moparisthebest: should I change something in my git config to make my PRs easier to handle?
moparisthebest
nicoco, it's fine, though I am curious what made that other one, did you edit something with the github UI maybe?
moparisthebest
I was just using your PR for testing my triage script since it's the first PR I saw that edited just 1 existing xep
daagshas joined
nicoco
I may have used the github UI at some point yes
nicoco
truenicoco is my github username
konstantinoshas left
konstantinoshas joined
Alexhas left
florettahas left
nicoco
so, the 2 emails I sent to standards@xmpp.org yesterday never reached the mailing list it seems. example of sent mail: https://paste.sr.ht/~nicoco/aeab19abcec27bbd20e261657f1fc9d906d4ea51 - I did not even receive a delivery failure or anything.
Also, I am apparently subscribed to the mailing list but never received the 4 emails of yesterday? What did I do wrong? Apologies for being a little dumb about something as straightforward as using a mailing list
moparisthebest
mailing lists are not straightforward at all, unfortunately
moparisthebest
you are sure you are subscribed with that email ? https://mail.jabber.org/mailman/listinfo/standards
moparisthebest
the mail not reaching you is more easily explainable, I hardly get any mail from the lists too, because my server is set up properly to apply DMARC policies and such
nicoco
ok, it's too early in the morning here, I did receive yesterday's email after all -_-
marmarperhas left
florettahas joined
nicoco
but my emails not reaching the list is really happening though. Anything in the email I have pasted that can explain it? This is just vanilla thunderbird from debian stable sending a plain text email.
moparisthebest
I can't explain that, maybe you got moderated somehow and someone has to allow it through the first time or something?
tbm16has left
nicoco
possibly, yes. I know that gmail does not like my @nicoco.fr emails and they end up in spam (I'm not even selfhosting, it's provided by my registrar :/)
mdosch
Maybe check SPF, dmarc and so on. E.g. there https://mecsa.jrc.ec.europa.eu
karoshihas joined
nicoco
mdosch: hmmm indeed my email provider does not seem grea:
CONFIDENTIAL DELIVERY: 3.5/5
PHISHING AND IDENTITY THEFT: 0/5
INTEGRITY OF MESSAGES: 0/5✎
nicoco
mdosch: hmmm indeed my email provider does not seem great:
CONFIDENTIAL DELIVERY: 3.5/5
PHISHING AND IDENTITY THEFT: 0/5
INTEGRITY OF MESSAGES: 0/5 ✏
Danielhas left
Danielhas joined
tbm16has joined
derdanielhas left
nicoco
I'll just send from my old gmail account I guess, bye bye swag
nicocohas left
nicocohas joined
Paganinihas left
Paganinihas joined
wurstsalathas joined
emushas joined
wurstsalathas left
wurstsalathas joined
marmarperhas joined
tbm16has left
tbm16has joined
rubihas left
rubihas joined
Mario Sabatinohas joined
atomicwatchhas left
nicomuchas joined
atomicwatchhas joined
nicomuchas left
nicomuchas joined
rubihas left
rubihas joined
atomicwatchhas left
atomicwatchhas joined
rubihas left
rubihas joined
neoxhas joined
atomicwatchhas left
Alexhas joined
asterixhas left
asterixhas joined
derdanielhas joined
atomicwatchhas joined
asterixhas left
asterixhas joined
catchyhas left
catchyhas joined
rubihas left
rubihas joined
sonnyhas left
sonnyhas joined
asterixhas left
asterixhas joined
rubihas left
rubihas joined
goffihas left
nicomuchas left
Maxencehas joined
Ellenor Malik
as a qmailer I would be likely to show low confidentiality on that absurd score
papatutuwawahas joined
goffihas joined
atomicwatchhas left
Paganinihas left
goffihas left
goffihas joined
qwestionhas joined
sonnyhas left
sonnyhas joined
atomicwatchhas joined
goffihas left
goffihas joined
rubihas left
rubihas joined
lskdjfhas joined
antranigvhas joined
rubihas left
rubihas joined
karoshihas left
rubihas left
antranigvhas left
rubihas joined
antranigvhas joined
papatutuwawahas left
marmarperhas left
karoshihas joined
qwestionhas left
marmarperhas joined
qwestionhas joined
inkyhas left
asterixhas left
asterixhas joined
sonnyhas left
sonnyhas joined
Zashhas left
Stevehas left
Stevehas joined
tykaynhas joined
mhhas left
mhhas joined
Kevhas joined
Zashhas joined
qwestionhas left
nicoco
well, it helped me set up a few magic things in my dns entries, and now I see that my mails now reach the mailing list! thanks mdosch, that was a useful tip
Kevhas left
atomicwatchhas left
govanifyhas left
Guus
I think I've seen a writeup somewhere about the dangers of stanza address spoofing. Can someone unearth a link?
petrescatraianhas left
govanifyhas joined
Dele Olajidehas joined
marmarperhas left
Titihas joined
intosihas joined
rubihas left
inkyhas joined
marmarperhas joined
jcbrandhas left
Dele Olajidehas left
Dele Olajidehas joined
petrescatraianhas joined
atomicwatchhas joined
stphas joined
Andrzejhas joined
catchyhas left
catchyhas joined
Axelhas joined
debaclehas joined
rubihas joined
beanhas joined
beanhas left
Axelhas left
gooyahas joined
stphas left
antranigvhas left
alex11has joined
LNJhas joined
govanifyhas left
mdosch
nicoco: yw
Zash
Guus, which kind of spoofing?
MSavoritias (fae,ve)has left
MSavoritias (fae,ve)has joined
xnamedhas left
xnamedhas joined
tykaynhas left
govanifyhas joined
Guus
clients receiving stanzas with a 'from' address that is not the address of the entity that sent the stanza.
atomicwatchhas left
Sevehas left
Sevehas joined
Martinhas joined
Patigahas left
Patigahas joined
MSavoritias (fae,ve)has left
MSavoritias (fae,ve)has joined
Patigahas left
Patigahas joined
Axelhas joined
tbm16has left
tbm16has joined
atomicwatchhas joined
flow
Guus: I think that should never happenâ„¢. it's only a concern for wrapped stanzas, e.g., when carbons are used. I believe the carbons xep has some words about it, maybe you mean that?
asterixhas left
asterixhas joined
Vaulorhas left
Vaulorhas joined
atomicwatchhas left
antranigvhas joined
miruxhas left
miruxhas joined
cheokeshas joined
atomicwatchhas joined
debaclehas left
cheokeshas left
adiaholichas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
adiaholichas joined
cheokeshas joined
cheokeshas left
sonnyhas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
djorzhas joined
cheokeshas left
djorzhas left
sonnyhas joined
cheokeshas joined
cheokeshas left
kujiuhas left
cheokeshas joined
cheokeshas left
kujiuhas joined
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
Stevehas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
tbm16has left
tbm16has joined
cheokeshas joined
cheokeshas left
xeckshas left
xeckshas joined
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
Friendly Resident Cynichas left
cheokeshas joined
cheokeshas left
djorzhas joined
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
Menelhas left
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
Menelhas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
Stevehas joined
cheokeshas joined
Menelhas left
cheokeshas left
Menelhas joined
cheokeshas joined
cheokeshas left
djorzhas left
cheokeshas joined
djorzhas joined
debaclehas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
sonnyhas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
cheokeshas joined
cheokeshas left
catchyhas left
cheokeshas joined
catchyhas joined
cheokeshas left
catchyhas left
cheokeshas joined
catchyhas joined
cheokeshas left
cheokeshas joined
cheokeshas left
sonnyhas joined
Ray22has joined
neshtaxmpphas left
neshtaxmpphas joined
Stevehas left
Stevehas joined
Stevehas left
Stevehas joined
adiaholichas left
adiaholichas joined
Sevehas left
Sevehas joined
tbm16has left
Friendly Resident Cynichas joined
djorzhas left
marchas left
tbm16has joined
zonsopkomsthas left
zonsopkomsthas joined
atomicwatchhas left
Stevehas left
Wojtekhas joined
jcbrandhas joined
catchyhas left
catchyhas joined
govanifyhas left
Sevehas left
govanifyhas joined
atomicwatchhas joined
atomicwatchhas left
atomicwatchhas joined
atomicwatchhas left
Sevehas joined
atomicwatchhas joined
Stevehas joined
Half-Shothas left
Matthewhas left
uhoreghas left
homebeachhas left
Half-Shothas joined
Matthewhas joined
homebeachhas joined
uhoreghas joined
adiaholichas left
govanifyhas left
Stevehas left
goffihas left
goffihas joined
marchas joined
govanifyhas joined
adiaholichas joined
marmarperhas left
papatutuwawahas joined
rubihas left
Sevehas left
Vaulorhas left
Vaulorhas joined
Stevehas joined
djorzhas joined
marchas left
rubihas joined
Sevehas joined
Wojtekhas left
Stevehas left
Stevehas joined
Kevhas joined
Kevhas left
goffihas left
wladmishas left
goffihas joined
wladmishas joined
singpolymahas left
singpolymahas joined
marchas joined
Ray22has left
konstantinoshas left
konstantinoshas joined
Kevhas joined
rubihas left
rubihas joined
singpolymahas left
singpolymahas joined
oshnhas left
Kevhas left
neshtaxmpphas left
Titihas left
neshtaxmpphas joined
singpolymahas left
singpolymahas joined
stphas joined
tbm16has left
tbm16has joined
bhavyhas left
bhavyhas joined
papatutuwawahas left
singpolymahas left
singpolymahas joined
arcxihas left
Stevehas left
singpolymahas left
singpolymahas joined
LNJhas left
Andrzejhas left
LNJhas joined
tbm16has left
Wojtekhas joined
tbm16has joined
adiaholichas left
stphas left
adiaholichas joined
goffihas left
Titihas joined
vanitasvitaehas left
Stevehas joined
arcxihas joined
Wojtekhas left
Half-Shothas left
homebeachhas left
Matthewhas left
uhoreghas left
Half-Shothas joined
Matthewhas joined
homebeachhas joined
uhoreghas joined
LNJhas left
Wojtekhas joined
marmarperhas joined
moparisthebest
Guus, flow: except when there are bugs https://bugs.chromium.org/p/project-zero/issues/detail?id=2254
mhhas left
singpolymahas left
singpolymahas joined
vanitasvitaehas joined
Wojtekhas left
singpolymahas left
mhhas joined
singpolymahas joined
Trunghas left
Wojtekhas joined
miruxhas left
Stevehas left
adiaholichas left
LNJhas joined
adiaholichas joined
miruxhas joined
Maranda[x]has left
Wojtekhas left
Maranda[x]has joined
Carbon Budgethas left
Marandahas left
Mjolnir Archonhas left
brunrobehas left
Patigahas left
Menelhas left
miruxhas left
Menelhas joined
LNJhas left
singpolymahas left
singpolymahas joined
atomicwatchhas left
flow
of course, if you are not standards compliant then it can happen
flow
but with <forwarded/> the situation is slighlty different as it is hard, if not impossible, to validate the value
flow
I am also not sure if Guus really wants to know about the dangers, or rather the causes of address spoofing
marmarperhas left
Guus
Finding motivation for others to validate 'from' addresses in their client.
projjalmhas joined
jonas’
what do you mean by "validate" in this context?
Guus
ensure that the sender of an IQ result is the one that you sent the IQ get/set to.
Zash
oh, when you only check the id?
Guus
Not accept roster pushes from anything but your local domain - something like that.
singpolymahas left
singpolymahas joined
Zash
https://xmpp.org/extensions/xep-0280.html#security has some CVEs you can scare people with :)
LNJhas joined
asterixhas left
asterixhas joined
asterixhas left
asterixhas joined
projjalmhas left
Guus
ah, thanks.
singpolymahas left
singpolymahas joined
Wojtekhas joined
Zash
Hm, I sorta expected Ge0rG or xnyhps to have blogged something on the subject but I find nothing.
Stevehas joined
Dele Olajidehas left
Dele Olajidehas joined
Stevehas left
Mario Sabatinohas left
thilo.molitorhas left
Mario Sabatinohas joined
Stevehas joined
thilo.molitorhas joined
Guus
One of those CVEs is from Ge0rG
flow
Guus, I think you need to take from address *and* stanza id into account when matching an IQ response to an result
flow
of course, that is not trivial in XMPP
Dele Olajidehas left
Dele Olajidehas joined
flow
(or use sufficently random IDs, that is)
Wojtekhas left
davidhas joined
davidhas left
Wojtekhas joined
konstantinoshas left
konstantinoshas joined
goffihas joined
Wojtekhas left
Menelhas left
singpolyma
Even if you use address but bad IDs it can be an issue. I had a stack that was using sequential IDs and every time the software restarted it would start at 1 again. Was a pretty big problem. I patched it to uuids
Menelhas joined
marmarperhas joined
Menelhas left
Dele Olajidehas left
Menelhas joined
Menelhas left
Ray22has joined
Patigahas joined
singpolymahas left
singpolymahas joined
Calvinhas joined
catchyhas left
catchyhas joined
djorzhas left
Wojtekhas joined
yushyinhas left
miruxhas joined
davidhas joined
davidhas left
yushyinhas joined
singpolymahas left
singpolymahas joined
Wojtekhas left
singpolymahas left
singpolymahas joined
LNJhas left
Andrzejhas joined
neshtaxmpphas left
neshtaxmpphas joined
davidhas joined
davidhas left
neshtaxmpphas left
papatutuwawahas joined
neshtaxmpphas joined
BASSGODhas left
inkyhas left
LNJhas joined
beanhas joined
beanhas left
beanhas joined
Tobihas left
Tobihas joined
marchas left
marmarperhas left
marchas joined
beanhas left
LNJhas left
inkyhas joined
singpolymahas left
singpolymahas joined
Carbon Budgethas joined
catchyhas left
catchyhas joined
beanhas joined
brunrobehas joined
konstantinoshas left
neshtaxmpphas left
neshtaxmpphas joined
konstantinoshas joined
neshtaxmpphas left
neshtaxmpphas joined
catchyhas left
Sevehas left
Sevehas joined
catchyhas joined
singpolymahas left
singpolymahas joined
catchyhas left
beanhas left
marmarperhas joined
L29Ahhas left
L29Ahhas joined
miruxhas left
neshtaxmpphas left
neshtaxmpphas joined
debaclehas left
singpolymahas left
singpolymahas joined
Wojtekhas joined
miruxhas joined
L29Ahhas left
catchyhas joined
marmarperhas left
singpolymahas left
singpolymahas joined
sebastianhas left
sebastianhas joined
marchas left
Marandahas joined
Mjolnir Archonhas joined
singpolymahas left
singpolymahas joined
Tobiashas left
Tobihas left
Tobiashas joined
Tobiashas left
Tobihas joined
Tobiashas joined
neshtaxmpphas left
neshtaxmpphas joined
Wojtekhas left
djorzhas joined
Ray22has left
Dele Olajidehas joined
asterixhas left
asterixhas joined
twisted firestarterhas left
Dele Olajidehas left
djorzhas left
Wojtekhas joined
twisted firestarterhas joined
djorzhas joined
L29Ahhas joined
singpolymahas left
singpolymahas joined
emus
Hello,
a kind reminder to reach out if you are interested to apply with your project at the GSoC 2023 via the XSF.
Furthermore, we need a backup for the Org Admin role (me).
Most required information is in the wiki page: https://wiki.xmpp.org/web/Google_Summer_of_Code_2023#Overview
Last but not least we are looking for volunteers to create a little but hopefully entertaining XMPP quiz for appliers. It should contain basically:
- General questions on what XMPP is
- General architectural question to understand the setup
- First technical questions
- What you can think of
Collect your questions (but *not* the answers!) here:
https://yopad.eu/p/XMPP-Quiz-365days✎
emus
Hello,
a kind reminder to reach out if you are interested to apply with your project at the GSoC 2023 via the XSF.
Furthermore, we need a backup for the Org Admin role (me).
Most required information is in the wiki page: https://wiki.xmpp.org/web/Google_Summer_of_Code_2023
Last but not least we are looking for volunteers to create a little but hopefully entertaining XMPP quiz for appliers. It should contain basically:
- General questions on what XMPP is
- General architectural question to understand the setup
- First technical questions
- What you can think of
Collect your questions (but *not* the answers!) here:
https://yopad.eu/p/XMPP-Quiz-365days ✏