17:00:52 #startmeeting security 17:00:52 Meeting started Thu Aug 27 17:00:52 2015 UTC and is due to finish in 60 minutes. The chair is tmcpeak. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:00:53 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:00:55 The meeting name has been set to 'security' 17:00:57 o/ 17:00:58 #chair hyakuhei 17:00:58 Current chairs: hyakuhei tmcpeak 17:01:07 Hey everyone :) 17:01:09 o/ 17:01:11 heyo/ 17:01:13 Thanks for kicking off tmcpeak 17:01:16 hi 17:01:18 salut 17:01:19 sure, np 17:01:24 \o 17:01:46 o/ 17:02:25 Ok... 17:02:29 So Agenda 17:02:53 I haven't seen much going on with Bandit or Anchor 17:02:57 Mid-Cycle obviously 17:03:02 Bandit is quiet before the storm 17:03:18 I'm anticipating going nuts on it next week, want to do other things in life first :P 17:03:35 chair6 did some work though 17:03:35 Yeah I've been in a similar camp, trying to tie things off before next week 17:03:45 o/ 17:03:46 Nice 17:04:00 I suspect this might be a shorter meeting than normal 17:04:02 agenda wise michaelxin and co released their API testing tool initial version 17:04:02 hi tristanC 17:04:09 o/ 17:04:10 probably be good to get some info on that 17:04:22 He's not here atm 17:04:49 a very solid point :) 17:05:02 I asked if he'd be willing to do an intro on it next week at midcycle and he said sure 17:05:04 ^ there he is 17:05:12 sorry, I am late 17:05:28 I think a demo at the midcycle would be great 17:05:33 +1 17:05:33 welcome michaelxin! 17:05:38 sure 17:05:44 Can one of you add it to the agenda? 17:05:50 sure 17:05:52 #link https://etherpad.openstack.org/p/security-liberty-midcycle 17:06:06 hi, everyone 17:06:12 hi michaelxin 17:07:11 #topic midcycle 17:07:20 done :) 17:07:39 So I'd really like it if everyone could take a look at the link above and ensure that the topic reflect things that you want to be involved in 17:08:11 there's a lot of stuff now, probably won't have time for half of this 17:08:18 That's fine 17:08:32 We'll continue to do it unconference style. Decide what we think is most important 17:08:44 +1 17:08:47 +1 17:08:53 worked out well last time 17:08:54 +1 17:08:57 Some of the discussions like TA & Crypto can be lengthy or wrapped up quickly if we have some clear objectives. 17:09:27 I'm quite excited to be doing this again, the last two have been such a success! 17:09:39 nice, i'm eager to see how it all goes down =) 17:09:44 yeah, the weeks are a whirlwind but super productive 17:09:58 Chaos but lots of sprints, lots of LOC and lots of good progress :) 17:10:30 first timer. Excited. 17:10:41 Heh 17:10:46 So onto other exciting things 17:10:50 #topic Summit 17:11:09 The agenda is out, Security has 12 slots on the summit, design stuff is yet to be decided 17:11:36 didn't seem like we had much of a track this time, any reason in particular for that @hyakuhei? 17:11:48 12 sessions is a pretty good track 17:12:01 looked like we got all day Thurs and 2 or 3 hours weds 17:12:17 Yeah, I think we had 2-3 more slots last time 17:12:20 Depends on a lot of things 17:12:32 Most of which I don't have much visbility of tbh 17:12:43 there is no monday, so every track is short a few slots. 17:12:43 cool fair enough 17:12:56 dave-mccowan - ah, interesting 17:14:43 One thing I need to do is request the rooms we want for design sessions 17:15:06 hyakuhei: +1 17:15:30 As before we have fishbowl slots (largish rooms) and Workroom slots (smaller) as well as meetup-sessions on the Friday afternoon (likely sparse) 17:15:57 I'm hoping to get 4 workrooms and 2 fish bowls. 17:16:22 workrooms will be for point-tasks: Future of Bandit, Fixing Fuzzing, Anchor roadmap etc 17:16:31 fishbowl will be wider more community facing topic 17:16:51 We can try for more fishbowls but there's a lot of competition 17:17:05 Maybe I'll request 4-3 and we'll see what happens :) 17:17:45 do you want to do a show of hands who is planning to attend? 17:17:59 Tokyo overall? 17:18:00 for something like "future of Bandit" there might not be enough 17:18:03 yeah 17:18:14 I guess so 17:18:21 Show of hands - who's going to be in Tokyo? 17:18:23 o/ 17:18:26 o/ 17:18:29 o/ 17:18:32 o/ 17:18:43 or maybe a civs poll to select the sessions topics ? 17:18:47 o/ 17:18:48 tkelsey will be 17:18:52 sigmavirus24, browne, Daviey, tkelsey? 17:19:03 chair6: possibly 17:19:08 o/ 17:19:12 o/ 17:19:22 ahh ok cool, looks like there would be enough for Bandit then 17:19:36 I'm sure we can find good content 17:19:36 I don't think I'll be in tokyo fwiw 17:19:44 There'll be a lot of stuff to continue from the mid-cycle 17:19:53 I will also not be 17:20:00 :( 17:20:04 =( 17:20:08 Where's the next one, austin ? 17:20:12 yea 17:20:14 eat all the sushi for me 17:20:33 will do! 17:20:49 ok cool, I've put in a request for three fish bowls and 4 work rooms 17:21:26 We'll see what the OpenStack gods decide to give us. 17:21:50 +1 17:22:39 Cool. I didn't have much else to cover today, running around trying to get things ready :) 17:22:47 question about midcycle 17:22:54 how will we decide the sessions? 17:23:02 dart throwing mostly :) 17:23:06 haha 17:23:10 Morning and after lunch 17:23:16 I'll take the group through options for the day 17:23:23 people jump on things that need jumping on 17:23:32 ok, sounds good 17:23:48 It works pretty well, means you can change tasks without burning out, or just go learn about something new etc 17:23:57 cool 17:24:41 I'll put my contact info at the top of the etherpad in case anyone gets into difficulties 17:24:58 I'll drop mine also 17:25:17 i'll update with the address etc a little later today too 17:25:23 well email address at least :P 17:25:43 So the address is on the logistics page but it'll do no harm to put it on the etherpad too 17:26:18 and we'll just need a driver's license, or passport, or something to get guest passes for hp? 17:26:45 (sorry, little unfamiliar with the process) 17:26:50 SSN#, bank account #, etc 17:26:58 All of the above please. 17:27:00 ok, should i just post it here ;) 17:27:04 Oh and cash for erm, security 17:27:07 lol 17:27:11 :-) 17:27:18 Yeah just bring some sensible photo ID 17:27:30 sensible you say... 17:28:19 heh yes. 17:28:24 #topic Any other business 17:28:43 The link for API fuzzing tool is located at https://github.com/rackerlabs/syntribos 17:28:53 anyone tried syntribos yet ? 17:28:58 please feel free to play with it and send us your feedback. 17:28:59 Not yet 17:29:10 I haven't but will soon 17:29:13 my email is michael.xin@rackspace.com 17:29:14 haven't run it, just been browsing the code and instructions 17:29:34 bandit fellas, there's a small review at https://review.openstack.org/#/c/216885/ introducing some basic per-run metrics 17:29:48 We want to hear back from community before adding too many stuff 17:30:00 looks nice 17:30:17 for bandit, one of my guys created a script to convert report to html and pdf 17:30:53 So you might want to add a work topic on Syntribos for the mid-cycle, I can see people wanting to throw new code into the mix, up to you 17:31:03 michaelxin: very cool, is there code for it somewhere? 17:31:24 let me dig it out for you. 17:31:35 michaelxin that sounds interesting, could be something to add to tools/ in the bandit repo.. 17:31:44 +1 17:32:52 ok, anything else to discuss today? 17:32:54 a native HTML / PDF report formatter could be cool too 17:33:14 nothing here 17:33:20 tmcpeak: It is currently in our internal githhub 17:33:28 michaelxin: ahh ok cool 17:33:31 I will ask him to make it public and send it to you 17:33:36 cool, thank you 17:33:39 in openstack-security. 17:34:21 Good plan! 17:34:28 Ok, I think that's a wrap then.... 17:34:32 thanks everybody 17:34:36 #endmeeting