17:02:06 #startmeeting security 17:02:07 Meeting started Thu Nov 3 17:02:06 2016 UTC and is due to finish in 60 minutes. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:02:08 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:02:10 The meeting name has been set to 'security' 17:02:20 o/ 17:02:30 o/ 17:02:44 o/ ish - sorry on a call :'( 17:02:47 o/ 17:02:57 #chair hyakuhei 17:02:59 Current chairs: hyakuhei lhinds 17:03:07 o/ 17:03:09 Hi 17:03:13 #topic agenda 17:03:15 hi 17:03:26 todays agenda: https://etherpad.openstack.org/p/security-agenda 17:03:33 #link https://etherpad.openstack.org/p/security-agenda 17:03:49 please made additions / amendments if needed 17:03:55 elmiko how are you? 17:04:21 Michaelxin__: not bad! just getting ready for kubecon and apachecon =) 17:04:24 how you doing? 17:04:28 #topic Privacy Badger + Security blog 17:04:46 Doing ok 17:04:53 Thanks 17:04:59 I can't recall where we are with Privacy Badger, anyone that can update there? 17:05:09 what's the issue here? 17:05:22 is the blog showing some unfriendliness in PB? 17:05:34 IIRC its an addon which does not like the blog? 17:05:51 Hi, I'm Vincenzo Di Somma, this is my first meeting, I'm a security architect, I'm between jobs and looking for ways to help you guys. 17:05:53 yeah, i use it all the time, didn't notice the security blog had warning 17:06:01 Security Blog..any posts pending? 17:06:03 it looks for tracking tokens and the like 17:06:41 #action hyakuhei to give lhinds mergies (or help him spot where the function is) 17:06:54 elmiko: something like that 17:07:03 I was half in the meeting when it was discussed 17:07:11 hi vds ! 17:07:13 vds: welcome! 17:07:16 nice to have you! 17:07:20 Welcome 17:07:21 Welcome! 17:07:43 thank you! 17:07:55 anymore on the blog...? 17:08:08 going, going, gone.. 17:08:14 #topic OpenCIT 17:08:31 oh wait 17:08:31 I think we might need tmcpeak for this. 17:08:35 elmiko: sure... 17:08:47 openCIT? 17:08:50 just to add on to the blog thing, looks like the blog site has hidden links to google-analytics and something about google drive 17:08:54 that's what PB is reporting 17:09:08 ahh iirc thats because we are hosting some of the images on google drive 17:09:17 makes sense 17:09:24 just wanted to add that, sorry for the overlfow 17:09:31 so we need to move them into the gitpages repo? 17:09:35 yup 17:09:52 and remove the analytics stuff, i would imagine, although that kinda doesn't help with metrics lol 17:09:59 yeh thats annoying 17:10:00 #action lhinds to move images over to gitpages repo 17:10:06 thanks lhinds 17:10:18 i'd have thought every website in the world would trigger the analytics filter 17:10:36 not sure about if we should touch analytics, lets park that for next week maybe 17:10:43 capnoday: they mostly do lol 17:10:51 lhinds: +1 17:11:04 k OpenCIT 17:11:08 #link https://etherpad.openstack.org/p/security-cit 17:11:18 OpenCIT is intels next evo of trusted boot 17:11:20 lhinds +1 17:11:24 ahh yeah 17:11:35 they have re-wrote the openattestation stuff 17:11:37 looks neat 17:12:02 and can do new funky things like extend the trust from the kvm/qemu for the VM boot cycle 17:12:20 they shared with us about the new nova scheduler filter for trusted compute pools. 17:12:37 I think they want some community momentum so were seeking others to get involved 17:12:47 thus presenting to the OSSP at the summit 17:13:15 we gave some feedback, but not sure what the next steps were. 17:13:27 I guess we can check with tmcpeak when he is back 17:13:44 #topic Syntribos 17:14:25 All team members went to a local security conference 17:14:35 Lascon 17:14:46 So, no update this week 17:14:52 k, thx Michaelxin__ 17:15:02 #topic OSSN 17:15:26 So we have three embargoed notes being worked on by hyakuhei and tmcpeak 17:15:41 and a new public if anyone has an interest in getting into note authorship? 17:16:25 if not I will assign it to myself 17:16:38 #link https://bugs.launchpad.net/ossn/+bug/1562175 17:16:38 Launchpad bug 1562175 in OpenStack Security Advisory "Pre-auth COPY in versioned_writes can result in a successful COPY that wouldn't have been authorized" [Undecided,Incomplete] 17:16:59 if anyone wants to read it first, and have a think about it, you can ping me later on and we can discuss whats needed 17:17:31 notes are a good way of getting involved into the security group, and there is some hand holding on the first few, so don't be concerned about taking on something major 17:17:43 can I take it? 17:17:50 vds: sure! 17:17:53 thanks! 17:18:01 do you have a launchpad account? 17:18:11 yup 17:18:23 vds 17:18:34 k, under 'OpenStack Security Notes' - changed 'UNassigned' to yourself 17:18:53 and I can help you get going from there, what TZ are you in? 17:19:15 s/changed/change 17:19:16 Isnt there a wiki page on how to get started writing notes? 17:19:37 capnoday: good Q.. 17:19:41 17:19:52 #link: https://wiki.openstack.org/wiki/Security/Security_Note_Process 17:20:08 yep, there we go vds ^ 17:20:09 lhinds: UTC+2 17:20:35 great, thanks 17:20:44 vds: ok, so I am on UTC right now, so you can ping me if you need any help. 17:21:04 thanks sicarie 17:21:10 lhinds: will do, thx! 17:21:17 vds: I'm also secguide core and do quite a bit with documentation (of which this is a more relaxed version) so feel free to reach out to me as well, though lhinds will probably be more helpful 17:21:38 sicarie: thx 17:21:44 sicarie +1, he helped me a lot to get started 17:21:54 #topic Security Review 17:22:09 I doubt there is anything new here with the summit just passed? 17:22:37 did anything come out of the summit? 17:22:41 there were sessions on this? 17:23:16 So I copied and pasted the last etherpad entry...does this pertain to Threat Analysis or something else? 17:24:37 regarding the summit, we spoke about threat analysis, I showed the new Notes API I started prototyping, and there was a demo of the Bandit Jenkins plugin. 17:24:37 pasted it where? 17:24:49 https://etherpad.openstack.org/p/security-agenda 17:24:55 nothing on the threat analysis at the summit? 17:25:20 There was some good feedback. Unfortunately I'm on the phone right now 17:25:25 capnoday: yes, hyakuhei did a session with projects invited..like an ambassdor / out reach 17:25:46 Not much on the https://etherpad.openstack.org/p/BCN-security-ta 17:26:05 ok lets shelve this until next week 17:26:05 thanks hyakuhei 17:26:42 #topic security guide 17:27:00 nothing from me 17:27:04 been trying to recover 17:27:07 updates were merged for newton: https://review.openstack.org/#/c/382600/2/releasenotes/source/newton.rst 17:27:23 and the queue is empty: https://review.openstack.org/#/q/status:open+project:openstack/security-doc,n,z 17:27:43 hope your feeling better sicarie 17:27:53 just need sleep: new baby 17:27:54 :D 17:28:02 but I should be able to ramp up again soon 17:28:05 oh, I know those :) 17:28:33 #topic OpenStack Barcelona Washup 17:28:47 so this is for a post summit discussion. 17:29:15 I highlighted the key points above. I was thinking, those of us that went could maybe joint author a blog post? 17:29:24 hyakuhei sound like a good idea? 17:29:56 that will be a way of capturing for others, and having on record 17:30:25 i nominate gmurphy 17:30:33 lol 17:30:53 sorry, just had to give him a hard time :) 17:31:13 another topic of interest was the nova security summit: https://etherpad.openstack.org/p/ocata-nova-summit-security 17:31:17 #link https://etherpad.openstack.org/p/ocata-nova-summit-security 17:31:20 understandable, he's so loveable =) 17:31:41 Lot's on image signing, with feedback from myself and hyakuhei (well more hyakuhei then me) 17:32:09 k, that's all from me.. 17:32:12 #topic AOB 17:32:42 I just noticed Bandit was not on the list, so if some Bandit cores are here, I could hash that as a topic? 17:32:46 same for anchor 17:33:05 anchor is currently a nop 17:33:13 so that can stay off the agenda for the moment 17:33:19 capnoday: thx 17:33:32 travis and tkelsey arent here, so lets leave bandit unless anyone wants to discuss it 17:34:02 k, thanks all! 17:34:06 #endmeeting