F-Droid Devs

114 Members
F-Droid development discussion only | Use #fdroid:f-droid.org for general, app- and repo-related matters | Meeting every Thursday at 11:30 UTC | This channel is publicly logged at https://matrix.f-droid.org/alias/%23fdroid-dev:f-droid.org 19 Servers

Load older messages


SenderMessageTime
29 Mar 2021
@eighthave:matrix.org_hcto FDroidException09:16:39
@eighthave:matrix.org_hcthe buildbot prototype shows that it would be much easier to capture logs with buildbot09:17:38
30 Mar 2021
@freenode_shiver:matrix.orgshiver left the room.00:03:05
@freenode_shiver:matrix.orgshiver joined the room.00:08:54
@freenode_izzy:matrix.orgizzy Just wondering: is anyone going to (or already did) answer that mail to team on F-Droid being pre-installed on that new phone? I'm not fit enough in that area to answer it, but it's lying there for almost 4 days now. 00:24:49
@freenode_cdesai:matrix.orgcdesaihow can I get added to team@? admin issue?00:26:16
@freenode_izzy:matrix.orgizzy I guess so. AFAIR Ciaran runs that address and would need to add you. Check admin, there must already be the issue from the "previous run". 00:37:02
@freenode_cdesai:matrix.orgcdesailast comment there was 2y ago :D00:37:55
@freenode_cdesai:matrix.orgcdesaiadmin#9500:38:15
@freenode_[gibot]:matrix.org[gibot][admin] #95: being added to team@f-droid.org - https://gitlab.com/fdroid/admin/issues/9500:38:16
@freenode_whf:matrix.org@freenode_whf:matrix.org left the room.01:23:07
@freenode_whf:matrix.org@freenode_whf:matrix.org joined the room.01:23:16
@freenode_whf:matrix.org@freenode_whf:matrix.org left the room.01:23:16
@freenode_mimi89999:matrix.orgmimi89999_hc, In https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/246 is the compressed data different with a 2-8 byte diff in size or is it the same with the 2-8 bytes appended?14:09:39
@eighthave:matrix.org_hc mimi89999: I don't know, but my guess is that the compressed data is the same since the ZIP algorithm should be deterministic 16:27:59
@freenode_mimi89999:matrix.orgmimi89999Ok, but is the data the same?16:29:18
@freenode_mimi89999:matrix.orgmimi89999Did you upload the 2 apk?16:30:11
@freenode_mimi89999:matrix.orgmimi89999I can inspect them16:31:14
@freenode_mimi89999:matrix.orgmimi89999Even if it should, it does not mean that the implementations are identical16:32:44
@eighthave:matrix.org_hcI thought obfusk was able to confirm that the Python and Java implementation were able to produce the exact same compressed output17:28:14
@eighthave:matrix.org_hcbased on this, seems like we should up our security standards. Like requiring two factor auth for accounts with Developer status: https://arstechnica.com/gadgets/2021/03/hackers-backdoor-php-source-code-after-breaching-internal-git-server/19:29:31
@freenode_cdesai:matrix.orgcdesai I'm not sure if gitlab lets you configure that with such granularity 19:30:50
@freenode_cdesai:matrix.orgcdesaihttps://gitlab.com/help/security/two_factor_authentication#enforcing-2fa-for-all-users-in-a-group19:32:15
@proletarius101:matrix.orgproletarius101
In reply to @eighthave:matrix.org
based on this, seems like we should up our security standards. Like requiring two factor auth for accounts with Developer status: https://arstechnica.com/gadgets/2021/03/hackers-backdoor-php-source-code-after-breaching-internal-git-server/
What have it actually done? To my understanding, the attack path is on the git server other than github. And it attempt to impersonate commit authors
19:33:13
@freenode_cdesai:matrix.orgcdesai As Developer I can't see 2fa status of others, but owners should be able to under 19:33:19
@freenode_cdesai:matrix.orgcdesaihttps://gitlab.com/groups/fdroid/-/group_members?sort=access_level_desc19:33:19
@proletarius101:matrix.orgproletarius101
In reply to @proletarius101:matrix.org
What have it actually done? To my understanding, the attack path is on the git server other than github. And it attempt to impersonate commit authors
That's why I think it has nothing to do with account compromise
19:35:32
@freenode_cdesai:matrix.orgcdesai proletarius101: in our case, gitlab is the git server who we trust, but in addition if anybody who has developer access has an account compromise they could push commits 19:36:31
@proletarius101:matrix.orgproletarius101We can prevent this simply by protect the main branch (no force push on that), and ask each commit to be signed19:36:37
@proletarius101:matrix.orgproletarius101
In reply to @freenode_cdesai:matrix.org
proletarius101: in our case, gitlab is the git server who we trust, but in addition if anybody who has developer access has an account compromise they could push commits
Yeah, but the commit owner should be transparent
19:37:15

Show newer messages


Back to Room ListRoom Version: 1