-
anaxagoras
wherethehairygirlsat@conversations.im for rtbl please
-
Amolith
anaxagoras: added
-
anaxagoras
ty
- cumoozingfromerectanuses removed by moderator
- cumoozingfromerectanuses removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- psjjenw removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
- r0 removed by moderator
-
nuron
ralphm, MattJ, jonasā: ^
-
anaxagoras
rapeandkillamolithonsight@conversations.im for rtbl please
-
anaxagoras
there is also mayflower12693, same person, but not sure host part
- hairygirlsequalserectpenis removed by moderator
- hairygirlsequalserectpenis removed by moderator
- hairygirlsequalserectpenis removed by moderator
- hairygirlsequalserectpenis removed by moderator
- penisfartsmakingpee removed by moderator
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
- a moderator removed a message
-
Guus
Server operators: as a developer of server software, how would you suggest that I reach you with important information? I'm trying to get people to upgrade to a version of our software that doesn't have an exploitable vulnerability, but I am having a hard time reaching more than ~6% of you. Does anyone have suggestions on how to improve this?
-
MattJ
Guus, "hard time reaching more than 6% of you" - are you saying you have managed to reach 6%, but unable to reach more? or there are 6% you are finding it hard to reach?
-
Guus
Only 6% of the active servers have been updated to the latest version.
-
Guus
(less than, even)
-
henriette
was a CVE filed? some distros won't push updates without one
-
MattJ
Openfire users don't use distro packages :)
-
henriette
eek
-
MattJ
Guus, if you can work out a suitable shodan search to identify the vulnerable services, you can look up IP/domain contacts
-
henriette
maybe add an update check/notification for future occurrences
-
henriette
if people neglect their server, let them toil
-
MattJ
Unless you are already able to get the domains/IPs from your telemetry
-
Guus
CVE had been published. We're not maintaining packages in distro specific management repos.
-
MattJ
The 6% probably hang around places like this, or the forums, etc. and they're the wrong crowd to adk how to reach them
-
henriette
do you maintain an rpm/apt repo that people install from? or is no one updated because they have to deploy a jar?
-
Guus
I can record IPs. Apart from apparent privacy issues: How do I get contact information from that?
-
henriette
maybe check dockerhub for any openfires and push them to update, users may rely on that way
-
Guus
> The 6% probably hang around places like this, or the forums, etc. and they're the wrong crowd to adk how to reach them Yeah, but not being able to ask the other 94% is kind of the stated problem. š
-
henriette
hairlygirl@conversations.im for rtbl please
-
MattJ
henriette, done
-
henriette
ty
-
MattJ
Guus, look up the reverse DNS
-
henriette
and then do whois on that
-
MattJ
That should give you their domain, or at least their provider, which you can contact
-
Guus
We do not maintain package repos at all. We only offer downloads
-
MattJ
Failing that, whois for the IP will give contact addresses
-
henriette
just note that reverse dns sometimes isn't set or may be a remanent from a previous IP holder (on some low end hosts)
-
Guus
> do you maintain an rpm/apt repo that people install from? or is no one updated because they have to deploy a jar? No jars. We offer platform specific installers
-
henriette
and they have no auto update mechanism?
-
Guus
No
-
Guus
Only an update check that's reported in the administrative interface
-
jonasā
Guus, build an opt-in update notification thing into the next release.
-
jonasā
this can be done in a way that it's not privacy invasive
-
henriette
and make a deb+rpm repo
-
jonasā
(e.g. using a DNS record)
-
Guus
> (e.g. using a DNS record) š¤Ø
-
jonasā
Guus, you could have TXT records for each openfire version with machine-readable content which indicates the security status of that release ("supported", "vulnerable:$fixedVersion", "unsupported") and build code into openfire which looks up the TXT record of its own version and acts according to the result
-
jonasā
as DNS resolution generally happens through recursive resolvers, this is pseudonymised.
-
jonasā
for example, run `dig TXT auth-3.4.0.security-status.secpoll.powerdns.com`
-
jonasā
(to nobody's surprise, powerdns, a DNS server, uses this technique)
-
Guus
That'd improve/make more anonymous the already existing update check. My issue is that only 6% of our admins look at the results of such an update check.
-
jonasā
oh
-
jonasā
make it send a daily message to the admin via XMPP? :-)
-
Guus
We Do That
-
jonasā
ok, then you're doomed
-
Guus
Not daily, but on update availability.
-
jonasā
might be your (corporate) audience :|
-
Guus
Yeah
-
jonasā
Guus, to me, it seems you've done much more than the typical software vendor already and you cannot force people to act responsibly.
-
Guus
Thanks. It's kind of heartbreaking to get reports about crypto miners being installed.
-
jonasā
indeed
-
jonasā
you could also build a kill-switch into the next release.
-
jonasā
but I'm not sure if that's ethical
-
Guus
Absolutely not
-
jonasā
:-)
-
Guus
Our stuff is used in military, law enforcement, health care
-
jonasā
myeah
-
jonasā
that might cause some issues :-)
-
jonasā
but is it better if it's shut down controlledly, or when a cryptominer or worse takes over?✎ -
henriette
do you provided a hardened systemd unit with your packages?
-
jonasā
but is it better if it's shut down controlledly, or when a cryptominer or worse takes (ransomware in a hospital, yay) over? ✏
-
Guus
Well, all of those users are in that 6 percent.
-
Guus
> do you provided a hardened systemd unit with your packages? No. I don't know what that is, but no.
-
henriette
systemd has native sandboxing capabilities
-
jonasā
hardened systemd units: you can restrict what a process can do with systemd, such as removing write access to anywhere except specific directories, restrict access to systemcalls, network families etc.
-
henriette
so at least it'd be limited to miner and not a root escalation/total system compromise
-
jonasā
*much harder to do full system compromise
-
Guus
That's actually a good improvement (but won't help the majority of our instances that are running on Windows).
-
henriette
win32 has sandboxing options too
-
henriette
but must be directly integrated and may not play nice with java
-
Guus
Is worth looking into
-
Guus
Yeah, Java is powerful in that way. And with our plugin API, you can pretty much add any custom code that you like.
-
Guus
(which is part of the current attack vector)
-
henriette
maybe default disable that if possible?
-
Guus
Yeah we've been thinking about that
-
Guus
It's a heavily used feature though
-
Guus
Gotta run. Thanks for the feedback everyone
-
jonasā
cs✎ -
jonasā
(ignore) ✏
-
jonasā
FWIW, we set this room to moderated to combat the spam. We used to have a bot here which auto-voices server admins, which is currently broken. We'll work on fixing that and then we can also process further voice requests.
-
jonasā
(moderated == you can only read, not send messages unless you're "voiced")
-
henriette
hairygirl@conversations.im for rtbl please
-
henriette
(last one was ly)
-
Zash
Guus, posted to https://www.openwall.com/lists/oss-security/ ?
-
Link Mauve
Hi, Matrix.org is now making a publicly accessible archive of their rooms (which includes MUCs), you might want to ban their bot if you donāt want that: https://chaos.social/@n0toose/110593475148424017
-
Link Mauve
I see it at xsf@ for instance, under the nick archive.matrix.org/faq
-
Link Mauve
Or voice your concerns if you donāt think this is a good way to leak all of your chats to the world.
-
MattJ
On the one hand, xsf@ is already publicly logged
-
MattJ
On the other hand, we control those logs (e.g. I suspect when we remove objectionable stuff, the matrix side won't update)
-
msavoritias
also i have no idea i am being logged by a third party when joining the xsf room
-
Link Mauve
MattJ, speaking of which, we might want to reduce the verbosity of those logs by hiding joins/parts by default, to make them more easily readable.
-
henriette
Would it have to be banned from matrix side, or can it be banned from xmpp side across the bifrost?
-
henriette
And weren't most already logged at view.matrix.org?
-
MattJ
FWIW their site now says "The Matrix Public Archive is on hold" - "We are reviewing the Matrix Public Archive to ensure that it doesn't break privacy expectations and have taken it down as a temporary measure while we conduct the investigation."
-
Trung
I'm getting this when visit https://archive.matrix.org/ > We are reviewing the Matrix Public Archive to ensure that it doesn't break privacy expectations and have taken it down as a temporary measure while we conduct the investigation.
-
MSavoritias (fae,ve)
yeah there was backlash. (unsurprisingly)
-
bkil
henriette: Precisely. static-view have been working just like that since 2017, but due to certain bugs, it can't be reliably used for sharing permalinks to past messages (the whole point of the project in my opinion). Hence why the (badly named) archive was created that is basically just a noJS, server-side rendered matrix client. It is not meant to persist (i.e., backup, store, aggregate) messages, as that would be prohibitively expensive. If you check the FAQ, they usually only cache messages for minutes, so the moment you make the room invite-only, the public log disappears.
-
bkil
I'm also puzzled why a few started a banning spree just now - the first public release of archive-matrix went live almost 1 year ago.
-
msavoritias
because probably they dont follow all github repos of matrix closely?
-
msavoritias
its fair if they found out only now
-
msavoritias
aside of all the ethical concerns of course