/srv/irclogs.ubuntu.com/2024/02/06/#ubuntu-security.txt

=== sarnold_ is now known as sarnold
=== chris14_ is now known as chris14
sarnoldJuest: publishing your keys should be pretty safe, at least if you want the email address on the keys to be published..02:49
sarnoldJuest: consuming keys from the keyservers is riskier, but still moderately safe02:50
tewardmdeslaur: just gonna ask but since when has Microsoft ever done anything to the standards expected for software specs and stuff (re: unzip bug)13:42
mdeslaurteward: hehe, well, you'd think they would do interoperability tests...but I guess not :)13:43
tewardmdeslaur: I mean Microsoft **intentionally** ignores/violates email RFC for handling responding to messages, prioritizing the 'Thread-Topic' header - a microsoft-ism - over 'Subject' when hitting "Reply" in any Microsoft mail client13:44
tewardand breaks things like lists, etc.13:45
=== sdeziel_ is now known as sdeziel
mdeslaurteward: it took me _way_ too long to figure out why I couldn't extract a downloaded pictures zip file13:45
tewardMicrosoft has *zero* care for standards and they've proved it time and time again13:45
tewardmdeslaur: welcome to Microsoft, population "Use our [CENSORED] and nothing else"13:45
mdeslaurteward: breathe in, breathe out13:45
tewardmdeslaur: oh i haven't even BEGUN my daily microsoft hatred tirade!  *ground shakes and shatters and dark smoke and fire just erupt from the hellhole that opened*13:46
teward:P13:46
tewardmdeslaur: but no Microsoft has never cared for interop with anything.  Except basic WSL stuff13:46
tewardand... well, that's about it.  Only thing they did positive was SQL Server for Linux when you *need* MS SQL Server and PSQL isn't a good alternative13:47
tewardye i'm biased :P13:47
mdeslaurhehehe13:58
tewardmdeslaur: security related question, how much of a 'security' bug is it when the default permissions set by the installer 14:19
tewardfor a netplan yml on install trigger immediate warnings from Netplan when applying?14:19
tewardblah stupid keyboard14:19
mdeslaurteward: you mean the permissions are too open?14:19
tewardencountered last night on a brand new 22.04 image with up to date netplan, the 50-cloud-config.yml file was created with 644 root:root perms and Netplan started whining about 'too open' and wouldn't stop yelling unless it was 60014:20
tewardye14:20
tewardtrying to reproduce in a 22.04 VM because LXD containers sometimes are not the most reliable test14:20
mdeslaurwell, file a bug, but since it's the installer, there's no real point in it going to -security14:20
tewardright that'd be against subiquity or whatever it is in use right now14:21
tewardwas wondering if it qualified as a security bug or not though14:21
tewardjust before i go down the rabbit hole :P14:21
mdeslaursure, it's complaining for a reason, mark it security14:24
=== chris14_ is now known as chris14
tewardmdeslaur: for awareness, https://bugs.launchpad.net/subiquity/+bug/2052524 was filed for that issue i observed.  The backport of netplan.io to jammy-updates introduced the new warnings unlike previous, and Foundations has this on their todo list to address for the installer now I believe21:36
-ubottu:#ubuntu-security- Launchpad bug 2052524 in subiquity "INSECURE permissions for Ubuntu Netplan YAML on installer execution" [High, Triaged]21:36
mdeslaurcool, thanks teward 21:36

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!