============================ #openstack-meeting: security ============================ Meeting started by gagehugo at 15:01:54 UTC. The full logs are available at http://eavesdrop.openstack.org/meetings/security/2018/security.2018-12-20-15.01.log.html . Meeting summary --------------- * LINK: https://etherpad.openstack.org/p/security-agenda (gagehugo, 15:02:35) * LINK: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20170 (fungi, 15:07:27) * LINK: https://launchpad.net/bugs/1795800 Timing oracle in core auth plugin simplifies brute-forcing usernames (fungi, 15:09:00) * LINK: http://eavesdrop.openstack.org/irclogs/%23openstack-keystone/%23openstack-keystone.2018-12-17.log.html#t2018-12-17T20:03:41 (gagehugo, 15:09:34) * LINK: https://review.openstack.org/#/q/topic:add_hsm_parameters (redrobot, 15:10:23) Meeting ended at 15:23:02 UTC. People present (lines said) --------------------------- * gagehugo (23) * fungi (12) * redrobot (6) * openstack (4) Generated by `MeetBot`_ 0.1.4