16:59:45 #startmeeting Security 16:59:46 Meeting started Thu Jan 5 16:59:45 2017 UTC and is due to finish in 60 minutes. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 16:59:47 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 16:59:50 The meeting name has been set to 'security' 17:00:03 o/ 17:00:22 o/ 17:00:59 o/ 17:02:09 ... 17:02:24 o/ 17:03:09 Quiet start to the year :) 17:03:44 #link https://etherpad.openstack.org/p/security-agenda 17:04:24 o/ 17:04:26 Our last meeting was quite some time back: #link http://eavesdrop.openstack.org/meetings/security/2016/security.2016-12-15-17.01.html 17:04:28 sorry im late 17:04:35 o/ 17:04:41 o/ 17:04:42 welcome tkelsey capnoday 17:04:51 tkelsey: how dare you be late before I'm late?! :P 17:04:52 hi hyakuhei 17:05:01 lol :) 17:05:40 ok, lets roll on then :) 17:05:47 oh hi sigmavirus :P 17:05:58 #topic Syntribos 17:06:00 damnit. Thought I'd snuck in 17:06:11 Hi All, another year ahead :) 17:06:21 Excellent 17:06:23 :P 17:06:26 we are still working on modifying the templates 17:06:44 on adding ability to add meta variables to req templates 17:06:50 this is the patch for it: https://review.openstack.org/#/c/411415/ 17:07:06 In the mean time a few of us are testing swift.. 17:07:40 with things like if we can find any leakage of info , or privilege escalation or something like that 17:07:46 good work unrahul 17:07:51 +1 17:08:04 we got a few 500 errors, still keeping the hopes high.. 17:08:15 if we get something interesting will let you guys know.. 17:08:19 thanks capnoday tkelsey :) 17:08:27 thats it from us for this week.. 17:09:35 Cool, thanks unrahul 17:10:04 Hmmm, I don't see our OSSN ninja here today. 17:10:10 #topic OSSN 17:10:15 lhinds you around ? 17:10:37 It looks like there's only two OSSN in the queue and they are both under embargo 17:10:55 So capnoday tmcpeak hyakuhei lhinds and whoever else is a core-sec, get on it :) 17:11:03 * capnoday looks 17:11:08 lhinds published a couple of OSSN over the holidays so I think we're all caught up 17:11:20 ahh, embargoed notes <3 17:11:21 For those who are interested, the list is here #link https://bugs.launchpad.net/ossn 17:12:02 hyakuhei: "#link" has to be on its own line I think? 17:12:10 grumble. 17:12:14 #link https://bugs.launchpad.net/ossn 17:12:15 heh 17:12:28 ok, I probably didn't need to use the #link anyway. 17:12:32 That'll teach me for being fancy. 17:13:04 The next item is the blog 17:13:07 #topic Blog 17:13:23 Lets levelset. Does everyone know we have a blog that cross posts with planet openstack? 17:13:41 actualy I didn't know it cross-posted 17:13:43 well. We do 17:13:44 Excellent. 17:13:51 yup 17:14:17 sweet 17:14:30 The actual blog is here 17:14:33 #link https://openstack-security.github.io/ 17:14:45 Writing posts is easy, just markdown 17:14:47 Very easy 17:14:53 and I've not written my post for 2-3 months 17:15:14 are we waiting on any blog posts? 17:15:22 I'd like to take a second to gather some suggestions for articles 17:16:00 well not directly related but what's the plans for PTG? 17:16:06 I assume we want to do some cross-team work? 17:16:11 if we're going? 17:16:29 im waiting on funding confirmation 17:16:37 Security are going, but I don't know how many people from the group are going. 17:16:43 Lets add PTG to the agenda 17:17:24 i'll be at the PTG 17:17:51 great 17:17:53 is the idea with PTG that you spend (bulk) of time with whatever team you're closest to? 17:18:06 Yes but that you also collaborate with others 17:18:09 #topic PTG 17:18:13 ^ As travis can't wait 17:18:20 well it was leading to a blog post idea 17:18:27 albeit very slowly 17:18:29 #link https://www.openstack.org/ptg/ 17:18:46 You'll notice that we are a Monday/Tuesday group 17:19:07 We are specifically in the first section so that we have more time to spend with the more security critical projects over the final three days. 17:19:27 right 17:19:28 The registration is still open: https://pikeptg.eventbrite.com/ 17:20:09 the blog post I was thinking (although could just as easily be a OS-dev post) was about asking if any teams have noticed security concerns they want security advice for 17:20:45 probably more effective as dev-ML 17:20:50 Probably 17:20:56 Though you could do both I guess and reference it 17:21:05 Certainly we'd want a couple of post PTG writeups 17:21:13 It's going to be very interesting to see how the PTG goes 17:21:16 hyakuhei: do we have any numbers about viewers of our blog? 17:21:36 Nope 17:21:40 sorry, now I'm back on blog 17:21:43 lol 17:21:44 lol 17:22:00 I'm operating under the assumption that I won't be at PTG 17:22:12 I haven't had as much OpenStack time dedicated lately :( 17:22:30 Indeed 17:22:36 who here knows they're going to the security session at PTG? 17:22:48 I'll be there :) 17:23:10 what about rackers? 17:23:12 None from the OSIC team would be there.. , we were hoping to attend the next mid cycle meet (assuming it would be there) 17:23:31 unrahul: midcycle == PTG? 17:23:33 unrahul we'll see how the PTG goes. Their intent is to replace the mid-cycles. 17:23:42 :o 17:23:44 tmcpeak They're not quite the same 17:23:50 We might end up having a mid-cycle around the time of the summit 17:23:53 but midcycles are dead, are they not? 17:23:58 As the summit will know be more marchetecty 17:24:02 tmcpeak no-one knows 17:24:07 emm 17:24:10 It really depends if/how the PTG works 17:24:16 yeah, PTG is a replacement for midcycle 17:24:20 midcycles aren't an official openstack function 17:24:26 there is also the question of wether any technical folks will bother to go to the summit 17:24:33 so they can't be replaced or ended by the OS head honchos 17:24:46 However, the intention is that the PTG will remove the _need_ for a midcycle for most projects 17:24:52 well here's the thing 17:24:56 So as I said, it depends how the PTG goes 17:25:00 we haven't planned /budgeted for PTG so this time around we cant come.. 17:25:04 for our midcycles we usually pick a place that's conveniently located for a bulk of our members 17:25:11 so we get more participants by default 17:25:17 usually SA, Austin, or Seattle 17:25:22 who all will be in PTG .. hyakuhei and .. ? 17:25:28 but Atlanta… everybody has to travel 17:25:33 I agree 17:25:35 conveniently located for.. nobody 17:25:39 :) 17:25:44 and have said as much to various TC peoples 17:26:07 it's not going to be much of a PTG session if only Rob goes 17:26:13 even though Rob is awesome and all 17:26:43 However, this is the direction they're going in and for the moment, I'm going to see if we can embrace it and get value from it. A few of us (like me) will have to go anyway. However if the PTG doesn't allow us to do what we need to (and I think the mid-cycles have generally been great events) then we can still have midcycles 17:26:58 but for now, we need to be good citizens and give this a fair try 17:27:03 i think thats reasonable 17:27:11 the opportunity to work with other teams is very valuable 17:27:16 i never have time for that at summits 17:27:22 For my part, my attendance is mostly going to be about the final three days, sitting in on the discussions with other teams and being the voice of security 17:27:35 seems reasonable 17:27:43 That's not an easy thing to pitch to a travel-budget holder though, I get that. 17:27:46 hmm.. that makes sense.. 17:28:10 lol 17:28:16 I suspect after the PTG I'll talk to dave-mccowan and 17:28:26 as we often co-host midcycles, I'll get his take 17:28:34 If we are both PTLs then 17:28:39 Which brings me onto the next topic 17:28:49 #topic Elections 17:28:53 THE ELECTIONS ARE COMING 17:29:02 I nominate tmcpeak 17:29:10 wait, do i have to do that by email? 17:29:19 capnoday: via gerrit actually 17:29:22 January 30-Feb 03 17:29:25 ELECTIONS 17:29:25 and only once the nominations open 17:29:29 Right, you've all been told 17:29:43 sigmavirus got a link/howto? 17:29:43 sigmavirus I suspect capnoday was being facetious 17:29:45 hyakuhei: I recommend daily reminders until someone pukes ;) 17:29:48 i actually wasnt :D 17:29:56 sigmavirus heh 17:30:00 capnoday: it should be on docs.openstack.org 17:30:04 I don't have a link though 17:30:21 Could be https://governance.openstack.org/election/ 17:30:38 (First result on google at least) 17:30:53 lol 17:30:59 #link https://governance.openstack.org/election/#how-to-submit-your-candidacy 17:31:01 Someone should teach capnoday how to google 17:31:03 ^If you want to run 17:31:08 Thanks sigmavirus 17:31:14 so the PTL nomination is PTL nomination Jan 18, 2017 23:59 UTC Jan 29, 2017 23:45 UTC 17:31:17 as per the link.. 17:31:29 and elections from Jan 30 17:31:38 thanks sigmavirus hyakuhei 17:31:40 #info PTL Nominations are open from 18 Jan 2017 23:59 UTC until 29 Jan 2017 23:45 UTC 17:32:09 Ah see, I got the wrong dates. 17:32:13 This stuff is hard :P 17:32:15 I should probably land a commit in a security project so I can vote 17:32:16 but yolo 17:32:17 Timetable here 17:32:19 #link https://releases.openstack.org/ocata/schedule.html#pike-ptls-self-nomination 17:32:58 hyakuhei you running again? 17:33:18 hyakuhei: you should state your intention on the ML too, for greatest reach 17:33:26 We already had the Keystone PTL state they're not running again 17:34:07 I'm in talks with my management about it :) 17:34:25 :D 17:34:30 When you know, let us know ;) 17:34:33 I would like it if we had people who want to try, or to take things in a different direction also stand 17:34:33 is anybody else intending to run? 17:35:39 The collective eagerness is deafening 17:35:44 lol 17:35:46 lol 17:35:51 They're all sneaky, paranoid security types 17:36:04 Playing the cards close to their vests, etc., etc.? 17:36:09 if hyakuhei doesn't get management blessing what happens if we end up with no PTL? 17:36:26 Management makes tmcpeak do it. 17:36:28 tmcpeak: I could run, but again, I'd need to land code 17:36:28 :D 17:36:30 :D 17:36:33 haha 17:36:54 sigmavirus: surely you've landed something in Bandit? 17:37:05 tmcpeak: I don't think so 17:37:31 sigmavirus: run our docs through a grammar checker, there's surely some gold in there 17:37:46 lol 17:37:51 thanks tmcpeak - nice to know my efforts are valued ;) 17:38:04 I guess I co-authored a thing: http://stackalytics.com/?module=bandit&metric=commits&user_id=sigmavirus24 17:38:05 I meant Bandit docs actually, but yeah, even better! 17:38:08 hahaha 17:38:12 hehe.. 17:38:13 Dunno if it's been merged though 17:39:08 I just don't have a reason to run for PTL, other than for us to have a PTL 17:39:21 fair enough 17:39:27 That's a good reason 17:39:29 actually, let's play a little game 17:39:43 michaelxin: not to my management 17:39:48 realistically, on average, how many hours a week do you all have for OS-security? 17:40:04 Well that's relative. 17:40:17 I am supposed to have 4 hours each week. 17:40:21 tmcpeak: assuming that these are hours are provided by management? 0 17:40:21 ouch 17:41:09 The OSIC security team is full time 17:41:12 mine is probably 2 17:41:19 around 2-4, but that's assuming nothing's on fire 17:41:46 michaelxin: supposed to… but in actuality? 17:41:47 probably 2-4, although i havent had clear steer from my management 17:42:11 tmcpeak: 1-2 hours. 17:42:19 in reality 17:42:37 ~.75 17:43:17 so what I'm hearing is there are a few people with at most half a day per week to spend on OpenStack security except for OSIC 17:43:26 Not overly dissimilar myself. Though there's the occasional week where I loose days to it. 17:44:00 tmcpeak: worth noting that OSIC will disappear potentially given that they're going to focus on Nova, Glance, Cinder, Keystone, and 3 other projects in the future 17:44:14 heat, horizon, and ironic iirc 17:44:30 the reason I'm asking about all this is I want us to take this into account when we consider maintaining our existing projects and starting new ones 17:44:33 dunno when that ramp down is happening though 17:44:50 good info 17:44:52 for example, it does not sound like we have the time to do security review across OpenStack right now 17:45:15 but we could, for example, keep notes going 17:45:15 Maybe. 17:45:16 tmcpeak: agreed 17:45:22 Review is interesting 17:45:34 OSIC with no security .. :o 17:45:37 I can put more people on reviews because they need review experience and to develop review processes 17:45:44 scary info 17:45:58 hyakuhei: yes, but there are internal properties that need reviewing too :) 17:47:06 tmcpeak sure, but there is a lot of crossover, at least with materials, process, etc 17:47:18 sorry, not trying to be debbie downer, just want us to think about what footprint we want to maintain 17:47:40 tmcpeak: being realistic isn't being a downer 17:47:47 +1 17:47:49 it's being practical 17:48:04 personally I will probably spend majority of "openstack" dedication to keeping Bandit maintained 17:48:21 yeah, my current openstack dedication is working on craton 17:48:31 Penelope Practical ? 17:48:38 lol 17:48:44 :P 17:48:51 debbie's more fun sister 17:48:56 lol 17:49:12 moving alon 17:49:14 *along 17:49:16 haha 17:49:18 with 10 min left 17:49:24 well one last thing 17:49:58 given that we have on average 3 hours a week, do we want to use one of them meeting, or should we cut meeting time in half, move to twice monthly and keep the allocated time to work on OSSP stuff? 17:50:20 It's rare that we finish a meeting in 30 minutes 17:50:25 Though they could be more structured 17:50:27 hyakuhei: I contend that we could 17:50:29 I'm open to trying shorter meetings 17:50:32 I have a fond place in my heart for the meetings but given that we have less in flight we probably don't need as much meeting 17:50:54 if we kept the hour block on the calendar we could steal 30 minutes to work on actual stuff for OSSP 17:50:56 :) 17:50:57 Having a strict agenda and sticking to it and timeboxing topics is good for this 17:51:03 Also having discussions on the ML first is always helpful 17:51:03 Every other week tends to get messy 17:51:09 shorter meeting is good 17:51:12 That's also true 17:51:15 agreed with hyakuhei about every other week 17:51:18 hyakuhei: agreed two weeks is messy 17:51:36 ok, so we'll look to have shorter, 30 minute meetings, (still start at 1700UTC) 17:51:51 and we agree that we'll have to be more disciplined about agenda in order to make that work. 17:51:57 hyakuhei: +1 17:51:59 cool, hyakuhei want to write a dev-ML bit about it? if not I can 17:52:00 try that next week? 17:52:11 like the openstack equivilant of speed-dating? 17:52:16 hah 17:52:17 Yes 17:52:48 cool 17:52:49 We kinda jumped around the agenda a bit as it's our first meeting, I wanted to mention the signing keys just because it's the sort of thing this group would be interested in: http://lists.openstack.org/pipermail/openstack-dev/2016-December/109111.html 17:53:00 I'll write something up tmcpeak 17:53:17 #topic Any other business 17:53:29 hyakuhei: +1 17:53:34 getting back into secguide touchups, core review here please: https://review.openstack.org/#/c/416138/ 17:54:35 i joined late, but i thought i'd throw in re: PTG and Barbican 17:55:02 we're planning on using PTG instead of a midcycle, but attendance RSVPs are very low. 17:55:18 dave-mccowan: how low? 17:55:29 dave-mccowan ours too 17:55:38 so far 2 confirmed, and 2 maybes. 17:55:52 eek 17:55:59 I think that's 1 more confirmed than us :P 17:56:04 lol yeah 17:56:15 i don't think we'll be able to fill all the time we've reserved the last 3 days with barbican topics. i'd be happy to share, if the security project needs a room for the second half of the week. 17:56:41 dave-mccowan currently I've got a room to myself for the first two days :P 17:56:51 think how much work you will get done! 17:56:57 Thanks for the offer though. I wonder how other teams are doing. 17:57:01 capnoday I am 17:57:03 dave-mccowan: I think we'd be lucky to fill ours too 17:57:06 ok last couple of minutes 17:57:20 that has to be a point on both mid-cycle/ptg and the time we spend on it, we get a LOT done when we all sit in the room for a week 17:57:36 yeah most of our forward momentum is at midcycles 17:58:03 if we average 2 hours per week normally, but then we get 24 hours done twice a year, that's pretty big 17:58:08 tmcpeak +1 17:58:23 so hyakuhei should I save my travel budget for a midcycle? 17:58:24 :) 17:58:43 OSSN bug smash, sec guide sprint, Bandit sprint, etc? 17:58:54 +1 17:59:02 except why dont you come to the PTG and do it there... 17:59:09 Seems that way. I haven't seen much about this on the ML, I'll ping it 17:59:18 Because we position the midcycle so many don't have to travel 17:59:21 or try to 17:59:25 hyakuhei: ++ 17:59:27 anyway, that's our lot. Thanks all 17:59:32 o/ 17:59:35 #endmeeting