/srv/irclogs.ubuntu.com/2014/11/12/#ubuntu-us-mi.txt

jrwrencrap they are pulling: mitm ssl proxy :(00:14
cmaloneyYeah, thats' some bullshit02:46
jrwrenmitm ssl proxy is especially scary when you consider that your wireless vendor controls the root ca list on your wireless device. they can mitm ssl and you would never know.13:44
brouschOne more reason the Internet needs to be treated as a regulated public utility13:46
dzhoI don't disagree at either end of that, but I don't think the connection between them is as strong.14:41
dzhothe conclusion I'd draw is, this is why we need libre software on our devices14:41
dzhoso we can know from whence our ca settings come, and what they are14:41
brouschSo Linux users are unaffected by this mitm attack?14:46
cmaloneyGOo dmorning14:47
rick_h_morning14:52
jrwrendzho: exactly! And we need not just browsers like firefox, but firefox with Certificate Patrol and ability to not SSL connect if a CA has changed. sadly, trusted CAs can't be trusted.15:00
dzhobrousch: sorry, is that a serious question, or just rhetorical?15:02
dzhoin either case, you perhaps may be confusing me for an open source advocate.15:03
brouschSerious. If open source software prevents this kind of problem, why were Linux users still affected?15:03
dzhohaha15:03
dzhoyeah, that's the problem.15:03
dzhoyou seem to think I'm advocating free software as some sort of magic pixie dust to improve quality.15:03
dzhoas if this is just some question of industrial efficiency.15:04
dzhoSix Sigma, whoo!15:04
dzhobrousch: this is what happens when people handwave away the difference between the free software movement and open source15:07
jrwrenbrousch: linux users are affected. I think dzho was pointing out that it is only with open source that we can be sure what is happening.15:07
dzhojrwren: close enough, yeah15:07
brouschPerhaps15:08
dzhothat's still a quality argument, and I won't dispute it.15:08
dzhohttps://www.gnu.org/philosophy/when_free_software_isnt_practically_better.html15:08
dzhoif you've seen that already, my apologies.15:09
dzhosorry, I lost this link, which I prefer, since it brings more to the forefront Mako http://mako.cc/writing/hill-when_free_software_isnt_better.html15:11
jrwrendzho: does anecdotal evidence to the contrary negate the entirity of that argument?15:12
dzhoI'm sympathetic to some of the aversion to RMS that people have, and so think it good to emphasize that there are other prominent free software advocates.15:12
dzhojrwren: sorry, which argument?15:12
jrwrendzho: nevermind. This isn't the article that I thought it was. :)15:13
dzhothere's an open source quality argument, and a free software is inherently valuable despite quality argumen . . . oh, ok :-)15:13
cmaloneyI think OSS tends to bring deeper-level security to the forefront15:14
jrwrencmaloney: hahahahahahahahaha15:14
jrwrencmaloney: you've heard of openssl?15:14
cmaloneyBut I can say from personal experience that I haven't checked my CA list in a while15:14
jrwrencmaloney: you remember the debian ssh keys issue?15:14
cmaloneyjrwren: You remember ILOVEYOU? :)15:14
jrwrencmaloney: :)15:14
cmaloneyThe fact that it was 20 years on for openssl means the code was convoluted enough for smart people not to notice15:15
jrwrencmaloney: Yes.15:16
cmaloneyAnd OSS gets volunteers with varying levels of experience, much like commercial software.15:16
cmaloneyTrying to think of the recent case where a router was pretty much "WONTFIX" on something rather serious.15:16
jrwrencmaloney: in fact, mozilla NSS is a good example15:16
cmaloneyNot coming to me offhand.15:16
dzhoI sort of think of FOSS conditions are pre-requisites, rather than guarantees of, certain kinds of security.15:18
cmaloneyThe difference between OSS and commercial software is commercial software has to pay smart people to audit their code. :)15:18
dzho(commas might need to be shifted around a bit there but whatev)15:18
dzhoOSS and commercial are not opposites :-)15:19
cmaloneyOSS hopefully gets those smart people for free. :)15:19
cmaloneydzho: Oh I know this. They're two sides of the same coin.15:19
dzhoin fact, I think it *possible* for FOSS to allow companies to collaborate to their mutual benefit in a way that would be rightly seen as collusive in a proprietary context.15:19
cmaloneyI can see where you're coming from on that15:20
dzhodangit, I've got a spot on this shirt.15:21
cmaloneyI'm glad I'm not in Marquette at the moment15:38
cmaloneyApparently they have the snow.15:38
jrwrencmaloney: or OSS doesn't get those smart people at all, because they are too busy being employed by the commercial vendors.15:39
cmaloneyjrwren: Yeah15:41
cmaloneyhttp://arstechnica.com/information-technology/2014/11/microsoft-open-sources-net-takes-it-to-linux-and-os-x/15:45
rick_h_yea, jrwren must be doing a happy dance right now...or a "wtf, why not just buy out and use mono"15:48
brouschI've been using VS 2013 desktop for a week now. Very nice15:51
jrwrenyeah, speaking of open source.15:51
jrwrenrick_h_: they likely will be using mono, or did use mono to do the port.15:51
rick_h_jrwren: yea, curious on how that interaction went down15:52
jrwrenrick_h_: MSFT has basically been helping Xamarin every since they launched.15:53
brouschI'm so confused! How can it be a trap if it's MIT licensed?15:53
greg-gpatents15:53
jrwrenEvery since Scott Guthrie became VP of that division, MSFT has been very open and nice.15:53
rick_h_jrwren: yea, but they've still kind of kept thing apart in a way.15:53
jrwrenrick_h_: yup, and now they'll be less apart.15:53
rick_h_jrwren: yea, but now do they need two different implementations?15:54
rick_h_jrwren: or can they all get on board in a single community/code base?15:54
brouschWhew, thanks greg-g15:54
greg-gbrousch: yw, have a nice (paranoid) day!15:54
rick_h_jrwren: they get mono's work on apps on other platforms and mono gets to be ootb for all users15:54
jrwrenrick_h_: pretty sure Mono will use the parts of open source .net that make sense. definitely std library.15:58
jrwrenrick_h_: runtime will probably be trickier since mono targets WAY more platforms than .net.15:58
jrwrenrick_h_: Mono does some things which .net has never done. 64bit large array for example. Which people do use in certain applications. Mono runtime will likely stick around.15:59
jrwrengreg-g: https://github.com/dotnet/corefx/blob/master/PATENTS.TXT16:00
jrwrenbrousch: .net was never a trap, silly.16:00
greg-gof course that doesn't have line breaks....16:01
greg-galso, thanks jrwren :)16:01
greg-g:) We (WMF) are probably going to switch to Debian Jessie (not all at once, gradually) from Precise16:40
rick_h_greg-g: :(16:41
rick_h_greg-g: any killer issue you hit out of curiosity?16:41
jrwrengreg-g: o_O why?16:41
rick_h_or just general debian support?16:41
brouschI assumed it was already on Debian16:47
greg-grick_h_: jrwren there will probably be a blog post when we start doing it. Right now it's just a 17 message thread on our ops list. Hard to summarize. One point is security updates on the entire archive, not just "main"16:51
greg-gAlso, systemd vs upstart16:51
greg-gthe longer we stick with upstart the longer we'll create techdebt in it, so might as well switch to systemd now with Jessie than with ... uh, whatever version Ubuntu will be doing the switch16:52
greg-g15.04, apparently16:52
greg-gpaste-spam:16:53
greg-g* One important difference is, of course, upstart & systemd. This is certainly going to be a difference and is going to require work. However, Ubuntu has already declared they will also switch (probably by 15.04) and hence we'll need to do this eventually anyway. Us jumping ship earlier means that we won't need to keep writing upstart16:53
greg-g services for thefull trusty cycle (until April 2016) and that we c an take advantage of the systemd ecosystem and its benefits (cgroups anyone?) earlier.16:53
greg-gbut, nothing official yet, but the tea leaves (aka list discussion) seems to be saying we're going to switch to Debian with Jessie (on a rolling basis)16:55
jrwreninteresting.16:58
jrwrendo you use many packages outside of main?16:58
jrwreni've not run debian in a long time. Doesn't debian have main and contrib as well?16:58
greg-gdoubt we use anything in contrib that we don't package ourselves, but debian's security promise is much wider (by # of packages) than Ubuntu's16:59
greg-g* Debian actually security-supports the whole archive, rather than ignoring 95% of it (universe), like Ubuntu. This isn't theoretical: it's the reason e.g.  we still have Icinga behind password auth, why we've had a phpMyAdmin compromise in Labs in the past etc.17:00
greg-g* Even in the small set of packages that overlap, Debian's security support is usually better than Canonical's. They're usually faster and usually with more well-thought out patches. (e.g. Heartbleed & POODLE). Also compare the quality (and domain name!) of http://security-tracker.debian.org/ with http://people.canonical.com/~ubuntu-security/cve/17:00
jrwrengreg-g: very interesting.17:01
jrwrenI wonder how debian is so good now when they were so terrible years ago :)17:01
greg-g(that phpmyadmin reference is because someone installed it on a vm in our "labs" infra, aka, our public openstack for anyone)17:01
rick_h_greg-g: but still, 6mo wait for ubuntu + systemd is > changing out whole OS?17:05
rick_h_we already have cgroups in ubuntu, the whole LXC toolchain is based on it17:05
* greg-g is on a call now17:05
rick_h_greg-g: np, just doing some :P17:05
jrwreni'm anti systemd. I hope ubuntu changes course and continues with upstart.17:10
jrwrenI think eventually debian will not use systemd by default.17:10
jrwrenSo, it seems we value different things :)17:10
greg-grick_h_: short answer: there's a lot more in the thread about this that I haven't quoted :)17:35
rick_h_greg-g: cool, I was just curious if there was a straw that broke the camels back kind of thing17:56
greg-gnot sure if there was a straw, I think it's more "we all kinda want to do it anyways, and timing is right"18:00
greg-gthe only problem will be our OpenStack host machines, from what I can tell.18:00
greg-g(not the guests, but the hosts)18:00
rick_h_cool18:01
rick_h_hmm, so is this a kind of app hosting thing like a strange app engine built off aws? https://aws.amazon.com/blogs/aws/code-management-and-deployment/18:21
jrwrenrick_h_: looks like it. Looks like AWS take on Heroku or Azure Web Sites.18:22
rick_h_yea18:22
jrwrenrick_h_: or, AWS take on the best of them all, Cloud Foundry :)18:23
jrwrenrick_h_: not sure how it is different from Elastic Beanstalk18:24
* cmaloney is listening to Finntroll - Trollhammaren20:11
cmaloney<320:11
jrwrenevarlast is currently listening to Suffer the Flesh, by Android Lust (from Resolution)20:17
trevlarrick_h_: are you going to CHC tonight? I can finally get your books back to you :)22:51
rick_h_trevlar: yep, what books?23:11
mrgoodcatcompany gf works at is looking for a html/css/js developer23:13
mrgoodcatlet me know if interested23:13

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!