*** salv-orlando has joined #openstack-security | 00:09 | |
*** salv-orlando has quit IRC | 00:12 | |
*** jamielennox|away is now known as jamielennox | 00:20 | |
*** salv-orlando has joined #openstack-security | 01:12 | |
*** salv-orlando has quit IRC | 01:17 | |
*** yaya has joined #openstack-security | 01:30 | |
*** yaya_ has joined #openstack-security | 01:31 | |
*** yaya has quit IRC | 01:34 | |
*** yaya_ is now known as yaya | 01:34 | |
*** yaya has quit IRC | 01:50 | |
*** markvoelker has joined #openstack-security | 01:51 | |
*** markvoelker has quit IRC | 01:55 | |
*** zul has joined #openstack-security | 02:01 | |
*** hyakuhei has quit IRC | 02:08 | |
*** hyakuhei has joined #openstack-security | 02:11 | |
*** salv-orlando has joined #openstack-security | 02:33 | |
*** salv-orlando has quit IRC | 02:38 | |
*** sdake_ has joined #openstack-security | 02:46 | |
*** yuanying has quit IRC | 02:47 | |
*** sdake has quit IRC | 02:50 | |
*** yuanying has joined #openstack-security | 02:52 | |
*** diazjf has joined #openstack-security | 02:52 | |
*** diazjf has quit IRC | 02:52 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/314347 | 02:58 |
---|---|---|
*** edmondsw has joined #openstack-security | 03:02 | |
*** sdake_ has quit IRC | 03:07 | |
*** yuanying has quit IRC | 03:43 | |
*** yuanying has joined #openstack-security | 03:47 | |
*** rcernin has joined #openstack-security | 03:48 | |
*** markvoelker has joined #openstack-security | 03:52 | |
*** markvoelker has quit IRC | 03:56 | |
*** salv-orlando has joined #openstack-security | 04:39 | |
*** stefany has joined #openstack-security | 04:40 | |
*** salv-orlando has quit IRC | 04:44 | |
*** rcernin has quit IRC | 04:52 | |
*** stefany has left #openstack-security | 05:11 | |
*** austin987 has joined #openstack-security | 05:22 | |
*** jamielennox is now known as jamielennox|away | 05:24 | |
*** jamielennox|away is now known as jamielennox | 05:28 | |
*** salv-orlando has joined #openstack-security | 05:31 | |
*** markvoelker has joined #openstack-security | 05:52 | |
*** markvoelker has quit IRC | 05:57 | |
*** ErrorxError has joined #openstack-security | 06:02 | |
*** ErrorxError has quit IRC | 06:04 | |
*** jamielennox is now known as jamielennox|away | 06:15 | |
*** liverpooler has joined #openstack-security | 06:16 | |
*** liverpooler has quit IRC | 06:21 | |
*** liverpooler has joined #openstack-security | 06:21 | |
*** salv-orlando has quit IRC | 06:49 | |
*** tesseract has joined #openstack-security | 06:57 | |
*** salv-orlando has joined #openstack-security | 06:59 | |
*** rcernin has joined #openstack-security | 07:01 | |
*** jamielennox|away is now known as jamielennox | 07:18 | |
*** salv-orlando has quit IRC | 07:29 | |
*** sdake has joined #openstack-security | 07:34 | |
*** lhinds_awk has joined #openstack-security | 07:46 | |
*** lhinds__ has joined #openstack-security | 07:46 | |
*** lhinds_awk has quit IRC | 07:53 | |
*** lhinds__ has quit IRC | 07:53 | |
*** markvoelker has joined #openstack-security | 07:53 | |
*** markvoelker has quit IRC | 07:58 | |
*** yaya has joined #openstack-security | 08:22 | |
*** dmk0202 has joined #openstack-security | 08:26 | |
*** yaya has quit IRC | 08:27 | |
*** sdake_ has joined #openstack-security | 08:32 | |
*** sdake has quit IRC | 08:35 | |
*** agireud has quit IRC | 09:50 | |
*** markvoelker has joined #openstack-security | 09:54 | |
*** sdake_ is now known as sdake | 09:57 | |
*** markvoelker has quit IRC | 09:58 | |
*** agireud has joined #openstack-security | 10:11 | |
*** pcaruana has joined #openstack-security | 10:11 | |
*** agireud has quit IRC | 10:39 | |
*** liverpooler has quit IRC | 10:48 | |
*** shohel has joined #openstack-security | 10:59 | |
*** liverpooler has joined #openstack-security | 11:01 | |
*** shohel has quit IRC | 11:04 | |
*** shohel has joined #openstack-security | 11:07 | |
*** dmk0202 has quit IRC | 11:07 | |
*** shohel has quit IRC | 11:21 | |
*** agireud has joined #openstack-security | 11:39 | |
*** dmk0202 has joined #openstack-security | 11:42 | |
*** markvoelker has joined #openstack-security | 11:55 | |
*** markvoelker has quit IRC | 11:57 | |
*** markvoelker has joined #openstack-security | 11:57 | |
*** M1dgard has joined #openstack-security | 11:57 | |
*** M1dgard has left #openstack-security | 11:57 | |
*** dave-mccowan has joined #openstack-security | 12:25 | |
*** sdake has quit IRC | 12:27 | |
*** jmckind has joined #openstack-security | 13:27 | |
*** nkinder has joined #openstack-security | 13:40 | |
*** jmckind has quit IRC | 13:49 | |
*** jmckind has joined #openstack-security | 13:52 | |
*** user154752 has joined #openstack-security | 13:55 | |
*** ametts has joined #openstack-security | 13:56 | |
*** edtubill has joined #openstack-security | 13:56 | |
*** d0ugal has quit IRC | 14:15 | |
*** d0ugal has joined #openstack-security | 14:17 | |
*** jhfeng has joined #openstack-security | 14:27 | |
*** tmcpeak has joined #openstack-security | 14:56 | |
*** rcernin has quit IRC | 15:07 | |
*** jmckind has quit IRC | 15:10 | |
*** vinaypotluri has joined #openstack-security | 15:19 | |
*** yaya has joined #openstack-security | 15:26 | |
*** openstackgerrit has quit IRC | 15:33 | |
*** openstackgerrit has joined #openstack-security | 15:33 | |
*** dmk0202 has quit IRC | 15:42 | |
*** user154752_ has joined #openstack-security | 15:44 | |
*** user154752 has quit IRC | 15:47 | |
*** ccneill has joined #openstack-security | 15:50 | |
*** tesseract has quit IRC | 15:54 | |
*** pcaruana has quit IRC | 15:59 | |
*** austin987 has quit IRC | 16:03 | |
*** austin987 has joined #openstack-security | 16:16 | |
*** mdong has joined #openstack-security | 16:22 | |
*** diazjf has joined #openstack-security | 16:47 | |
*** diazjf has quit IRC | 16:50 | |
tmcpeak | chair6, sigmavirus24: https://review.openstack.org/#/c/322558/ :\ | 16:56 |
tmcpeak | do something sigma! :P | 16:57 |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:00 | |
*** woodburn has joined #openstack-security | 17:00 | |
*** rcernin has joined #openstack-security | 17:01 | |
*** gmurphy_ is now known as gmurphy | 17:50 | |
*** nkinder has quit IRC | 18:01 | |
*** yaya has quit IRC | 18:17 | |
*** diazjf has joined #openstack-security | 18:23 | |
*** bpokorny has joined #openstack-security | 18:47 | |
ccneill | https://github.com/dxa4481/Pastejacking | 19:00 |
ccneill | :X | 19:00 |
*** diazjf has quit IRC | 19:00 | |
*** diazjf has joined #openstack-security | 19:03 | |
tmcpeak | ccneill: yeah, saw that. Definitely undesirable property of JS | 19:03 |
ccneill | yep | 19:03 |
ccneill | and the mitigation is "be careful" | 19:04 |
ccneill | which is always super helpful to non-technical people | 19:04 |
ccneill | lol | 19:04 |
tmcpeak | "I'd like JS to be able to add things to my clipboard with no user intervention" — said nobody ever | 19:04 |
ccneill | +1 | 19:04 |
ccneill | I mean.. I guess I'm happy that it's not happening in flash? | 19:04 |
ccneill | ¯\_(ツ)_/¯ | 19:04 |
ccneill | https://randywestergren.com/widespread-vulnerable-ads-part-two-flash-edition-facebooks-liverail-akamai-adobe-products-affected/ | 19:04 |
ccneill | this looks fun too | 19:04 |
*** mdong has quit IRC | 19:09 | |
*** mdong has joined #openstack-security | 19:11 | |
*** jmckind has joined #openstack-security | 19:15 | |
tristanC | heh, you may also be interested in https://conference.hitb.org/hitbsecconf2016ams/materials/D2T2%20-%20Shangcong%20Luan%20-%20Xen%20Hypervisor%20VM%20Escape.pdf | 19:16 |
tmcpeak | tristanC: ++ | 19:19 |
*** edtubill has quit IRC | 19:27 | |
*** edtubill has joined #openstack-security | 19:28 | |
*** vinaypotluri has quit IRC | 19:30 | |
*** jmckind has quit IRC | 19:37 | |
*** sdake has joined #openstack-security | 19:45 | |
*** mdong has quit IRC | 19:45 | |
*** sdake_ has joined #openstack-security | 19:49 | |
*** sdake has quit IRC | 19:51 | |
*** mdong has joined #openstack-security | 19:58 | |
*** vinaypotluri has joined #openstack-security | 19:58 | |
ccneill | tristanC: will definitely have to check that out. this is another one that's been in my nightmares for a while: https://arxiv.org/abs/1507.06955 | 20:03 |
*** diazjf has quit IRC | 20:04 | |
*** dmk0202 has joined #openstack-security | 20:05 | |
*** jmckind has joined #openstack-security | 20:06 | |
*** diazjf has joined #openstack-security | 20:09 | |
*** diazjf has quit IRC | 20:16 | |
*** nkinder has joined #openstack-security | 20:16 | |
tristanC | ccneill: oh right, we are getting down the rabbit hole now :) But isn't rowhammer mitigated by ecc or bios upgrade ? | 20:27 |
*** dmk0202 has quit IRC | 20:28 | |
*** diazjf has joined #openstack-security | 20:28 | |
tristanC | note that there isn't much in the hitb slides, but a reminder that hypervisor aren't bug-free | 20:28 |
*** diazjf has quit IRC | 20:29 | |
*** diazjf has joined #openstack-security | 20:32 | |
*** dmk0202 has joined #openstack-security | 20:44 | |
ccneill | tristanC: my understanding is ECC is an effective mitigation, I'm not sure about BIOS upgrades though | 20:47 |
*** jmckind has quit IRC | 20:48 | |
tristanC | well http://googleprojectzero.blogspot.ca/2015/03/exploiting-dram-rowhammer-bug-to-gain.html says so... | 20:55 |
*** jmckind has joined #openstack-security | 20:56 | |
tristanC | and ecc may not help according to http://blog.erratasec.com/2015/03/some-notes-on-dram-rowhammer.html | 20:56 |
ccneill | yeah, that's most of why it haunts my nightmares haha | 20:56 |
ccneill | it seems to be in a sort of "unresolved" state, where some people are looking into it, but it's not generally appreciated | 20:57 |
ccneill | GPZ's research was very interesting | 20:57 |
*** diazjf has quit IRC | 20:59 | |
tristanC | so... does any of you guys use monitoring probe to check for high rate of cache miss ? | 21:01 |
*** diazjf has joined #openstack-security | 21:04 | |
*** unrahul has joined #openstack-security | 21:04 | |
ccneill | <_< probably should.. | 21:05 |
tristanC | would be nice to know if it's noticable without false positive on a typical openstack compute node | 21:08 |
ccneill | wonder how widely it's being exploited in the wild | 21:13 |
*** jmckind has quit IRC | 21:27 | |
*** jmckind has joined #openstack-security | 21:29 | |
*** edmondsw has quit IRC | 21:29 | |
*** bpokorny_ has joined #openstack-security | 21:31 | |
*** bpokorny has quit IRC | 21:35 | |
*** dmk0202 has quit IRC | 21:38 | |
*** mdong has quit IRC | 21:41 | |
*** bpokorny_ has quit IRC | 21:45 | |
*** bpokorny has joined #openstack-security | 21:46 | |
*** jhfeng has quit IRC | 21:51 | |
*** jmckind has quit IRC | 21:54 | |
*** edtubill has quit IRC | 21:56 | |
*** diazjf has quit IRC | 21:57 | |
*** sdake has joined #openstack-security | 22:10 | |
*** sdake_ has quit IRC | 22:12 | |
*** ametts has quit IRC | 22:14 | |
*** turvey has joined #openstack-security | 22:15 | |
*** turvey has quit IRC | 22:39 | |
*** turvey has joined #openstack-security | 22:43 | |
*** bpokorny has quit IRC | 22:44 | |
*** turvey is now known as mwturvey | 22:44 | |
*** mwturvey is now known as turvey | 22:45 | |
*** turvey is now known as mwturvey | 22:45 | |
*** mwturvey is now known as fragglerock21 | 22:45 | |
*** fragglerock21 has quit IRC | 22:47 | |
*** mwturvey__ has joined #openstack-security | 22:48 | |
*** mwturvey__ has quit IRC | 22:48 | |
*** bpokorny has joined #openstack-security | 23:08 | |
*** mwturvey__ has joined #openstack-security | 23:24 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!