13:00:42 #startmeeting Security Team Meeting - Agenda: https://fedoraproject.org/wiki/Security_Team_meetings 13:00:42 Meeting started Thu Oct 30 13:00:42 2014 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 13:00:42 Useful Commands: #action #agreed #halp #info #idea #link #topic. 13:00:45 #meetingname Fedora Security Team 13:00:45 The meeting name has been set to 'fedora_security_team' 13:00:58 Sparks: Hi, 13:00:59 #topic Roll call 13:01:54 Hi! 13:02:22 * mhayden hops in 13:05:13 * jrusnack here 13:06:19 Okay... lets get started. 13:06:26 #info Participants are reminded to make liberal use of #info #link #help in order to make the minutes "more better" 13:06:32 #topic Meeting time 13:06:42 #info Currently we meet at 13:00UTC. After daylight savings expires this weekend (US) we'll change to 14:00UTC. 13:06:50 Anyone have any problems with this? 13:07:07 that sounds good to me 13:07:12 fine for me 13:07:21 * mhayden is horrible at TZ conversions :/ 13:07:26 Yep, good for me too. 13:07:36 mhayden: :) 13:07:42 same here, 13:08:47 Okay, moving on. 13:08:51 #topic Outstanding BZ Tickets 13:08:58 #info Wednesday's numbers: Critical 1, Important 44, Moderate 337, Low 125, Total 507, Trend -8 13:09:06 #info Current tickets owned: 182 (~36%) 13:09:11 #info Tickets closed: 144 13:09:24 Any questions or comments? 13:10:00 i'd like to get more involved with reducing those numbers, but i'm not sure about the best approach 13:11:11 mhayden: Beating the drums is always encouraged. 13:11:19 hah :) i'm familiar with that 13:11:30 is there a BZ search link i can use to find those tickets? 13:11:34 mhayden: take one of the open ones by assigning it to yourself, 13:12:24 https://fedoraproject.org/wiki/Security_Team#Contact 13:12:51 that's perfect -- thanks Sparks 13:13:32 #topic Open floor discussion/questions/comments 13:13:37 Anyone have anything? 13:13:43 Yep, 13:14:00 We plan to cover these basic of how to triage open security bugs, day after tomorrow at FAD 13:14:16 pjp: Cool 13:14:45 Sparks, is openscap absent from the wiki above, or just forgotten? 13:15:48 any suggestions for the FAD, as to which details are good to be shared, if anything we should avoid or if we should focus on any specific package/product? 13:16:11 fenrus02: ummm.. not forgotten but not really useful to us at the moment. 13:16:38 in the beginning I plan to brief the attendees about Fedora Security team, it's mission, and how we operate, and then proceed towards collective bug triaging 13:16:49 pjp: +1 13:16:50 pjp: that sounds useful 13:17:16 Not sure if you've seen it, I sent it to fedora-security list too -> https://pjps.wordpress.com/2014/10/18/fedora-activity-day-1-nov-2014-theme-security/ 13:17:34 i'd like to circle back on this thread here and talk about notifications -> https://lists.fedoraproject.org/pipermail/security/2014-October/001990.html 13:17:43 Sparks, same with 'checksec' ? 13:17:59 fenrus02: I'm not familar with checksec. Tell me about it. 13:18:28 fenrus02: i assume you mean checksec.sh, not the company? 13:18:29 IMO, we need to groom group of people who could regularly do Fedora package audits 13:18:59 Sparks, in theory, all running daemons or long-running procs have relro / pie / and several other compile time options set. checksec locates those items. it could be classified as a bug if they dont 13:19:23 fenrus02: That sounds useful. 13:19:39 Sparks, yes, it's a .sh - but packaged without the extension 13:20:02 fenrus02: please feel free to add it to the wiki, 13:20:12 fenrus02: That's the script that checks for NX, etc. Right? 13:20:17 yes. 13:20:55 fenrus02: Heard of checksec2? 13:21:02 no? 13:21:13 not packaged? 13:21:31 links ? 13:21:54 pjp, added. 13:22:07 fenrus02: thank you. 13:23:29 fenrus02: Looking 13:23:31 The tools/resources sections is meant to collate useful security tools, anything that fits that bill is good to be listed there 13:24:06 https://github.com/kholia/checksec 13:24:07 Sparks: dang, checksec2 is handy 13:24:37 Sparks: http://jacekalex.sh.dug.net.pl/checksec2 ? 13:25:25 pjp: Yes! 13:26:35 seems that http://jacekalex.sh.dug.net.pl/checksec2 is older than http://www.trapkit.de/tools/checksec.html (which is packaged) 13:30:24 fenrus02: I think checksec2 has some added features. 13:30:46 So, any suggestions for the upcoming FAD, if you'd like me to cover anything specific or triage bugs for any package/product etc. please let me know, 13:30:54 fenrus02: But I haven't been following that. I just happened to have a Product Security ninja on the phone when you asked. 13:31:01 Sparks, that would be odd. the trapkit version lists the jacekalex as a predecessor 13:31:53 fenrus02: What would be odd? 13:32:53 Sparks, the url above listed as 'checksec2' (v1.3) is listed in the history changelog of the url above labeled as 'checksec' (v1.5). 13:33:44 fenrus02: Oh, maybe they came together. I really don't know. 13:34:45 For anyone who uses Drupal. #link https://www.drupal.org/PSA-2014-003 13:34:58 Sparks, nor i. just reading the urls changelogs above. your ninja would know more 13:35:05 The EPEL packages are a little behind, but it looks like they're in testing. 13:35:33 bvincent: People still use Drupal? 13:35:35 * Sparks runs 13:35:44 :) 13:36:07 Sparks: A certain university does. 13:36:29 bvincent: A certain open source company does, too. 13:37:00 fenrus02: I'll see if I can find out anything. 13:37:06 Sparks: Drupal becomes so over customized, I never can pick the sites out anymore. 13:37:21 Sparks: Typically the fixed header should have given it away. Ha. 13:38:55 #action Sparks to follow up with fenrus02 (via the security list) on checksec and checksec2. 13:39:03 Anyone have anything else? 13:39:56 Not me, 13:43:29 i'll defer on my mailing list topic until i can figure out a suggested solution 13:44:34 mhayden: I guess those are the security update announcements via bodhi, right? 13:44:59 right -- just trying to think of something a bit more consumable for companies and individual users who depend on fedora daily 13:45:11 * mhayden is building a product at $dayjob on fedora ;) 13:45:23 Cool! 13:45:32 mhayden: they have RSS feeds too I think, 13:45:59 i had originally tied the RSS feeds from https://admin.fedoraproject.org/updates/ to a twitter account (@fedorasecurity) 13:46:13 but then the script fell apart and someone from RHT's sec team asked for the account -- i transferred it 13:46:34 Oh, 13:46:42 err. 13:46:56 nevermind. I'll need to see how feasible this is first. 13:46:57 :) 13:47:10 Okay, I'm closing it up unless someone has something else. 13:47:11 mhayden: I think that would be revskills ? 13:47:24 jrusnack: you might be right, i'd have to dig through emails ;) 13:47:38 Sparks: feel free to close, i'm just rambling 13:48:10 Okay, we can ramble over in #fedora-security-team 13:48:16 Everyone have a good day! 13:48:17 :) 13:48:22 Thank you. 13:48:22 #endmeeting