14:14:11 #startmeeting Security Team FAD 2016 14:14:11 Meeting started Fri Mar 11 14:14:11 2016 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:14:11 Useful Commands: #action #agreed #halp #info #idea #link #topic. 14:14:11 The meeting name has been set to 'security_team_fad_2016' 14:14:23 #meetingname Security Team FAD 2016 14:14:23 The meeting name has been set to 'security_team_fad_2016' 14:14:31 #topic Roll Call 14:15:01 * Sparks 14:18:59 .hello corey84 14:19:00 linuxmodder: corey84 'Corey Sheldon' 14:19:03 (remote) 14:39:50 * zoglesby is here 14:43:23 #topic Expediting Security Updates in Fedora 14:43:29 #link https://fedorahosted.org/rel-eng/ticket/5886 14:53:37 BZ Private 14:53:45 Group 14:56:51 Private List w/ Encryption 15:25:32 * linuxmodder & bbl 15:49:13 FabioOlive: Hi 15:53:19 #topic Apprenticeship 15:57:54 #link 15:57:58 #link 15:58:07 #link https://fedoraproject.org/wiki/Security_Team_Apprenticeship 16:46:21 .fasinfo sparks 16:46:22 Sparks: User: sparks, Name: Eric Christensen, email: sparks@redhat.com, Creation: 2007-07-17, IRC Nick: Sparks, Timezone: US/Eastern, Locale: en, GPG key ID: 024BB3D1, Status: active 16:46:25 Sparks: Approved Groups: @gitfedora-security-team gitcsi cla_fedora cla_done sysadmin-keys @gitdocsglue cvsfedora @docs +gitfedora-wiki @gitfedora-cms fedorabugs packager @docs-publishers @gitweatheralert @docs-writers @gitamateur-radio-menus cla_fpca @gitkeysigning-party-manual @gitsecure-coding @gitcreate-tx-configuration sysadmin-hosted elections sysadmin sysadmin-docs gitpublican-fedora @security-team 16:57:39 .fasgroup gitweatheralert 16:59:24 https://gist.github.com/major/21bba17de6c5c955916b 17:04:14 Sparks: hey there, how's the FAD going? 17:04:38 FabioOlive: We're making progress! 17:04:47 hi! 17:04:51 Greetings! 17:05:19 We're FADing and we have questions. Would you be available to come up on Google Hangout at some point in time to talk with us? 17:05:35 yes definitely 17:05:47 like, today, or some unspecified time? 17:05:49 :) 17:06:59 today 17:06:59 now 17:07:00 Today! 17:07:02 Now! 17:07:04 FAD! 17:07:14 Yeah, what he said. 17:07:26 lol 17:07:46 how about in an hour? like, 1:15? I need to get some lunch 17:08:04 Yeah, that'll be fine. 17:08:58 cool i'll come back here then 17:09:10 Awesome, thank you! 17:10:44 Sparks: depending on how many people you need, you might want to try appear.in/fedora (I can't recall whether this was the room I registered or not) 17:10:51 (it was too long ago) 17:12:11 oh I had registered https://appear.in/fedora-security-team 17:12:23 room .../fedora was there too though 17:12:32 FabioOlive: Yeah, I tried that and it didn't work for me for some reason. 17:12:38 hmm 17:12:40 ok 17:12:45 FabioOlive: We actually have a Google Hangout setup and in use right now. 17:12:54 * FabioOlive realizes his headset is plugged to the wrong device 17:12:58 ha! 17:13:28 it was so quiet :) 17:13:33 FabioOlive: https://plus.google.com/hangouts/_/hungrymachine.com/zachary-oglesby 17:14:33 Sparks: I'll see if I can join in a while, got plenty of stuff to do here 17:14:41 FabioOlive: Please do 17:15:16 ok let me see if this thing works here 17:16:30 oh I need the plugin 17:27:44 so we still usign the hangouts or appear.in? 17:28:16 stepped out for a mtg locally 17:29:37 linuxmodder: yes 17:29:49 still the same hangout 17:31:02 d-caf, nice also Sparks appear.in link works 17:31:18 just its an empty room --I use appear.in for other platforms too 17:31:47 linuxmodder: hangout 17:32:48 linuxmodder: I couldn't get appear.in to work earlier. The thing is we have have this ChromeBox thingy that only supports Google Hangout. 17:32:52 Sparks, post FAD I can wwalk oyu thru appear.in if you want 17:32:54 linuxmodder: Not ideal. 17:35:18 lookign to get a yk mini myself next month 17:42:18 I would love if they got nfc for the yk mini, but then I guess I would need nfc in my phone... 17:49:03 or on the lappy 17:49:14 I do mostly VOIP myself 17:51:02 gents a Flying_Cat is claiming in #fedora libotr verison is vuln to 2016-2851 asked him to join us in the other channel 17:55:00 linuxmodder: https://bugzilla.redhat.com/show_bug.cgi?id=1316262 17:58:49 This links to all of them https://bugzilla.redhat.com/show_bug.cgi?id=1316133 18:00:02 upstream source: https://lists.cypherpunks.ca/pipermail/otr-users/2016-March/002581.html 18:01:12 so its merely a no time yet to do fedpkg update? 18:02:15 in the last 48 hour s 18:03:39 FabioOlive: Would you relay to Kurt that Let's Encrypt is now in Fedora and EPEL. 18:05:42 Sparks, just like to the magazine or blog post ( can't remember which one ran the article) 18:05:49 s/like/link 18:10:07 Sparks, FabioOlive https://fedoramagazine.org/letsencrypt-now-available-fedora/ 18:11:07 linuxmodder: +1 18:12:37 jhogarth++ 18:12:38 linuxmodder: Karma for jhogarth changed to 7 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 18:12:49 nice writeup btw jhogarth 18:16:16 hey all! 18:17:28 send me a hangouts invite or the link? 18:17:45 mattdm: https://plus.google.com/hangouts/_/hungrymachine.com/zachary-oglesby 18:18:25 hold on a second :) 18:18:52 can you invite me in so it rings on my phone? i use hangouts there instead of my computer 18:19:17 email address? 18:19:35 at gmail.com 18:19:56 (mattdm) 18:20:05 mattdm, open it in hangouts 18:20:08 the link that is 18:20:35 mattdm: sent (I think) 18:21:27 er, is it LivingSocial? 18:21:32 yes 18:21:45 ok cool yes 18:21:50 zach works for them iirc 18:21:52 We are at my office, using a "Chromebox for Meetings" 18:39:44 https://fedoraproject.org/wiki/Objectives/Fedora_Modularization,_Prototype_Phase 18:46:51 http://gunshowcomic.com/comics/20130109.png 18:47:43 #link https://fedoraproject.org/wiki/Objectives/Fedora_Modularization,_Prototype_Phase 18:48:03 .chair 18:48:03 linuxmodder: (chair ) -- Alias for "echo $1 is seated in a chair with a nice view of a placid lake, unsuspecting that another chair is about to be slammed into them.". 18:48:21 #chairs 18:49:05 Sparks, can you or zoglesby add those links to the minutes ? the fedoramagazine and modularity wiki 18:52:06 can someone drop that link here? 18:54:41 which one mattdm 18:58:34 https://sparkslinux.wordpress.com/2015/03/26/for-discussion-orphaned-package-in-fedora/ 18:58:38 #link https://sparkslinux.wordpress.com/2015/03/26/for-discussion-orphaned-package-in-fedora/ 19:12:16 Sparks linuxmodder : thanks for the fedora magazine link, I'll definitely read/tweet/etc that 20:08:10 https://fedoraproject.org/wiki/Security_Team_Apprenticeship 20:42:22 https://xkcd.com/364/ 20:42:32 15:42 < Sparks> https://xkcd.com/364/ 20:42:33 Here's my fingerprint: 2048R/210BDF5A 21:09:01 FabioOlive, it's also on my planet connected blog fyi 21:10:05 that's an old key alright 21:11:35 my fingerprints are: personal -> rsa4096/BB082E66 fas -> rsa4096/24E58F80 both carry pics 21:12:15 also up on admin.fedoraproject.org/ page 13:31:18 I did not put my notes on owncloud and am in the office today, so I am going to have to wait until tonight to type it all up. 13:32:15 zoglesby, did you happen to get my updated keys email ? hated the idea of having to re-gen them right after the key signing 14:45:31 linuxmodder: where you there for the key signing? 14:46:00 sadly no but I gave my keyids whicha re no longer valid 14:46:20 ones shown in fas presently are the new keys 14:54:01 linuxmodder: sorry, but I don't go signing keys willy-nilly. 14:54:29 Nor do I 16:06:43 linuxmodder: Did you revoke your old key? 16:07:03 zoglesby: Hope you got the share. It appears the federated ID worked. 16:07:33 zoglesby: If you want, you can just add your information to that folder and we'll all have it! 16:07:45 jsmith: Do you have an owncloud instance up? 16:48:28 Sparks: got it? 16:48:40 :s/?// 16:48:46 zoglesby: Woot 16:48:53 Technology works! 16:49:05 fedcloud! 17:41:53 Sparks: I do not 17:46:21 Sparks: (at least, not publically accessible) 17:46:24 Sparks: Why do you ask? 18:51:20 jsmith: Going to share files with you from Friday 18:52:28 Sparks: Gotcha... 00:10:11 Sparks: notes sent to list 00:29:56 zoglesby: thanks :) 00:30:11 this: http://seclists.org/oss-sec/2016/q1/645 o_O ? 14:21:09 zoglesby: Thank you. I'm currently writing up my blog article on the events and I'm leveraging your notes 07:28:33 hi can anyone point to me to good resources on Shim 07:28:49 like its necessity in secure boot mode 07:28:58 and stuf 13:55:10 I assume I missed the meeting? 13:56:27 Oh, wait time change, maybe I didn't! 13:57:26 its in like 10 mins no? 14:03:02 linuxmodder: should be like now 14:05:19 Ugh, is it Thursday already? 14:05:34 yep 14:57:47 Astradeus: Hi 14:59:28 Sparks: i'm here :) 14:59:56 Astradeus: Take a look at this: https://fedoraproject.org/wiki/Security_Team#Work_Flow 15:03:21 bugzilla is slow ;) 15:05:52 Astradeus: Yes 15:06:57 how do i modify "Whiteboard"? that field is fixed for me 15:07:39 aah, i need to be added to the bug, is that true? 15:09:29 Sparks: this looks straightforward, does it? https://bugzilla.redhat.com/show_bug.cgi?id=1306682 15:18:03 Astradeus: there is a specific fas group you need to be a part of to edit the bugs 15:18:10 can't remember off hand 15:18:25 .fas dcafaro 15:18:26 d-caf: dcafaro '' 15:18:47 can't remember the command to list fas groups 15:19:44 .fasinfo dcafaro 15:19:45 d-caf: User: dcafaro, Name: None, email: dac@cafaro.net, Creation: 2008-09-26, IRC Nick: None, Timezone: None, Locale: None, GPG key ID: None, Status: active 15:19:48 d-caf: Approved Groups: gitfedora-security-team cla_fedora fedorabugs cla_fpca cla_done security-team 15:20:22 d-caf: fedorabugs, maybe? 15:20:31 probably 15:21:04 ah, okay 15:21:55 .fasinfo sparks 15:21:56 Sparks: User: sparks, Name: Eric Christensen, email: sparks@redhat.com, Creation: 2007-07-17, IRC Nick: Sparks, Timezone: US/Eastern, Locale: en, GPG key ID: 024BB3D1, Status: active 15:21:57 that looks like some meta-group 15:21:58 Sparks: Approved Groups: @gitfedora-security-team gitcsi cla_fedora cla_done sysadmin-keys @gitdocsglue cvsfedora @docs +gitfedora-wiki @gitfedora-cms fedorabugs packager @docs-publishers @gitweatheralert @docs-writers @gitamateur-radio-menus cla_fpca @gitkeysigning-party-manual @gitsecure-coding @gitcreate-tx-configuration sysadmin-hosted elections sysadmin sysadmin-docs gitpublican-fedora @security-team 15:22:22 at least according to the group description 15:35:30 okay, seems like i need to be approved for the group 'security-team' first, in order to be auto-synced to 'fedorabugs' 15:36:06 (according to an old email by sparks from august 2014 on the security-team mailing list) 15:42:15 Wow, I said that? 15:45:22 Astradeus: You are astra in FAS? 15:45:51 .fas astradeus 15:45:56 Sparks: astra 'David Kaufmann' 15:46:24 .fasinfo astra 15:46:26 Sparks: User: astra, Name: David Kaufmann, email: astra@ionic.at, Creation: 2013-11-27, IRC Nick: Astradeus, Timezone: Europe/Vienna, Locale: en, GPG key ID: 5CBED71B23D2450E, Status: active 15:46:29 Sparks: Approved Groups: fedorabugs security-team cla_fpca cla_done 15:46:29 .fasinfo corey84 15:46:32 linuxmodder: User: corey84, Name: Corey Sheldon, email: sheldon.corey@gmail.com, Creation: 2014-11-28, IRC Nick: linuxmodder, Timezone: US/Eastern, Locale: en, GPG key ID: 02AABD91 FF32E0EE 2584CBE4, Status: active 15:46:34 linuxmodder: Unapproved Groups: summer-coding fedmsg-announce 15:46:37 linuxmodder: Approved Groups: security-team marketing magazine fedorabugs qa fedora-join commops campusambassadors scitech fi-apprentice ambassadors cla_fpca cla_done 15:46:49 Astradeus: I can add you to fedorabugs. I don't think security-team is one of the groups that automatically ive you fedorabugs 15:47:11 fedorabugs is exclusive to security-team 15:47:13 fedorabugs is automatic for people in packager or qa, if I recall correctly 15:47:23 qa fir sure 15:47:26 linuxmodder: no. fedorabugs is automatically granted to packagers 15:48:18 Okay, seems security-team is indeed in the list. But it's not a requirement, just one way to get fedorabugs 15:48:18 Sparks: thanks 15:48:36 puiterwijk: it appears that fedorabugs does come with membership with the security-team group 15:48:40 yes, found in an old list archive 15:48:55 Sparks: yeah, correct. As said, it's one of the ways to get it 15:49:03 Sparks: https://lists.fedoraproject.org/archives/list/security-team@lists.fedoraproject.org/thread/X3SNOAJR4S3N6RKY4XYOPBASVEMO7K6U/ 15:49:20 Astradeus: Well, I see that it added you... :) 15:51:49 Sparks: it seems i'd have to wait for it to be synced to the bugzilla instance 15:52:11 so either i follow a bug you manage readonly or we do it some other time? 15:57:40 Astradeus: I'm a little busy this morning... sorry 16:00:46 no problem, lets do this some other time? unfortunately i don't have much time later, so another date maybe? 16:07:13 Astradeus: Yeah, there are others that can help too. 17:38:16 Sparks, pjp d-caf I'm game for helping with enbargo builds stuff 00:07:29 sorry for missing today's meeting -- been out on vacatoin 00:07:32 err vacation 12:48:06 soooo, we've got http://badlock.org/ coming up April 12th 12:48:18 not sure how exciting this is going to be 13:36:11 mattdm: at least it has its own website, logo and announcement ;) 13:43:22 Astradeus: And suspense-building teaser updates 14:20:23 mattdm: Ugh 14:21:55 From the Badlock website -> "We are grateful to the Heartbleed team to use their template." 14:22:24 At least the logo is licensed CC0. 14:28:27 which CVE is this ? 14:29:02 Not sure it's been assigned a CVE yet 14:52:26 It has a CVE... 14:52:28 Wait 14:53:13 linuxmodder: CVE-2016-2118 14:53:31 linuxmodder: But it's embargoed so you won't find anything about it now 13:55:19 Good morning. FST Meeting in ~5 minutes in #fedora-meeting 13:56:21 zoglesby jsmith linuxmodder mhayden ^^^ 13:56:38 i have a conflict today - but i should be in within 30 minutes 13:58:27 mhayden: Unacceptable 13:58:31 haha 13:58:40 it's with my boss, so i feel likei oughtta go 13:58:55 Sparks: http://paste.fedoraproject.org/344610/45882784/raw/ 13:59:23 Pfftt... tell him/her that you'll be a little late. 14:04:28 yeah, yeah, on my way 14:05:10 no meetinb seems to be going on #fedora-meeting 14:08:12 zoglesby: Hush you 14:09:04 you pinged me, not the other way around 14:09:39 Yeah yeah 14:34:00 Sparks, congrats 14:34:13 Southern_Gentlem: Thanks. 14:34:25 Southern_Gentlem: Which also means I am now an Extra Class VE 14:34:48 yep 14:35:05 Which means we won't have to import a VE from afar 14:35:17 i hadnt heard you had finally gotten the upgrade 14:35:38 and the Extra pool gets a major change July 1st 14:36:03 Yeah, we had an Extra Class class in our club which was very helpful. I flew right through the test 14:36:24 grows to 713, 130 questions removed 143 new questions +60 revised 14:36:47 Sparks, i am teaching an Extra class starting in May 14:37:17 Nice 14:37:28 zoglesby: What are your thoughts on SELF? 14:37:31 how many VE sessions you do now a year Southern_Gentlem 14:37:59 Sparks: I have not put any thought into it, but I will start now. 14:38:30 21-22 14:39:40 rvarc 10 vtara 7 nrvarc 4 Larc 4 == 25 14:40:18 so 25-27 14:41:43 programming note: 20160324 updates Southern_Gentlem just kickdd off WILL have the patched libotr 4.1.1 Sparks zoglesby from the previous weeks cve chatter 14:42:03 you come up for larc? 14:42:22 linuxmodder, no we have a LARC team down here 14:42:31 ah 14:42:35 they will be doing the testing at SELF 14:42:47 ah 14:44:15 Larc == Free Testing 14:45:31 its what normally $20 these days? 14:46:04 Sorry folks -- couldn't make the meeting 14:47:38 Okay, I need to run to my next appointment. BBIAB 16:18:59 ola 16:21:16 hoje tem reuniao? 16:55:20 Southern_Gentlem: Yeah, ARRL just can't/won't compete with the Laurel group. 17:06:11 Sparks, they dont have to. ARRL does 90% of the testing 17:07:57 even if the ARRL was doing 80% that is a huge # every year and its growing 17:09:18 Southern_Gentlem: The ARRL doesn't do any of the testing here in Southern/Central Maryland 17:09:43 algum Brasileiro aqui? 17:10:00 FabioOlive: ^^^ 17:10:14 ola sparks 17:10:22 Boa tarde pessoal 17:11:34 d3v0x: 17:11:35 Por favor espere, me estoy poniendo a alguien para ti que habla español mejor que yo 17:11:39 jsmith: ^^^ 17:13:03 Sparks, but they do about everywhere else 17:13:39 i am surprised the ARRL isnt doint the testing for Dayton Hamvention but its LARC 17:14:48 I hope that opens the ARRL's eyes 17:15:51 d3v0x: Hablo español (más o menos), y un poco de Portuñol tambem :-p 17:17:05 d3v0x: (Pero hablo como un campesino Paraguayo...) 17:17:23 sparks its been Larc i know the last 5 years 17:17:29 oh 17:19:30 * jsmith will return shorlty 17:19:36 Shortly, that is :-/ 17:36:08 no hablo espanol :`( 17:40:31 hey 17:40:40 FabioOlive: ^^^ d3v0x 17:41:02 d3v0x: opa, sou brasileiro :) tudo bem? 17:42:32 bah! 17:43:20 Sparks: "bah!" was perfect, sounds like you are from my state 17:44:24 tudo fabio 17:44:26 e contigo? 17:45:12 d3v0x: tranquilo na correria. precisas de alguma coisa relacionada a segurança? 17:45:48 tudo de mais sofisticado, e estou meio que apanhando para mexer no chat 17:46:01 primeira vez e eh muito bom 17:47:56 d3v0x: seja bem vindo ao Fedora :-) em geral aqui se fala inglês, mas se precisas falar em português brasileiro, tem também o canal #fedora-br 18:04:41 Sparks: d3v0x wants to start contributing to the Fedora Security Team, but he may have a bit of a long road to get there, including improving his English, so I'll be mentoring him as best as I can 18:05:20 FabioOlive++ 18:05:20 Sparks: Karma for fleite changed to 1 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 18:05:28 FabioOlive++ 18:05:28 jsmith: Karma for fleite changed to 2 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 18:05:40 FabioOlive: That's great. I hate that we have language barriers... 18:05:52 heh, leave the ++ for when d3v0x closes his first bugs ;-) 18:06:34 FabioOlive: He'll get one too... But it will be because of you! 18:06:49 Sparks: yeah, well, he's learning English as well, so perhaps we'll bridge that gap soon :) 18:07:46 anything for the infra folks they are meeting now? 18:08:13 linuxmodder: Just hand them a full shot glass 18:08:32 lol as long as I keep mine sure :) 23:28:19 thank you to you guys for supporting me in my trajectory 23:29:59 thank you sparks 12:37:15 c0mrad3: also are you stalking me? :P 13:19:11 no zoglesby why did you think so ? :) 22:04:37 zoglesby: I'm stalking you. 22:28:28 Sparks: I was already aware of that 00:48:58 zoglesby: Oh good, I'd hate to think this came as a surprise. 10:10:08 * wmealing waves 10:11:11 hi wmealing! 13:38:50 noisy lot here 13:46:54 .ping 13:46:54 pong 13:46:58 Hmmm 13:47:15 .pingall Security Team Meeting in #fedora-meeting in ~12 minutes 13:47:18 nope 13:49:52 .nextmeeting 13:49:52 Sparks: (nextmeeting ) -- Return the next meeting scheduled for a particular channel. 13:50:00 .nextmeeting #fedora-meeting 13:50:01 Sparks: In #fedora-meeting is Security Team Meeting (starting in 9 minutes) 13:50:04 Sparks: In #fedora-meeting is Modularity WG (starting in an hour) 13:50:07 Sparks: In #fedora-meeting is irc support sig meeting (starting in 3 hours) 13:50:10 Sparks: - https://apps.fedoraproject.org/calendar/location/fedora-meeting%40irc.freenode.net/ 13:51:51 * mhayden woots 13:51:55 just sent this week's stats 13:52:32 mhayden: The ping command in zodbot isn't documented well so... 13:53:59 mhayden: I don't see it... 13:54:14 mhayden: Oh wait, I see it 13:54:21 hah, yay internet 13:54:28 it's a series of tubes, you know 13:54:33 one might have become clogged 13:57:30 * Sparks gets out the toilet plunger 14:00:41 d-caf mhayden jsmith zoglesby linuxmodder Anyone Else: Meeting in #fedora-meeting @ now! 17:21:04 Sparks, only owners can do .pingall now 17:21:06 .misc help pingall 17:21:08 nb: Error: There is no command "pingall". 17:21:15 maybe it wasn't pingall 17:21:18 oh, it's .nicks 18:02:39 nb: Yeah, it's something. 22:12:23 good night 12:36:50 zoglesby jsmith linuxmodder ANYONE: Can someone do the meeting this morning? I have a doctor appointment and will likely not be here. 13:51:39 report sent :) 13:52:15 Sparks: i'm going to be doubled down on meetings during the time slot today -- the other is a VC at $dayjob 13:58:55 mhayden: cool, thx 14:01:12 meeting anyone? 14:14:26 * mhayden is tied up this morning :/ 15:02:23 Sparks: I did the meeting for you :) 15:02:53 I will email the log to the mailing list even though there were only 2 of us 15:03:43 c0mrad3: I more or less updated the wiki with the new numbers and carried over everything else 15:12:55 ls 23:30:23 Hi, it looks like there's a meeting going on here?