| opendevreview | Goutham Pacha Ravi proposed openstack/security-doc master: OSSN-0101: Nova console proxy Origin poisoning https://review.opendev.org/c/openstack/security-doc/+/996187 | 16:41 |
|---|---|---|
| gouthamr | fungi: JayF rosmaita: ^ can i have your review on this? | 17:24 |
| fungi | gouthamr: i was just about done reading through it, so... yes! ;) | 17:24 |
| JayF | Why is that an OSSN, not an OSSA? | 17:25 |
| JayF | There's no operator action required other than applying patches, afaict | 17:25 |
| gouthamr | because of the classification, this was discussed here.. it wasn't treated as a class A vulnerability because the exploit requires other exploits | 17:25 |
| JayF | ack; I think it's confusing that we use that as part of the line but it's technically correct | 17:26 |
| fungi | yeah, that was my main question too, i had to revisit the bug report to confirm | 17:26 |
| JayF | It's 100% a decoder ring to operators already what OSSN v OSSA means | 17:26 |
| fungi | it was considered a hardening opportunity | 17:26 |
| JayF | and not having "OSSN means you need to do more than apply patches" as the only differentiator makes it harder | 17:26 |
| fungi | a hardening opportunity that got fixes backported and a publication about it, but no cve assignment requested | 17:27 |
| gouthamr | +1 | 17:27 |
| fungi | not directly exploitable to a malicious end, but could be chained with other bugs potentially | 17:27 |
| fungi | definitely a grey area for us | 17:28 |
| JayF | I'm not saying we should have a CVE or anything like that | 17:28 |
| JayF | just that this is 1000% a area so grey it makes it nearly-impossible for people outside of our sphere to understand OSSA vs N | 17:28 |
| fungi | made more grey by the fact that ossa and ossn were handled by entirely separate groups of people once upon a time, which was the real reason for the distinction | 17:28 |
| fungi | but then the people who handled the ossn process vanished, dumping it in the vmt's lap | 17:29 |
| JayF | Maybe I'll propose a change to make it where "any advisory with only patches, regardless of severity -> OSSA" "any advisory with action needed beyond application of patches, regardless of severity -> OSSN" | 17:29 |
| JayF | "regardless of severity" not meaning we file them in all cases; but instead that "more severe things are OSSAs" would not be true | 17:29 |
| fungi | i would be okay with that if we expect to continue having the vmt oversee the ossn process anyway. the reason for the separation before was to offload low-risk concerns to someone other than the vmt | 17:30 |
| JayF | coordination cost would be greater than the value I suspect | 17:30 |
| rosmaita | we have also had situations where we did both OSSA and OSSN | 17:30 |
| fungi | maybe explaining it differently: the vmt issued security advisories for things we deemed warranted them. some security practitioners in the community also wanted publications about things the vmt rejected from the advisory process so they came up with their own publication series about those | 17:32 |
| fungi | in reality, when those people then left the community, the ossn publication process would have ended, but the vmt had by that point baked ossn hand-off to the ossg into the vmt process, which we were too few/busy to amend to remove those references | 17:33 |
| fungi | though when it was just me, we basically stopped issuing ossn publications unless someone in the broader community wanted to write one, and then the vmt (me) essentially rubber-stamped them | 17:35 |
| fungi | though not really in the guise of the vmt, i was rubber-stamping them as a security-doc core reviewer/security sig chair | 17:36 |
| fungi | i was still not treating it as a responsibility of the vmt members | 17:36 |
| fungi | it's possible that nuanced distinction didn't confer | 17:37 |
| fungi | it was more a result of me wearing too many hats at once | 17:38 |
| * fungi became a hat tree | 17:38 | |
| opendevreview | Merged openstack/security-doc master: OSSN-0101: Nova console proxy Origin poisoning https://review.opendev.org/c/openstack/security-doc/+/996187 | 17:56 |
| gouthamr | tyty, will react to this discussion in a bit, got into a meeting | 17:56 |
| gouthamr | ugh, i messed up the version string | 18:31 |
| opendevreview | Goutham Pacha Ravi proposed openstack/security-doc master: OSSN-0101: Fix affected version string https://review.opendev.org/c/openstack/security-doc/+/996700 | 18:32 |
| gouthamr | sorry :( | 18:32 |
| gouthamr | https://wiki.openstack.org/wiki/OSSN/OSSN-0101 is live ; i'll edit this there too if you folks can approve | 18:32 |
| gouthamr | on the process, i agree.. since the VMT seems to now own the thing, and there's an overlap with the security-sig, we can define some rules | 18:50 |
| gouthamr | if the goal is that OSSNs will have some sort of operator intervention beyond applying patches, it'll be a good clarification; i agree that I've been using this as the VMT's classification was not enough to trigger an OSSA.. but, operator notification is still important to suggest an upgrade, so here's an OSSN | 18:51 |
| gouthamr | so if you propose the rules, i'll be +1, JayF | 18:52 |
| * gouthamr is a smaller hat tree, still growing some limbs | 18:53 | |
| fungi | lgtm, rubber-stamped ;) | 18:56 |
| gouthamr | haha :) | 18:56 |
| gouthamr | tyty, sending emails | 18:56 |
| fungi | yeah, the various ossn mentions in our taxonomy were essentially a compromise with the ossg back in the day, to indicate the sorts of non-ossa bugs they sometimes would issue an ossn about, though ossn can also be used for more than just vmt cast-off bugs | 18:57 |
| gouthamr | yes! external software/systems | 18:58 |
| fungi | accepted openstack-announce post, version string was certainly correct there! | 18:58 |
| gouthamr | neat :) | 18:59 |
| gouthamr | won't bug you anymore, hopefully for today | 18:59 |
| fungi | hah, it's the whole reason i come here tho! | 19:03 |
| gouthamr | bugs? :D | 19:04 |
| opendevreview | Merged openstack/security-doc master: OSSN-0101: Fix affected version string https://review.opendev.org/c/openstack/security-doc/+/996700 | 19:04 |
| -Guest12850- NOTICE: The Gerrit service on review.opendev.org will be offline briefly one hour from now, at 21:00 UTC, while we rename a project. | 20:02 | |
| -Guest12850- NOTICE: The Gerrit service on review.opendev.org is going offline momentarily at 21:00 UTC while we rename a project, but will return within a few minutes. | 21:00 | |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!