tue Jan 26 00:00:46 2021 |
00:05 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
00:12 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
00:12 | | mode/#code [+o Reiv] by ChanServ |
03:47 | | Degi [Degi@Nightstar-60n4ku.pool.telefonica.de] has quit [Operation timed out] |
03:48 | | Pink_ [uid208117@Nightstar-h2b233.irccloud.com] has quit [[NS] Quit: Connection closed for inactivity] |
03:51 | | Degi [Degi@Nightstar-7usc2o.dyn.telefonica.de] has joined #code |
04:34 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
04:45 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
04:45 | | mode/#code [+o Reiv] by ChanServ |
05:04 | | Netsplit Deepthought.Nightstar.Net <-> Krikkit.Nightstar.Net quits: @PinkFreud |
05:05 | | Netsplit over, joins: @PinkFreud |
05:13 | | Netsplit Deepthought.Nightstar.Net <-> Krikkit.Nightstar.Net quits: @PinkFreud |
05:15 | | Netsplit over, joins: @PinkFreud |
05:15 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
05:17 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
05:17 | | mode/#code [+o Reiv] by ChanServ |
05:20 | | Netsplit Deepthought.Nightstar.Net <-> Krikkit.Nightstar.Net quits: @PinkFreud |
05:20 | | Netsplit over, joins: @PinkFreud |
05:48 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
06:44 | | celticminstrel [celticminst@Nightstar-n1gkap.dsl.bell.ca] has quit [[NS] Quit: And lo! The computer falls into a deep sleep, to awake again some other day!] |
07:37 | | abudhabi [abudhabi@Nightstar-jc70e0.adsl.tpnet.pl] has joined #code |
07:46 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
07:46 | | mode/#code [+o Reiv] by ChanServ |
08:16 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
08:28 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
08:28 | | mode/#code [+o Reiv] by ChanServ |
08:58 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
08:59 | | mac [macdjord@Nightstar-re5.7if.45.45.IP] has joined #code |
08:59 | | mode/#code [+o mac] by ChanServ |
09:00 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
09:00 | | mode/#code [+o Reiv] by ChanServ |
09:02 | | macdjord|slep [macdjord@Nightstar-re5.7if.45.45.IP] has quit [Ping timeout: 121 seconds] |
09:29 | | macdjord|slep [macdjord@Nightstar-re5.7if.45.45.IP] has joined #code |
09:29 | | mode/#code [+o macdjord|slep] by ChanServ |
09:30 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
09:32 | | bluefoxx [fuzzylombax@Nightstar-gmbj85.vs.shawcable.net] has quit [Ping timeout: 121 seconds] |
09:33 | | mac [macdjord@Nightstar-re5.7if.45.45.IP] has quit [Ping timeout: 121 seconds] |
09:36 | | Pink [Pink@Nightstar-4dc2ar.ph.cox.net] has quit [Ping timeout: 121 seconds] |
09:59 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
09:59 | | mode/#code [+o Reiv] by ChanServ |
10:26 | | Kindamoody is now known as Kindamoody|afk |
10:27 | | bluefoxx [fuzzylombax@Nightstar-gmbj85.vs.shawcable.net] has joined #code |
10:29 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
10:52 | | catalyst_ [catalyst@Nightstar-scrrsn.dab.02.net] has joined #code |
10:54 | | catalyst [catalyst@Nightstar-ejd4sd.cable.virginm.net] has quit [Ping timeout: 121 seconds] |
11:05 | | himi [sjjf@Nightstar-v37cpe.internode.on.net] has quit [Ping timeout: 121 seconds] |
11:17 | | himi [sjjf@Nightstar-v37cpe.internode.on.net] has joined #code |
11:17 | | mode/#code [+o himi] by ChanServ |
11:27 | | catalyst [catalyst@Nightstar-ejd4sd.cable.virginm.net] has joined #code |
11:29 | | catalyst_ [catalyst@Nightstar-scrrsn.dab.02.net] has quit [Ping timeout: 121 seconds] |
11:37 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
11:37 | | mode/#code [+o Reiv] by ChanServ |
12:07 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
13:43 | | Pink [Pink@Nightstar-4dc2ar.ph.cox.net] has joined #code |
14:52 | | catalyst_ [catalyst@Nightstar-scrrsn.dab.02.net] has joined #code |
14:54 | | catalyst [catalyst@Nightstar-ejd4sd.cable.virginm.net] has quit [Ping timeout: 121 seconds] |
15:31 | | abudhabi [abudhabi@Nightstar-jc70e0.adsl.tpnet.pl] has quit [NickServ (RECOVER command used by abudhabi_)] |
15:31 | | abudhabi [abudhabi@Nightstar-qetl2p.adsl.tpnet.pl] has joined #code |
15:32 | | Kindamoody|afk is now known as Kindamoody |
15:38 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
15:38 | | mode/#code [+o Reiv] by ChanServ |
16:08 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
16:52 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
16:52 | | mode/#code [+o Reiv] by ChanServ |
16:52 | | catalyst [catalyst@Nightstar-8enj0b.dab.02.net] has joined #code |
16:54 | | catalyst_ [catalyst@Nightstar-scrrsn.dab.02.net] has quit [Ping timeout: 121 seconds] |
17:05 | | Emmy [Emmy@Nightstar-l49opt.fixed.kpn.net] has joined #code |
17:11 | <@sshine> | I just interviewed at a voluntary organization where the guy in charge is switching jobs in 4 days, and the job he is switching to is the one I interviewed for that I didn't get. |
17:12 | <@sshine> | it's a small world. |
17:22 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
17:36 | < catalyst> | huh |
18:15 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
18:15 | | mode/#code [+o Reiv] by ChanServ |
18:30 | | celticminstrel [celticminst@Nightstar-n1gkap.dsl.bell.ca] has joined #code |
18:30 | | mode/#code [+o celticminstrel] by ChanServ |
18:45 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
18:52 | | celticminstrel [celticminst@Nightstar-n1gkap.dsl.bell.ca] has quit [Ping timeout: 121 seconds] |
18:52 | | celmin [celticminst@Nightstar-kl02qd.dsl.bell.ca] has joined #code |
18:52 | | mode/#code [+o celmin] by ChanServ |
19:23 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
19:24 | | mode/#code [+o Reiv] by ChanServ |
19:42 | <&[R]> | <Sheila> https://www.openwall.com/lists/oss-security/2021/01/26/3 urgent: update `sudo` ASAP |
19:44 | <&McMartin> | Ten years between publication as open source and anyone noticing, eh |
19:45 | <@Reiv> | Good thing open source ensures better security |
19:45 | <@Reiv> | ofc if it was proprietary we'd never hear about it at all until it was a 0 day attack wouldn't we >_> |
19:45 | <&McMartin> | "Anyone noticing" includes the black hats, so it *is* still an advantage, yes |
19:46 | <&McMartin> | But I'd have to say that the era of "lol it is an obviously unbeatable and overwhelming advantage" flew out the window with Heartbleed and Shellshock |
19:46 | <&McMartin> | Shellshock still holds the record, at 25 years between publication and anyone noticing |
19:46 | <@Reiv> | Truth |
19:47 | <&McMartin> | But yeah, also that: you can detect attacks using 0days against OSS stacks the same way you do against proprietary ones |
19:47 | <&[R]> | Wasn't there an ancient as fuck Windows bug that was unearthed recently? |
19:47 | <&McMartin> | Quite possibly! I don't recall any particular one though. |
19:49 | <&[R]> | "On 2 November 2019, the first BlueKeep hacking campaign on a mass scale was reported, and included an unsuccessful <a href="/wiki/Monero_(cryptocurrency)" class="mw-redirect" title="Monero (cryptocurrency)">cryptojacking</a> mission." <3 Wikipedia |
19:50 | <&McMartin> | May 2019? That was like a thousand years ago |
19:51 | <&McMartin> | I extremely vaguely recall DejaBlue |
19:51 | <&[R]> | https://www.zdnet.com/article/printdemon-vulnerability-impacts-all-windows-versions/ <-- 24 years |
19:52 | <&McMartin> | Close to but not *quite* matching ShellShock! |
19:52 | <&McMartin> | But yeah, actually come to think of it |
19:52 | <&McMartin> | I should not be terribly surprised at bugs lying undetected for basically forever if people don't think to look for that *kind* of bug |
19:53 | <&McMartin> | That was the big lesson of the turn of the century, for which Coverity was probably the one people noticed |
19:53 | <&McMartin> | But, like, it took about a decade from C being standardized for someone to go "wait, can't you do SQL injections on printf?" |
19:54 | <@Tamber> | the "many eyes" principle, only does you any good if those eyes are looking in the right places, and have people equipped to ask the right questions. (...and if you don't then ignore/dismiss those people for whatever reason.) |
19:55 | <&McMartin> | The flaw in this cunning plan is indeed the unspoken assumption "open source gets you many eyes for free and by default" |
19:55 | <&McMartin> | Though uh |
19:56 | <&McMartin> | I have to admit that the degree to which it has not, and for critical infrastructure at that, is somewhat alarming. |
19:56 | <&McMartin> | Which means that we may have to bring in the Bystander Principle. |
19:56 | <@Tamber> | "Well, the people who built this must *obviously* have a reason for it being like that, and they'll probably just mock me if I ask about it" |
19:56 | <@Tamber> | <.< |
19:57 | <&[R]> | Know that feel |
19:58 | <&[R]> | I was asking questions about the xs shell and the author is like "read this 300 page PDF on LISP that I wrote and you'll understand" (wasn't LISP specifically, but it was a functional lang) |
19:58 | <&McMartin> | "Anybody *could* have done it, but so Nobody did." |
19:59 | <@Tamber> | "And thus, when everything burnt down overnight, it was Nobody's fault." |
19:59 | <&[R]> | There's also Linux infamously bitching about security researchers |
20:00 | <&[R]> | Linus* |
20:02 | <@Tamber> | See, this is where I think a lot of OSS projects have weilded the foot-cannon with great aplomb. If your expectation, as someone who isn't part of the in-group on a project and trying to raise an issue like this, is that you'll shouted at and mocked for the entire Internet to see, where it will duly be recorded for all eternity, for *daring* to question the Great [...] |
20:02 | <@Tamber> | [...] Leader's wisdom... ...why would you bother? |
20:03 | <@Tamber> | (Am I a touch cynical? Perhaps.) |
21:45 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
21:54 | | VirusJTG [VirusJTG@Nightstar-42s.jso.104.208.IP] has joined #code |
21:54 | | mode/#code [+ao VirusJTG VirusJTG] by ChanServ |
22:01 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
22:01 | | mode/#code [+o Reiv] by ChanServ |
22:33 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
22:48 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has joined #code |
22:48 | | mode/#code [+o Reiv] by ChanServ |
22:49 | | Reiv [NSkiwiirc@Nightstar-ih0uis.global-gateway.net.nz] has quit [[NS] Quit: http://www.kiwiirc.com/ - A hand crafted IRC client] |
22:54 | | abudhabi [abudhabi@Nightstar-qetl2p.adsl.tpnet.pl] has quit [Ping timeout: 121 seconds] |
23:24 | | catalyst [catalyst@Nightstar-8enj0b.dab.02.net] has quit [Ping timeout: 121 seconds] |
23:39 | | Vornicus [Vorn@ServerAdministrator.Nightstar.Net] has quit [Connection closed] |
23:48 | | Emmy [Emmy@Nightstar-l49opt.fixed.kpn.net] has quit [Ping timeout: 121 seconds] |
--- Log closed Wed Jan 27 00:00:48 2021 |