1465 lines
372 KiB
HTML
1465 lines
372 KiB
HTML
<html><body><style>
|
|
* {
|
|
font-family:sans-serif;
|
|
}
|
|
body {
|
|
text-align:center;
|
|
padding:1em;
|
|
}
|
|
.messages {
|
|
width:100%;
|
|
max-width:700px;
|
|
text-align:left;
|
|
display:inline-block;
|
|
}
|
|
.messages img {
|
|
background-color:rgb(248,244,240);
|
|
width:36px;
|
|
height:36px;
|
|
border-radius:0.2em;
|
|
display:inline-block;
|
|
vertical-align:top;
|
|
margin-right:0.65em;
|
|
}
|
|
.messages .time {
|
|
display:inline-block;
|
|
color:rgb(200,200,200);
|
|
margin-left:0.5em;
|
|
}
|
|
.messages .username {
|
|
display:inline-block;
|
|
font-weight:600;
|
|
line-height:1;
|
|
}
|
|
.messages .message {
|
|
display:inline-block;
|
|
vertical-align:top;
|
|
line-height:1;
|
|
width:calc(100% - 3em);
|
|
}
|
|
.messages .message .msg {
|
|
line-height:1.5;
|
|
}
|
|
</style><div class="messages"><div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-04-16 03:03</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-04-17 01:16</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-04-25 12:50</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-05-15 14:17</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-05-15 14:25</div><div class="msg">Here's a work in progress of an ethical design checklist: <a href="http://d3e.co/iz">http://d3e.co/iz</a>
|
|
|
|
It's a work in progress with intention to be published by Stanford Peace Innovation Lab in the coming months.
|
|
|
|
I invite you to add your thoughts and comments.
|
|
|
|
The list is intended to shape a process for continuous risk assessment to build ethical products; trying to provide a framework that's actually helpful rather than pointing a finger at broad terms like 'security', 'privacy', etc.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-13/329132457109_199841cd908ca7faa97f_72.jpg" /><div class="message"><div class="username">rachel</div><div class="time">2018-05-17 11:08</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2018-05-17 11:08</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-05-17 17:29</div><div class="msg">Here are the notes of our meeting on Risk management processes today. Thank you @rachel! <a href="https://docs.google.com/document/d/1Nc2kZzDuAebmGO6eqlFA0W133X21ceUthXPDCLhqq1k/edit?usp=sharing">https://docs.google.com/document/d/1Nc2kZzDuAebmGO6eqlFA0W133X21ceUthXPDCLhqq1k/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-05-17 19:24</div><div class="msg">For track B - Risks & Mitigations we now have an actual workable document to continue with next week. Thanks to @alexmandel. For cleaning up and ensuring that all documented issues are legible and understandable.
|
|
|
|
<a href="https://docs.google.com/document/d/1dHPTMmeRaLi3cQQmNjxZldfOx90PihE3ltT7bphiceQ/edit#">https://docs.google.com/document/d/1dHPTMmeRaLi3cQQmNjxZldfOx90PihE3ltT7bphiceQ/edit#</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-15/346893164260_0a370a8a1614301a6877_72.jpg" /><div class="message"><div class="username">alexmandel</div><div class="time">2018-05-17 19:24</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-20 07:27</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-23 13:03</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-23 13:11</div><div class="msg">@oskarth @naghdy A few security things we should solve this week:
|
|
1. Did we send some ETH to that guy who reported an issue with <a href="http://status.im">http://status.im</a> DNS settings? If not, I think we should do. Not sure how much, but it wasn't anything extremely critical or customer facing.
|
|
2. Should we pre-book another audit of the app run by Deja Vu? It looks like they are usually booked 3 months in advance and I guess our goal is to do that audit before public beta.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-23 13:27</div><div class="msg">@adamb on security issues, are we making any difference between remote and local exploits? rooted and non-rooted phone?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-23 13:55</div><div class="msg">Totally. I am not exactly sure what you mean by local vs remote exploit. Remote is e.g. a malicious DApp and local is a malware installed on the phone? For rooted and non-rooted phones, we only display an notification (<a href="https://github.com/status-im/status-react/issues/4190">https://github.com/status-im/status-react/issues/4190</a>). We don't block rooted phones but we try to make sure that the user of Status is aware that the phone is rooted.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-23 13:57</div><div class="msg">a remote exploit might be something like MITM or XSS as well.. it's more about physical access to the device vs not</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-23 13:58</div><div class="msg">nice with the notification!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-23 14:02</div><div class="msg">Oh yeah, so totally. We try to address MITM by e.g. forcing all DApps to use HTTPS and also force the WebView to verify certificates (@rachel knows more about the state of work around it). Similarly with any code injection (code injection using WebViews was tested by Deja Vu; it was time-boxed so they did not tried more sophisticated stuff).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-23 14:04</div><div class="msg">yeah, I've seen all the great work done so far - this was a random thought more in the context of the bounty program and how it will be awarded</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-23 14:07</div><div class="msg">we were joking the other day that we should bring a clean phone with <a href="http://status.im">http://status.im</a> to the `CCC` and announce we're transacting, to see how many seconds we last :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-23 14:09</div><div class="msg">Oh I see. In such a case, we will probably judge it case by case. If there will be a way to have unauthorized access to Status but it will require a local exploit, I guess it's still an issue. Unless it is a bug in the OS itself which can be exploited to get access to any app</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-23 14:09</div><div class="msg">What is `CCC`?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-23 14:15</div><div class="msg">chaos computer congress.. hacker event in germany - their survival guide is amusing to read: <a href="https://events.ccc.de/congress/2017/wiki/index.php/Static:How_To_Survive">https://events.ccc.de/congress/2017/wiki/index.php/Static:How_To_Survive</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-05-23 15:56</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-05-23 15:57</div><div class="msg">Good on both points. @adamb please reach out to Deja Vu for 4 weeks in Sep/Oct.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-05-23 15:57</div><div class="msg">I'll talk to @carl about payment of ETH to the guy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-05-24 10:57</div><div class="msg">Wanted to get feedback to determine how much we should be paying to the white hat email hacker.
|
|
|
|
I'm thinking around $2k would be sufficient based on the guidelines in <a href="https://docs.google.com/document/d/1JhUGeL-qnMl8KJBLu166b4MfamDFMle4F3pe7LZSqPM/edit">https://docs.google.com/document/d/1JhUGeL-qnMl8KJBLu166b4MfamDFMle4F3pe7LZSqPM/edit</a>, but wanted to gauge with the audience here.
|
|
|
|
cc @adamb @oskarth @jakub</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-05-24 10:58</div><div class="msg">CCC is a great event, I've been to it a few times, lots of fun</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-05-24 10:58</div><div class="msg">sg</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-24 11:37</div><div class="msg">Sounds good to me.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-05-24 11:54</div><div class="msg">@carl $2k it is. Should I follow up w/ @jason ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-25 00:18</div><div class="msg">where are bountied issues tracked?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-25 08:13</div><div class="msg">anywhere yet, but it's a good idea to track them</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-25 08:13</div><div class="msg">a spreadsheet for now is good enough?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-25 08:14</div><div class="msg">(we have just one so far :D)</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/3fbb10b8c7115b8c44459363fb6476cf.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0007-72.png" /><div class="message"><div class="username">divan</div><div class="time">2018-05-25 10:37</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-05-25 10:38</div><div class="msg">@hester set the channel purpose: track B - Risks & Mitigations</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-05-25 10:39</div><div class="msg">@hester set the channel purpose: track A - Process
|
|
track B - Risks & Mitigations
|
|
<a href="https://docs.google.com/document/d/1dHPTMmeRaLi3cQQmNjxZldfOx90PihE3ltT7bphiceQ/edit#">https://docs.google.com/document/d/1dHPTMmeRaLi3cQQmNjxZldfOx90PihE3ltT7bphiceQ/edit#</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-05-25 11:19</div><div class="msg">Mission for today's risk management call is to deep dive into 3 issues. Discuss the risk more in-depth, how we are currently managing this risk and what else might help prevent and recover.
|
|
|
|
*Please vote* on the risks to discuss this week! Add a '+1' comment to the 3 risks you believe are most important.
|
|
|
|
<a href="https://docs.google.com/document/d/1dHPTMmeRaLi3cQQmNjxZldfOx90PihE3ltT7bphiceQ/edit#">https://docs.google.com/document/d/1dHPTMmeRaLi3cQQmNjxZldfOx90PihE3ltT7bphiceQ/edit#</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-05-25 12:28</div><div class="msg">We had a good one though! </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-05-25 12:29</div><div class="msg">A spreadsheet sounds good, with the severity, impact and complexity columns for us to weight. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-25 12:30</div><div class="msg">I'm more thinking about it in terms of opening up the details of the vulnerability such that others can benefit from the knowledge.. for nimbus for example, I'll be poring over the geth & parity vulnerability logs so at least we don't fall into the same traps</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-25 12:44</div><div class="msg">we keep all security issues on Github with ?security? label for both status-go and status-react so they are easy to find and browse through</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-25 13:03</div><div class="msg">yeah, but I'd imagine that we'll have a process whereby security issues can be posted in a closed way giving us time to fix them, meaning that there needs to be a follow-up to publish both the issue (and potentially fix)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-25 13:14</div><div class="msg">Of course, but I guess in such a case we will just reuse the communication means we currently utilize like our blog, right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-05-25 13:29</div><div class="msg">A list of reported security issues: <a href="https://docs.google.com/spreadsheets/d/15f3rkXK9hzgIKMrhxJw8h1hHhRMoSYNxpA2fzBBcKBU">https://docs.google.com/spreadsheets/d/15f3rkXK9hzgIKMrhxJw8h1hHhRMoSYNxpA2fzBBcKBU</a></div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-05-25 13:40</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-13/329132457109_199841cd908ca7faa97f_72.jpg" /><div class="message"><div class="username">rachel</div><div class="time">2018-06-03 14:59</div><div class="msg">@hester let me catch you up on Friday's meeting here. :slightly_smiling_face: We cruised through about 5 issues on the call and came up with a handful of new mitigation tactics. There are also 2 topics that we feel merit wider discussion. First the solutions:
|
|
|
|
`There is no reminder that the seed phrase is not backed up.`
|
|
*Solution:* Lock all features that change the state of the account (chat commands, wallet, DApps) when a user has some minimum amount of value in their wallet, and has not backed up their seed phrase.
|
|
|
|
Build in reminder notifications that you need to back up after a certain event (e.g. first transaction).
|
|
|
|
`During the launch of a DApp, there is no visible indication of a valid HTTPS certificate.`
|
|
*Solution:* Issue for improving browser security warnings and protection: <a href="https://github.com/status-im/status-react/issues/4380">https://github.com/status-im/status-react/issues/4380</a>
|
|
|
|
`Users confuse a transaction message in chat with the actual transaction (phishing).` (touched upon only lightly)
|
|
*Solution:* Whisper could send a "payment in progress" message generated from transaction history for verification.
|
|
|
|
`Spoof ERC20 tokens: same symbol, different contract.`
|
|
*Solution:* This risk is best circumvented by our own due diligence when adding tokens. We could display information about each token in the asset list. And for cases where two tokens have the same name (e.g. WETH) we could distinguish them from each other in UI.
|
|
_Long term:_ Use a token curated registry for a socially authenticated list of tokens (similar to what DApp catalog might use)
|
|
|
|
`A user makes a poor choice of a password, because it has to be typed every time.`
|
|
*Solution:* Allow users to change their password through UI; allow users to recover their password through UI (both now technically possible)
|
|
_Long term:_ Biometric identification?
|
|
|
|
*To discuss:*
|
|
- How much do we want to fool-proof the system vs. educate our users? Lost password, forgotten seed phrase, etc. are all user error. A simple start would be to create a series of YouTube videos, like Ethereum 101 for new users, in conjunction w/ marketing team.
|
|
|
|
- How will identity management look in the future? Will we support multiple wallet addresses? Multiple chat accounts? This came up in context of the chat address exposing information about a user's wallet, but also with users struggling to locate the wallet address and confusing the two.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-06 09:35</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-03-08/150717543185_46c3b78ed6fd88d4b338_72.jpg" /><div class="message"><div class="username">anna</div><div class="time">2018-06-06 09:36</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-06-07 10:20</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-06-08 04:39</div><div class="msg">Continuing this thread in #security</div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-06-08 05:01</div><div class="msg">@hester commented on @hester?s file <a href="https://status-im.slack.com/files/U8DN8BUKG/FB3RLEHR9/Chat_risk_management_Product_principles_meetup_Switzerland">https://status-im.slack.com/files/U8DN8BUKG/FB3RLEHR9/Chat_risk_management_Product_principles_meetup_Switzerland</a>: Please add CONFIRMED behind your name when you're sure you'll be there.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2016-11-16/104878545009_e6897ef62e65dc08f5b8_72.jpg" /><div class="message"><div class="username">andmironov</div><div class="time">2018-06-08 05:03</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-08 05:04</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-01-11/298391058247_5455b8ad9c31c09d2bf2_72.jpg" /><div class="message"><div class="username">dmitry.shulyak</div><div class="time">2018-06-08 05:09</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-24/320320314756_fe0f3ce0bb820f1aa8e3_72.jpg" /><div class="message"><div class="username">dmitryn</div><div class="time">2018-06-08 05:11</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/8f5d17c2210ba9813f6612330fc0fc66.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0014-72.png" /><div class="message"><div class="username">janherich</div><div class="time">2018-06-08 05:11</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-06-08 05:22</div><div class="msg"><!here> in the above post notes of our call to plan a meetup in Switzerland work towards product principles.
|
|
|
|
- Feel free to edit
|
|
- Use the doc to share with your lead what the plan is and discuss trip approval
|
|
- Add CONFIRMED after your name if you'll be there for sure on the current dates (July 4-6)
|
|
- Keep in mind that the dates and location are not confirmed so please hold off on booking until they are</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-08 13:25</div><div class="msg">@stefania above is the agenda</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-06-11 02:56</div><div class="msg">cc @naghdy</div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-06-11 12:44</div><div class="msg">@patrick771 commented on @hester?s file <a href="https://status-im.slack.com/files/U8DN8BUKG/FB3RLEHR9/Chat_risk_management_Product_principles_meetup_Switzerland">https://status-im.slack.com/files/U8DN8BUKG/FB3RLEHR9/Chat_risk_management_Product_principles_meetup_Switzerland</a>: Risk management / product principles meetup</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-13/286372975188_242bad477cd4edddb601_72.jpg" /><div class="message"><div class="username">alli</div><div class="time">2018-06-12 12:50</div><div class="msg">I met someone yesterday who asked who I was working with, and when I told him Status, he said it was a funny coincidence - that he has just met someone the day before who showed him Status. That guy was a IT security expert who was showing him how when you sign up for Status, the password you type in's letters appear very briefly before they turn to black dots, and the guy was saying that makes Status not secure - that there can be some kind of malware running in the background that takes snapshots of this process, exposing the password to a third party; that it should just be blackdots when you enter the password - without this split second of showing what the password really is. I am speaking out of my depth here and don't know if this is something completely obvious, a standard convention, or something just overlooked. In any case, wanted to share, just as an FYI.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-06-12 13:29</div><div class="msg">Briefly showing the letters in password fields is a standard practice on devices that have keyboards sensitive to "fat fingers". The reason is to give the user some feedback while they're typing (e.g. did I just tap `s` instead of `d`)</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-06-12 13:32</div><div class="msg">What that guy said is technically true, but then again if you have malware that snaps your phone screen at will and sends it away, then your security is already breached, as the same malware can gain access of other just as dangerous things that appear on screen, e.g. seed phrase, signing phrase, etc. I.e. a phone like that is already hacked beyond help.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-13/286372975188_242bad477cd4edddb601_72.jpg" /><div class="message"><div class="username">alli</div><div class="time">2018-06-12 14:13</div><div class="msg">Gotcha. Again, wasn't sure if this was an oversight or a norm, so thanks for clarifying!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-12 17:52</div><div class="msg">@hester any news so far for planning the meetup? Like its almost mid june - good time to book some flights until they are not insane pricey</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-12/285244060371_dbc007c8c7963b36a3ee_72.jpg" /><div class="message"><div class="username">hester</div><div class="time">2018-06-13 10:45</div><div class="msg">Sorry @nastya not just yet, but working on it:) I checked prices yesterday, still reasonable at this point. Thanks for your patience! cc @yenda</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-06-13 10:54</div><div class="msg">both my banking apps are doing the same</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-03-08/150717543185_46c3b78ed6fd88d4b338_72.jpg" /><div class="message"><div class="username">anna</div><div class="time">2018-06-18 08:54</div><div class="msg">@adamb fyi <a href="https://status-im.slack.com/archives/C8KB9DR60/p1529312023000171">https://status-im.slack.com/archives/C8KB9DR60/p1529312023000171</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-18 09:44</div><div class="msg">@hester re basel, are there any details of where it is etc? want to book accommodation. Or do we have some kind of plans for that already?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-18 10:13</div><div class="msg">it is not confirmed yet i guess from Finance department</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-18 10:13</div><div class="msg">Hester is vacationing btw :slightly_smiling_face: @oskarth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-18 13:01</div><div class="msg"><!here> who can advise do we want to show a warning for user when he sets up a weak password like 111111 or six spaces? There was a discussion some time ago that we dont want to restrict enetering this but maybe we want to warn user at least?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-18 14:58</div><div class="msg">Usually, there is a password strength indicator</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-18 14:58</div><div class="msg">maybe we can use that?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-18 15:00</div><div class="msg">I think we should not prevent user from using a weak password but we should display some warning like ?are you sure you want to use a weak password??</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-18 15:00</div><div class="msg">that is what i am suggesting</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-18 15:00</div><div class="msg">I think it's a good idea</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 10:06</div><div class="msg">@oskarth @nastya @pedro @rachel @adamb @dmitry.shulyak @yenda @andreap @hester @arnetheduck.slack Hi all. We have approval from finance for the security meetup but I'd like to check one more time that July 4-6 in Basel would still work for most people? We?re working on finding an event/coworking space in Basel but wanted to double check if a week later (July 11-13) would work better since the timeline is tight at this point for organizing topics and agenda.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-20 10:08</div><div class="msg">sup</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-06-20 10:10</div><div class="msg">just a shout out to the security crew?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-20 10:10</div><div class="msg">:all_the_things:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-01-10/297564958950_752f7f4865590f38fffc_72.jpg" /><div class="message"><div class="username">pedro</div><div class="time">2018-06-20 10:12</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-20 10:12</div><div class="msg">11-13 should work for me as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 10:12</div><div class="msg">Sorry, hit enter a little early.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-06-20 10:14</div><div class="msg">I have a preference for 4-6 as I am already in the area, I probably could do 11-13 but trickier</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 10:26</div><div class="msg">Ok, good to know, thanks @andreap. Anyone else?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-20 10:27</div><div class="msg">@patrick771 11-13 works for me</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-06-20 10:33</div><div class="msg">I'm on a flight to cuba on the 11'th - I'd have to check recent developments in cloning tech :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-06-20 10:34</div><div class="msg">happy to push it back to something like 8-9-10 if that helps</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-06-20 10:35</div><div class="msg">actually, scratch that, I'm flying on the 10th - meaning I can do 7-8-9 at latest</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 10:38</div><div class="msg">ah, right @arnetheduck.slack. could be just easier to keep July 4-6 then. @dmitry.shulyak Zurich is $$$</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-01-11/298391058247_5455b8ad9c31c09d2bf2_72.jpg" /><div class="message"><div class="username">dmitry.shulyak</div><div class="time">2018-06-20 10:40</div><div class="msg">i understand. i meant that there are Berlin/Warsaw/Amsterdam</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-20 10:42</div><div class="msg">Lots of people in Berlin end of this month </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-20 10:42</div><div class="msg">I think there was some reason to have it in Switzerland but forgot why </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-06-20 10:43</div><div class="msg">some of it is because some of use are in .ch already at that time, and family constraints make it harder to move around</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 10:44</div><div class="msg">We also did a cost comparison and Basel came out on the cheaper end: <a href="https://docs.google.com/spreadsheets/d/1_kitoRIgtQZfORyv_xddRPWxypRnyilWJG7z9qV1MHM/edit#gid=0">https://docs.google.com/spreadsheets/d/1_kitoRIgtQZfORyv_xddRPWxypRnyilWJG7z9qV1MHM/edit#gid=0</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 10:53</div><div class="msg">Thanks all for the quick feedback. Let?s keep the 4-6th of July and we?ll communicate which coworking space we?ll use asap.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-20 10:57</div><div class="msg">does it mean i can buy a flight / accomodation? Which service we use now (since yondo is closed)?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:23</div><div class="msg">we have an estimate for flight and accommodations cost in column C in the spreadsheet above</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-20 11:24</div><div class="msg">180 EUR for flight okay its not doable for me</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:25</div><div class="msg">scratch that 250-500 EUR for return flights in Europe</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:26</div><div class="msg">quote from Stef</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:28</div><div class="msg">I believe these flight estimates are from more central locations in europe.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-20 11:33</div><div class="msg">i will double check with Stef . and accomodation is ? sorry can't understand)</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-06-20 11:34</div><div class="msg">So morning 4th to evening 6th confirmed?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:34</div><div class="msg">Yes</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-06-20 11:34</div><div class="msg">I'm going to book the Berlin-Basel night train</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:36</div><div class="msg">:bullettrain_side:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:39</div><div class="msg">@nastya between 215 - 360 EUR</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-20 11:40</div><div class="msg">gotcha. gonna book something from 3 (arrival day) till 6 (have to leave on 6th)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:41</div><div class="msg">great, we're working on the location for the meet up. will let you know asap.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-20 11:41</div><div class="msg">:all_the_things:</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-06-20 11:44</div><div class="msg">So I can book already before the price increases again ?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-06-20 11:44</div><div class="msg">It's 208? by train from Berlin</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:45</div><div class="msg">yes, recommend that folks go ahead and book flights/trains asap.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-20 11:46</div><div class="msg">and we're looking for a space in central Basel to meet so if you want to book accommodations near city center you can as Basel is not a big place + good transportation connections</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-06-20 12:11</div><div class="msg">Ok I took my 10h ride :D</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 06:45</div><div class="msg">Hey @oskarth @naghdy @andreaf @carl. There was some miscommunication I guess. I already booked a second audit with Deja vu Security a few weeks ago. It is scheduled for late September/early October. There is an initial scoping call with their engineer (the same one that worked with us previously) today at 5pm CET. Please let me know if anyone want to join.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-06-21 07:26</div><div class="msg">Ah ok no worries. The only thing I'd add is that we would like to add E2E messaging encryption to the audit.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 11:50</div><div class="msg">@patrick771 maybe it is reasonable to book a meeting room in a hotel? I booked some and they offer a conference room , assuming there is not a very huge amount of people maybe it could be considered as an option? Not sure about the prices though</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-21 11:57</div><div class="msg">@nastya where did you book your hotel? Rajanie just made the exact point this morning that hidden costs (e.g. clean up fees) to a coworking space often end up make them equivalent to a hotel conference room or business center.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 11:58</div><div class="msg">it is Metropol <a href="https://www.booking.com/s/17_6/674fe1e5">https://www.booking.com/s/17_6/674fe1e5</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 11:58</div><div class="msg">near the railway station i guess. Economy room seems fits our budet!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 11:59</div><div class="msg">like 400 USD for 3 nights i paid</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 11:59</div><div class="msg">seems okay</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-21 12:03</div><div class="msg">not sure they actually have conference room. they do have a business center but that's a different thing. I think it's the right idea just to find a conference rooms in a hotel.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 12:04</div><div class="msg">ah okay sorry for confusion! I just read the overview and it is stated the lounge could be used for conferences. But maybe we can do another hotel for sure!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:06</div><div class="msg">I just realized the timing with devcon isn't ideal </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:06</div><div class="msg">I assume that's the earliest they can do?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:10</div><div class="msg">Devcon is Oct 30, so why it's not ideal?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:11</div><div class="msg">I will ask. Maybe early September will be possible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:11</div><div class="msg">do you think that's enough time for them to do an audit, us fix problems and then public release?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:11</div><div class="msg">(For example)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:12</div><div class="msg">they should definitely finish that before that, especially that the scope does not seem huge</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:12</div><div class="msg">if they find issues and they won't require some architectural changes then I think we should be good</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:13</div><div class="msg">do we want to announce 1.0 at Devcon?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:13</div><div class="msg">what?s the plan?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:13</div><div class="msg">It?s not 100% clear right now I think, people have different views </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:13</div><div class="msg">Security seems like pre requisite though </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:14</div><div class="msg">Do you think they would be open to helping us find someone to semi replace them? :D or if they have thoughts on what a good test for security engineers is</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:15</div><div class="msg">weeeeell :smile: I am not sure because it seems like we would like to find someone who can replace them</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:16</div><div class="msg">to complement them ;)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:16</div><div class="msg">that's your point of view, not theirs :stuck_out_tongue:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:16</div><div class="msg">Yeah I know </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:16</div><div class="msg">If it seems appropriate and relaxed atmosphere it might be worth picking their brain on this casually </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:16</div><div class="msg">Cause some feedback from candidate was that it wasn't a good test </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:17</div><div class="msg">what did we end up with?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:17</div><div class="msg">if not np</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:17</div><div class="msg">pinged you in other thread </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:18</div><div class="msg">I might check with candidate as well on this </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:19</div><div class="msg">each point requires substantial effort so that might be a reason</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:20</div><div class="msg">agree</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:22</div><div class="msg">How many calls have we had already with candidates for that position?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:24</div><div class="msg">not many </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:24</div><div class="msg">do you want me to be on the call as well or all good?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:24</div><div class="msg">up to you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:25</div><div class="msg">it's at 5pm</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:26</div><div class="msg">But if you know about scope for the second audit from status-react perspective, your presence would be useful</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:26</div><div class="msg">Kk I'll skip this one then</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:26</div><div class="msg">I know that messaging is a priority because it was skipped previously</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:26</div><div class="msg">I think scope is what has been said above </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:26</div><div class="msg">Plus uncertainty</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:26</div><div class="msg">Ie double ratchets or whatever, depends on outcome of OKRs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:27</div><div class="msg">but e2e safe bet, can do PFS later / with internal </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:27</div><div class="msg">what?s pfs?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:27</div><div class="msg">perfect forward secrecy </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:28</div><div class="msg">oh wow :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:28</div><div class="msg">there are some topics in Discuss related to this but no decision yet </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:28</div><div class="msg">will be brought up at secure messaging meet up and hopefully come out of OKR process</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-06-21 12:28</div><div class="msg">ok, I will communicate</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:29</div><div class="msg">dark routing seems unlikely we?ll guarantee </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:29</div><div class="msg">Cool</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-06-21 12:29</div><div class="msg">as in it is mostly aspirational now and would be huge effort to ?verify?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-21 12:37</div><div class="msg">Anyone else besides @nastya booked their hotel? if not, please hold up for a minute to see if we can get a group booking at a hotel</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-21 12:39</div><div class="msg">if you have, keep it if there is no free cancelation policy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 12:40</div><div class="msg">:disappointed:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 12:40</div><div class="msg">u still can try Metropol! :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-21 12:41</div><div class="msg">yeah, giving them a call</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-06-21 13:26</div><div class="msg">I think I want to join too :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-06-21 13:26</div><div class="msg">it would be awesome)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-06-21 13:34</div><div class="msg">and if there are any security meetings, probably also )</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-21 14:24</div><div class="msg">Ok, @igor680 we?ve added you to the list. Can this group confirm that there is no one else we should check with. Here is the current list: <a href="https://docs.google.com/spreadsheets/d/1_kitoRIgtQZfORyv_xddRPWxypRnyilWJG7z9qV1MHM/edit#gid=1599681121">https://docs.google.com/spreadsheets/d/1_kitoRIgtQZfORyv_xddRPWxypRnyilWJG7z9qV1MHM/edit#gid=1599681121</a></div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-06-22 12:43</div><div class="msg">@patrick771 commented on @hester?s file <a href="https://status-im.slack.com/files/U8DN8BUKG/FB3RLEHR9/Chat_risk_management_Product_principles_meetup_Switzerland">https://status-im.slack.com/files/U8DN8BUKG/FB3RLEHR9/Chat_risk_management_Product_principles_meetup_Switzerland</a>: Current agenda for the security meetup.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-06-22 16:12</div><div class="msg">To follow up here since folks are asking about where to stay. @rajanie is helping us find a hotel + conference room in Basel all-in-one so we can get a decent price on a room block. Please hold up on booking rooms for the time being if possible as we're still waiting to hear from possible hotels.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-06-24 09:09</div><div class="msg">whitepaper on wire E2E encryption, and how their protocol works - priceless: <a href="https://wire-docs.wire.com/download/Wire+Security+Whitepaper.pdf">https://wire-docs.wire.com/download/Wire+Security+Whitepaper.pdf</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-06-28 06:21</div><div class="msg">We have two security reports:
|
|
```
|
|
|
|
I find Clickjacking vulnerability in your sites:
|
|
|
|
1.<a href="https://status.im/">https://status.im/</a>
|
|
2.<a href="https://hardwallet.status.im/">https://hardwallet.status.im/</a>
|
|
3.<a href="https://chat.status.im/">https://chat.status.im/</a>
|
|
4.<a href="https://wiki.status.im/">https://wiki.status.im/</a>
|
|
5.<a href="https://embark.status.im/">https://embark.status.im/</a>
|
|
6.<a href="https://docs.status.im/">https://docs.status.im/</a>
|
|
7.<a href="https://ideas.status.im/">https://ideas.status.im/</a>
|
|
8.<a href="https://contribute.status.im/">https://contribute.status.im/</a>
|
|
|
|
|
|
Poc : jut go to <a href="https://www.lookout.net/test/clickjack.html">https://www.lookout.net/test/clickjack.html</a> and test the link.
|
|
|
|
Reference : <a href="https://www.owasp.org/index.php/Clickjacking">https://www.owasp.org/index.php/Clickjacking</a>
|
|
<a href="https://en.wikipedia.org/wiki/Clickjacking">https://en.wikipedia.org/wiki/Clickjacking</a>
|
|
Best,
|
|
Nessim Jerbi
|
|
```</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-06-28 06:21</div><div class="msg">and</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-06-28 06:21</div><div class="msg">```Hello, I would like a security report regarding two publicly exposed internal server monitoring tools. Their accessibility does not seem to introduce any opportunity to exploit other network resources, but it does offer some information about the system which should not be externally available. Per the posted bug bounty metrics, I would classify this as Low severity. My findings are below, I kindly request a reply to confirm you have received this message.
|
|
|
|
Scope:
|
|
NetData web dashboard -- <a href="http://174.138.2.54:8000">http://174.138.2.54:8000</a>
|
|
Prometheus AlertManager WebUI --<a href="http://alerts.status.im">http://alerts.status.im</a> (174.138.2.54)
|
|
|
|
Reproduction:
|
|
Access the resources at the above listed URLs. Note: connecting to the AlertManager port using https://* will present the GitHub OAuth2 proxy login, as intended.
|
|
|
|
Risk Assessment:
|
|
This is not a critical vulnerability, however the exposure of these internal resources presents a potential attacker with some data which may be of use.
|
|
|
|
The exposure of AlertManager could allow an attacker to view, silence, and create alerts. From what I can tell, the functionality does not seem to be used, but the page itself is still exposed.
|
|
|
|
The NetData interface presents a larger amount of risk, as it exposes information on system services, users, user groups, disks, network interfaces, system performance, and applications.
|
|
|
|
Quoting from the NetData documentation, emphasis theirs (<a href="https://github.com/firehol/netdata/wiki/netdata-security">https://github.com/firehol/netdata/wiki/netdata-security</a>):
|
|
"netdata is a monitoring system. It should be protected, the same way you protect all your admin apps. We assume netdata will be installed privately, for your eyes only.
|
|
...
|
|
This information is not sensitive (meaning that it is not your business data), but it is important for possible attackers. ..."
|
|
|
|
Fix:
|
|
Update Nginix server configuration to redirect incoming http requests on 174.138.2.54:8000 to port 443, where users will login through the GitHub single sign-on. Disable AlertManager if unused, otherwise implement access control to allow only internal IPs to access the web UI.```</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-06-28 06:22</div><div class="msg">cc @jakub and @jasonniemczyk</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-26/387862472096_348f0e952994588e03ca_72.jpg" /><div class="message"><div class="username">jasonniemczyk</div><div class="time">2018-06-28 06:22</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-06-29 17:14</div><div class="msg">The whole book is awesome, but this chapter is also an awesome read for everyone here:
|
|
<a href="http://www.cl.cam.ac.uk/%7Erja14/Papers/SEv2-c25.pdf">http://www.cl.cam.ac.uk/%7Erja14/Papers/SEv2-c25.pdf</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-06-29 17:14</div><div class="msg">The book: <a href="http://www.cl.cam.ac.uk/%7Erja14/book.html">http://www.cl.cam.ac.uk/%7Erja14/book.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-01 13:24</div><div class="msg">ping on this. cc @oskarth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 08:19</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 08:19</div><div class="msg">@jakub thoughts on above?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 08:20</div><div class="msg">oh, yeah, let me check that out now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 08:20</div><div class="msg">cheers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 08:21</div><div class="msg">Yeah, those are good finds, I even have in my todo to add some basic auth for netdata, and use oauth2 for alerts(though I'll have to move it to separate hosts probably)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 08:22</div><div class="msg">so yeah, these are well spotted</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-02 09:06</div><div class="msg">Ok cool. Any thoughts on payouts? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 09:07</div><div class="msg">no idea, never dealt with this kind of thing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:07</div><div class="msg"><a href="https://gist.github.com/adambabik/7e1c9148610a64fbeb953eaf1b742456">https://gist.github.com/adambabik/7e1c9148610a64fbeb953eaf1b742456</a> i.e. the two dimensions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:07</div><div class="msg">impact: low/medium/high? and likelihood: low/medium/high?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 09:08</div><div class="msg">likelihood of what? being exploited?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:09</div><div class="msg">yeah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 09:09</div><div class="msg">I guess medium likelihood and low impact? netdata is just host metrics, you can kinda get an idea of what processes are running on our hosts but that's about it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 09:09</div><div class="msg">alerts one is just that, someone could see what alerts were on, not much harm in that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:09</div><div class="msg">IMO: Low impact medium likelihood => low severity (his words as well)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:09</div><div class="msg">yeah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:10</div><div class="msg">I didn't refresh slack messages before I hit enter, pinky swear</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 09:10</div><div class="msg">=]</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:10</div><div class="msg">> Low threats = up to $2,000 worth of ETH or SNT</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-02 09:11</div><div class="msg"> Ok. We can pay out both $1k? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:11</div><div class="msg">sg</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:11</div><div class="msg">strictly speaking it is out of scope of our bug bounty program</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:12</div><div class="msg">but it's not a great idea to play that game, lots of devs/community get pissed if you play the scope card for bug bounties for real issues</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 09:12</div><div class="msg">right</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:13</div><div class="msg">do we have a flow setup for payouts?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-02 09:13</div><div class="msg">truth be told I wouldn't consider those issues, since I did leave them be consciously, as to be done later, but you should reward people for taking the effort to find these</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 09:21</div><div class="msg">Might be worth cross checking our audit(s) with the questions asked here: <a href="https://uploads-ssl.webflow.com/5a88babea6e0f90001b39b0d/5a8bf07cd906b1000190b6a7_trust-wallet-exec-checklist.pdf">https://uploads-ssl.webflow.com/5a88babea6e0f90001b39b0d/5a8bf07cd906b1000190b6a7_trust-wallet-exec-checklist.pdf</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-02 12:30</div><div class="msg">Key points that was discussed during the audit:
|
|
- we do display a jailbreak info when starting the app for the first time. Do we do that before each restart??
|
|
- do we check HTTPS certs when opening DApps and using external APIs? I believe we agreed to do so for HTTPS cert check for DApps, I am not sure how it looks like for API calls,
|
|
- we do not perform memory zeroing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-02 14:20</div><div class="msg">Regarding threat modeling, there is a podcast with the author of _the book_ (cc @arnetheduck.slack): <a href="https://overcast.fm/+B1A1gMYbA">https://overcast.fm/+B1A1gMYbA</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-02 16:23</div><div class="msg">nice, that is indeed _the book_ from what I've found as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-03 09:10</div><div class="msg">Done. Both of them will be paid out. Thanks folks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-07-03 09:10</div><div class="msg">cheers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-01-10/297564958950_752f7f4865590f38fffc_72.jpg" /><div class="message"><div class="username">pedro</div><div class="time">2018-07-04 06:37</div><div class="msg">_added :-)_</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-07 16:29</div><div class="msg">I was just invited to the secureth effort (<a href="https://secureth.org/">https://secureth.org/</a>) - ping me if this sounds interesting (@adamb @igor680) - there's a security professionals meeting in berlin around the time of ETHberlin that would be interesting as a hiring venue (@carl, @jarradhope, @baofranca) and to connect with some of the infosec community as well - at least the subset that is explicitly interested in eth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-07 21:28</div><div class="msg">One idea I just thought about is re: Bug Bounty:
|
|
|
|
We should put ~2-5M SNT into a Status account, and ask the community to go attack (similar to <a href="https://medium.com/melonport-blog/melon-live-bug-bounty-2-acac69b4ac3e">https://medium.com/melonport-blog/melon-live-bug-bounty-2-acac69b4ac3e</a>). Any thoughts on the best way to practically implement this?
|
|
|
|
I'm slightly disappointed that we haven't attracted any proper attackers. By getting creative, and increase the $ on the table, maybe that will change.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-07-10 12:43</div><div class="msg">Is this channel public on Riot ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-10 13:01</div><div class="msg">Don?t think so </div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-07-10 13:06</div><div class="msg">Because to take care of the risk `15. - Spamming the network (our cluster) (related to 30)` in <a href="https://docs.google.com/spreadsheets/d/1o_sJKluskrlyNxAfDH_brqkFBsVWFFLLAdu8sUFEDdM/edit#gid=45783428">https://docs.google.com/spreadsheets/d/1o_sJKluskrlyNxAfDH_brqkFBsVWFFLLAdu8sUFEDdM/edit#gid=45783428</a> we decided in core-chat to write a program that spams the network so we can measure the problem</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-07-10 13:07</div><div class="msg">but talking about it publicly and publishing it before the problem is solve doesn't seem to be a good idea as nobody is at risk but some script kiddies could definitely use it against us if we made it public</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-12 08:09</div><div class="msg">@hutch can you please let me know if its linked</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-12 18:15</div><div class="msg">Node dependencies :( <a href="https://github.com/eslint/eslint-scope/issues/39">https://github.com/eslint/eslint-scope/issues/39</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-15 20:50</div><div class="msg">We have another vuln that a person who has already received $1k for the previous vulnerability of Clickjacking.
|
|
|
|
The find is:
|
|
```Another report:
|
|
i find a text injection can be used in phishing 404 page should not include attacker text !
|
|
Description :
|
|
This report is about how an attacker is able to spoof the content of 404 page and can add thr own Text in way that the Current Website is moved to someone new URL which is Attackers website , yet its not that much effective to make this attacker successful but still this need to fix .
|
|
|
|
Vulnerable URL : <a href="https://chat.status.im">https://chat.status.im</a>
|
|
POC URL: <a href="https://chat.status.im/%20https://chat.status.im%20has%20been%20changed%20to%20http://ATTACKER.com%20so%20please%20visit%20it%20or%20contact%20the%20support%20on%20this%20email:%20hacker@gmail.com%20,%20and%20about%20Status%20service%20">https://chat.status.im/%20https://chat.status.im%20has%20been%20changed%20to%20http://ATTACKER.com%20so%20please%20visit%20it%20or%20contact%20the%20support%20on%20this%20email:%20hacker@gmail.com%20,%20and%20about%20Status%20service%20</a>
|
|
Reference : <a href="https://www.owasp.org/index.php/Content_Spoofing">https://www.owasp.org/index.php/Content_Spoofing</a>
|
|
POC : <a href="https://i.imgur.com/DMdc42u.png">https://i.imgur.com/DMdc42u.png</a>
|
|
Mediation :
|
|
User Predefined 404 page , with fixed error content !
|
|
Please let me know if any more info needed !
|
|
|
|
Regard's
|
|
|
|
NESSIM JERBI```</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-15 20:50</div><div class="msg">Thoughts?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-16 16:15</div><div class="msg">It seems like an Apache server issue. He modified the URL which path fragment is put into the Apache standard 404 template. The solution, as described, should be a custom 404 page that does not inject URL?s path fragment.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-16 16:20</div><div class="msg">It would be much more dangerous if the content of <a href="https://chat.status.im/">https://chat.status.im/</a> could be spoofed but it's not a case.
|
|
|
|
Super low IMO because in theory someone could distribute a spoofed URL inside Riot and after clicking on it, the page would display a text like ?your Riot account got blocked, please email <mailto:support@atacker.com|support@atacker.com> with your username and password? or something like that while still see `<a href="https://chat.status.im">https://chat.status.im</a>`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-12/240066984213_b35ca6f6b9658bf5cabb_72.jpg" /><div class="message"><div class="username">jonny.z</div><div class="time">2018-07-17 02:47</div><div class="msg">@oskarth @naghdy Robbie (formerly of Truebit :robbie:) sent Jacek and I an email about a security group he has started and asked if we would like to participate. With Jacek out on holiday, who is best to take point on this? ```We've made some major progress with the security community setup over the past 6 weeks and now have representation from the majority of the ecosystem. Our first goal is the invite only security unconference at ETHBerlin. If you'd like to speak or propose a topic to cover at the event -- please post details here by Friday, July 20th. We will have a community call to finalize agenda on Friday July 27th. (also looking forward to your interview Jacek!).
|
|
|
|
In addition to the event:
|
|
The group has set up a Discourse to house community discussions <a href="https://discourse.secureth.org/">https://discourse.secureth.org/</a>. We will add relevant items from the telegram chat, but please feel free to post / respond / share.
|
|
Bi-weekly community calls will begin this Friday 7/13 at 10am PST (1pm Est, 7pm CEST). The idea of these calls is to increase discussion on community topics and allow teams to demo tools + processes.
|
|
Role call for the group and interview transcripts are here```</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-17 07:30</div><div class="msg">cc @cologic @adamb . Jacek mentioned this in Berlin, so I think he wants to be involved as well :robbie:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-13/329132457109_199841cd908ca7faa97f_72.jpg" /><div class="message"><div class="username">rachel</div><div class="time">2018-07-17 08:02</div><div class="msg">@naghdy I've started to add descriptions to the wall of shame based on Jarrad's comments: <a href="https://docs.google.com/spreadsheets/d/1o_sJKluskrlyNxAfDH_brqkFBsVWFFLLAdu8sUFEDdM/edit#gid=45783428">https://docs.google.com/spreadsheets/d/1o_sJKluskrlyNxAfDH_brqkFBsVWFFLLAdu8sUFEDdM/edit#gid=45783428</a>
|
|
|
|
@igor680 or @adamb perhaps you could help edit me and fill out the rest? The goal is to provide accessible explanations for the full wall of shame, so that anyone can understand the risks.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-17 08:03</div><div class="msg">This is great. Happy for this to live as a spreadsheet, doc, HackMD, whatever - just as long as anyone can help maintain it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-17 08:14</div><div class="msg">yeah, and I think he mentioned it here too: <a href="https://status-im.slack.com/archives/CA7AX3CKF/p1530980961000038">https://status-im.slack.com/archives/CA7AX3CKF/p1530980961000038</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-07-17 18:47</div><div class="msg"><a href="https://twitter.com/0xuid/status/1019286573375021056?s=12">https://twitter.com/0xuid/status/1019286573375021056?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-18 13:04</div><div class="msg">Just discovered this: <a href="https://docs.npmjs.com/getting-started/running-a-security-audit">https://docs.npmjs.com/getting-started/running-a-security-audit</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-23 07:56</div><div class="msg">We received an email from Github:
|
|
> status-im/open-bounty
|
|
> Known high severity security vulnerability detected in mime < 1.4.1 defined in package-lock.json.
|
|
> package-lock.json update suggested: mime ~> 1.4.1.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-24 11:58</div><div class="msg">Hey @oskarth @naghdy. Yesterday, I forwarded you an email form Deja Vu with what they came up with regarding the second audit. However, after the Basel meetup and OKRs for Q3, it looks like we don't need it at all, especially, as the audit was supposed to cover messaging protocol which is being rewritten. What are your thoughts?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-24 12:05</div><div class="msg">The other thing to consider is that launching 1.0 has basically been dropped</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-24 12:08</div><div class="msg">(moved to a thread) so we will release it when we release it? or we will release but won't call it 1.0?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-24 12:14</div><div class="msg">Hm, I don't know right now. It's a fair question.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-24 12:14</div><div class="msg">^ @andreap do you have any thoughts on this?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-24 12:15</div><div class="msg">I would wait until we implement x3dh and double ratchet, otherwise I don't really see much value in it, as we know currently what the shortcomings of the current protocol in terms of security are</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-24 12:15</div><div class="msg">roughly how long would you estimate this will take?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-24 12:17</div><div class="msg">we estimated it to a month to implement x3dh and double ratchet and get it working, for sure no less than that i'd say, but take it with a pinch of salt</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-24 12:17</div><div class="msg">the audit is scheduled to start in two months IIRC</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-24 12:18</div><div class="msg">two months and we send a commit hash or they need the commit hash before those two months?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-24 12:18</div><div class="msg">@adamb? I believe commit hash in 2m but scope decided beforehand, could be wrong</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-24 12:25</div><div class="msg">the former. we will release it when we release it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-24 12:45</div><div class="msg">Scope is decided early but I also provided them the links to modules and packages. Now, if we add x3dh and double-ratchet implementation, that might disrupt their plan</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-24 12:46</div><div class="msg">still, even if they audit it and we will move the protocol to status-go, that audit will be useless</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-24 12:52</div><div class="msg">Gotcha, thanks!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-24 13:05</div><div class="msg">@andreap does this estimate include rewrite to go? considering we have double ratchet lib in go</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-24 13:08</div><div class="msg">so, we will be using `go` from the get-go, we won't be coding anything in status-react in terms of x3dh/dr. New parts will be all be in `go` with new endpoints (`sendpublicmessage` etc). What is not included is moving all the state management in `status-go`, as that's not necessary for the implementation and currently we don't have a solution for encryption at the database level in `status-go`, so those two are nice to haves but have less priority then getting the thing working</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-24 15:10</div><div class="msg">> state management in `status-go`, as that's not necessary for the implementation
|
|
I thought our protocol was stateful wrt keys etc? or what do you mean?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-24 15:14</div><div class="msg">I understand it this way that storing keys and all other things will be kept in `status-react` for now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-24 15:15</div><div class="msg">And that's correct, messaging protocol was stateful and will continue being so</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:00</div><div class="msg">?Fixing mobile AppSec? presentation
|
|
|
|
<a href="https://www.dropbox.com/s/wk99vmikx5s3clf/CRESTCon%20-%20Fixing%20Mobile%20AppSec.pdf?dl=0">https://www.dropbox.com/s/wk99vmikx5s3clf/CRESTCon%20-%20Fixing%20Mobile%20AppSec.pdf?dl=0</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-25 11:05</div><div class="msg">@igor680 Haven't got around to chatting with your contact yet. It also looks like we are close to closing a great FTE security person. That said, do you have any thoughts on how we can start to push for security champions etc? Is this something you would be interested in driving? What can I do to help? Happy to talk more in private / on a call if you prefer.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:05</div><div class="msg">I've already started with #core-dapps and #core-wallet as a pilot :)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-25 11:06</div><div class="msg">Ohh awesome! Missed this :slightly_smiling_face: Where can I read more?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:06</div><div class="msg">We had a kick-off meeting today with @goranjovic and @andrey </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:06</div><div class="msg">Let me show you...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:07</div><div class="msg">@oskarth here is a hidden section of the docs: <a href="https://docs.status.im/docs/security_experiment.html">https://docs.status.im/docs/security_experiment.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:08</div><div class="msg">Just follow he links from there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-25 11:10</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:10</div><div class="msg">Security experiment docs (so they are here too): <a href="https://docs.status.im/docs/security_experiment.html">https://docs.status.im/docs/security_experiment.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-25 11:12</div><div class="msg">cool! what do you think about submitting it as an idea? considering it is essentially a project with people, expected results, etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-25 11:18</div><div class="msg">The scope analysis from Deja Vu for the second audit.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-25 11:24</div><div class="msg">@adamb can we do same time tomorrow instead?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-25 11:24</div><div class="msg">Yeah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-25 11:25</div><div class="msg">let me check how it looks like with other people</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-25 11:25</div><div class="msg">looks good</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-25 11:25</div><div class="msg">great, cheers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-25 11:26</div><div class="msg">changed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:51</div><div class="msg">Yeah, I can add it to ideas, sure. Will do today prob Friday.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-25 11:56</div><div class="msg">Ah, I?m away tomorrow... what time is that? I might be able to join anyway</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-25 12:33</div><div class="msg">@igor680 3:15pm</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-25 15:47</div><div class="msg">@adamb could you add @andreap as well to this call please?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-07-25 15:56</div><div class="msg">there's a lot of great information in this new report that just came out of Berkeley</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-25 19:35</div><div class="msg">invited</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-25 19:39</div><div class="msg">thanks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-26 13:08</div><div class="msg">> 4.7. Server trust
|
|
> A malicious server could cause communication between Alice and Bob to fail
|
|
> (e.g. by refusing to deliver messages).
|
|
> If Alice and Bob authenticate each other as in Section 4.1, then the only additional
|
|
> attack available to the server is to refuse to hand out one-time prekeys, causing
|
|
> forward secrecy for SK to depend on the signed prekey?s lifetime (as analyzed in
|
|
> the previous section).
|
|
> This reduction in initial forward secrecy could also happen if one party maliciously
|
|
> drains another party?s one-time prekeys, so the server should attempt to prevent
|
|
> this, e.g. with rate limits on fetching prekey bundles.
|
|
|
|
So essentially it's a form of censorship attack that can potentially lead to weakened guarantees if UX is put at a premium, if I understand it correctly <a href="https://signal.org/docs/specifications/x3dh/x3dh.pdf">https://signal.org/docs/specifications/x3dh/x3dh.pdf</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-26 14:12</div><div class="msg">Proposed reply to Deja Vu today:
|
|
|
|
> Hi Andrew,
|
|
>
|
|
> Thank you for the Description of Services proposal and cost analysis.
|
|
>
|
|
> We are still analysing the documents. There were some new developments regarding our messaging protocol and Q3 priorities that we need to take into consideration as well.
|
|
>
|
|
> We will do our best to provide you the final answer in the beginning of the next week.
|
|
|
|
@oskarth @naghdy please let me know if that sounds ok. I will cc you both.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-26 22:49</div><div class="msg"><a href="https://www.passbolt.com/">https://www.passbolt.com/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-26 22:51</div><div class="msg">We have a repository for keeping some passwords related to our infra. This can be something more general if we?d like to get rid of LastPass (I don't like it because of the poor UX; not sure if passbolt is better on that field but it's an alternative).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-07-30 07:11</div><div class="msg">:thinking_face:
|
|
|
|
<a href="https://twitter.com/gcpcloud/status/1023723352811352064?s=12">https://twitter.com/gcpcloud/status/1023723352811352064?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-30 07:15</div><div class="msg">lots of pretty cool stuff there. But the name of the article...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:49</div><div class="msg">@andreap @adamb can we continue the discussion here so that the channel is not public and visible in riot while we test that possible security issue?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:50</div><div class="msg">@andreap I think it works</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 12:50</div><div class="msg">oh oh</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:50</div><div class="msg">I tried with my public key and a dapp can get the private key</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 12:51</div><div class="msg">why do we need that patch?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:51</div><div class="msg">I can try to publish it somewhere so that we can try it together without publish it to everyone of course</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 12:51</div><div class="msg">does anyone know?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:51</div><div class="msg">I don't know when it was created and needed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 12:52</div><div class="msg">I also don't know. It?s been around for long time, definitely before I joined </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 12:52</div><div class="msg">But I don't see how it is useful </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:55</div><div class="msg">ok so from my test, if the dapp knows your whisper chat identity (public key), it can retrieve your private key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 12:55</div><div class="msg">@andreaf can you provide some background or a link to the previous discussions?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 12:55</div><div class="msg"><a href="https://status-im.slack.com/archives/C8QP8S5UH/p1532946592000267">https://status-im.slack.com/archives/C8QP8S5UH/p1532946592000267</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:56</div><div class="msg">@igor680 yes. I was reviewing a PR and noticed we can call `whisper.GetPrivateKey` passing a public key instead of an `ID`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 12:56</div><div class="msg">oh, we didn't fix it yet?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 12:56</div><div class="msg">the exposure of the `ssh` APIs?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 12:56</div><div class="msg">I mean, I was thinking they are only available in the private API endpoint</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 12:57</div><div class="msg">It did not work I guess and was reverted </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:58</div><div class="msg">well that's a thing, but in general shh doesn't expose the private key without knowing the ID of that key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 12:58</div><div class="msg">Does DApp know the public key? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:58</div><div class="msg">but in our case, the ID is not needed and we can just use the public key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:58</div><div class="msg">can you guys try an example just to see if it works for you as well please?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 12:58</div><div class="msg">removing the patch seems to be the safest, I can't see why it is needed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 12:59</div><div class="msg">I also don't see any reason for that</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 12:59</div><div class="msg">(we'll have to change status-react as well though)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 12:59</div><div class="msg">which patch?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 12:59</div><div class="msg"><a href="https://github.com/status-im/status-go/blob/7577296b3c3cb0ed6464fa57568b861594f9c97f/_assets/patches/geth/0014-whisperv6-notifications.patch#L31">https://github.com/status-im/status-go/blob/7577296b3c3cb0ed6464fa57568b861594f9c97f/_assets/patches/geth/0014-whisperv6-notifications.patch#L31</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 12:59</div><div class="msg">`0014-whisperv6-notifications.patch`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:00</div><div class="msg">I would shoot for a hot fix release. @igor680 what you think?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 13:00</div><div class="msg">a part from removing shh from the APIs, I would change that part of the code and try to understand why we need it if we need it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 13:01</div><div class="msg">cause the problem in general is that and not shh</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:01</div><div class="msg">we need `SelectedKeyPairID` for deduplication, so it needs to be in another patch then</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 13:01</div><div class="msg">ah ok so you need a way to select the key from a public key?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:02</div><div class="msg">nope, I need to know an id of the selected account</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:02</div><div class="msg">just to be able to distinguish between accounts</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:03</div><div class="msg">```
|
|
+// SelectedKeyPairID returns the id of currently selected key pair.
|
|
+// It helps distinguish between different users w/o exposing the user identity itself.
|
|
```</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 13:04</div><div class="msg">we can still have reverse lookup if needed, or it can be seeded with the pk, as long as it's not overriding getprivatekey</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:05</div><div class="msg">hmm, the deterministic IDs were there to keep the whisper identities the same between launches, if I'm not wrong</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:05</div><div class="msg">but it is pretty wrong that we expose `GetPrivateKey` at all :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:07</div><div class="msg">We expose all shh stuff</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 13:07</div><div class="msg">> hmm, the deterministic IDs were there to keep the whisper identities the same between launches
|
|
I think we can achieve that without the patch (you restore the private key as of now, return the pk + the id, you send the id in instead of the pk when talking to geth)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 13:07</div><div class="msg">dapp can get pubkey with new API, will be in next release</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:07</div><div class="msg">so, we don't have that exposed in the current release, right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:08</div><div class="msg">@andrey so it's not release yet. That?s good at least. Thanks!</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 13:08</div><div class="msg">knowing the pk a dapp can still access it though?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:08</div><div class="msg">Yes but it needs to know the public key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:08</div><div class="msg">So it can guess? </div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 13:09</div><div class="msg">or phish</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:09</div><div class="msg">Have a list of Status public keys and brute force it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:09</div><div class="msg">Yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 13:09</div><div class="msg">> Yes but it needs to know the public key
|
|
|
|
but the public key is your public whisper contact right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:10</div><div class="msg">Hm. It looks like removing determinism might be tricky. Should we work towards removing shh from DApps then first?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:10</div><div class="msg">my proposal would be to remove `shh` and `shhext` from being exported, and then figure out the patch's situation
|
|
|
|
for me it will have less suprises</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:10</div><div class="msg">@andreaf correct but Dapp can't easily connect these facts, I guess.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:10</div><div class="msg">we might break some DApps, but our app can use the private endpoint that won't be changed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:11</div><div class="msg">We can work on removing that determinism later.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 13:12</div><div class="msg">@adamb yes they can't get the current whisper identity, but in general we publish our identities to be contacted</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 13:14</div><div class="msg">I think the fact that we allow dapps to get access to the private key given the public key is already reaching the highest level of security impact, the fact that they need to know the pk is not really a mitigation, so @igor680 plan sounds like the best next move</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:14</div><div class="msg">we can always whitelist the subset of `shh` if we need to have some of these methods (the same way as 2 methods from `personal_` namespace are exposed)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:15</div><div class="msg">@andreaf correct. So as @andreap said, phishing is the easiest way but there is no direct way to connect a Dapp session with a public key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:16</div><div class="msg">ook, so
|
|
let's revert the revert both on `develop` and cherry-pick it to the status-go release (because it doesn't break the API compat) and get it out to testing asap.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:16</div><div class="msg">It does break it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:17</div><div class="msg">Some work on Status-react is needed </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:17</div><div class="msg">ah, can we then cherry-pick it to the latest updated status-go?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:17</div><div class="msg">That?s why it was reverted, right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:17</div><div class="msg">ah, this part is fine</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:17</div><div class="msg">I'm talking about, say, removed pending tx</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:17</div><div class="msg">Oh yeah. That should not be included</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:17</div><div class="msg">so as long as this `shh` change is the only breaking change, it is fine :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:18</div><div class="msg">Ok so which status-go SHA should we use?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:19</div><div class="msg">I would do `<a href="https://github.com/status-im/status-go/releases/tag/0.10.0-rc.1">https://github.com/status-im/status-go/releases/tag/0.10.0-rc.1</a>` based on the old one + this one commit.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:19</div><div class="msg">the old one = `<a href="https://github.com/status-im/status-go/releases/tag/0.10.0-rc.0">https://github.com/status-im/status-go/releases/tag/0.10.0-rc.0</a>`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:20</div><div class="msg">Ok, so I will do that and update <a href="https://github.com/status-im/status-react/pull/5319">https://github.com/status-im/status-react/pull/5319</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:22</div><div class="msg">:thumbsup: @andreap can you take a look at the react side of changes after it is done then? that sounds pretty urgent...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:23</div><div class="msg"><a href="https://github.com/status-im/status-react/pull/4659">https://github.com/status-im/status-react/pull/4659</a> ? this is status-react revert that should be probably reverted and fixed</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 13:25</div><div class="msg">@igor680 sure</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:25</div><div class="msg">yeah, but we should make sure on the status-go side that everything that is included in `CallRPC` would be accessible through `CallPrivateRPC` as well :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 13:25</div><div class="msg">@adamb can you ping me when the status-go build is ready?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:26</div><div class="msg">@andreap sure</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:26</div><div class="msg">@igor680 that should be a case.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:27</div><div class="msg">we probably might want to add a few sanity autotests to be sure that that is the case :stuck_out_tongue:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 13:27</div><div class="msg">@adamb tell me if I can help :wink:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:31</div><div class="msg">@andreaf if you can add these sanity tests that'd be great!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:31</div><div class="msg">we have quite many e2e tests that are using `RPCPrivateClient` and they pass. Check out changes <a href="https://github.com/status-im/status-go/pull/1131">https://github.com/status-im/status-go/pull/1131</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:32</div><div class="msg">But yeah, we can do more :wink: Like iterate over `APIModules` and make sure they work with the private client</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 13:33</div><div class="msg">I mean, just a few methods from each namespace is ok :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 13:33</div><div class="msg">ok so with PR 1131 we are tagging a new release right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 13:34</div><div class="msg">that's the plan unless where will be more changes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 14:09</div><div class="msg"><!channel> we've been invited to attend the security best practices conference, and I'm part of a telegram group <a href="https://ethereum-magicians.org/t/wiki-gathering-of-security-community/433">https://ethereum-magicians.org/t/wiki-gathering-of-security-community/433</a> (as part of <a href="https://status-im.slack.com/archives/CA7AX3CKF/p1531795650000048">https://status-im.slack.com/archives/CA7AX3CKF/p1531795650000048</a> and <a href="https://status-im.slack.com/archives/CA7AX3CKF/p1531795650000048">https://status-im.slack.com/archives/CA7AX3CKF/p1531795650000048</a>) - I think it's important that we're present - who can make an appearance?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-13/329132457109_199841cd908ca7faa97f_72.jpg" /><div class="message"><div class="username">rachel</div><div class="time">2018-07-31 14:10</div><div class="msg">I am physically here and available but absolutely not the right representative?you can put my name down as plan D.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 14:13</div><div class="msg">@andreap `release-0.10.0-ga6e2e079-263`
|
|
```
|
|
[consumer_0] Deploying artifact: <a href="http://139.162.11.12:8081/artifactory/libs-release-local/status-im/status-go/release-0.10.0-ga6e2e079-263/status-go-release-0.10.0-ga6e2e079-263.aar">http://139.162.11.12:8081/artifactory/libs-release-local/status-im/status-go/release-0.10.0-ga6e2e079-263/status-go-release-0.10.0-ga6e2e079-263.aar</a>
|
|
[consumer_1] Deploying artifact: <a href="http://139.162.11.12:8081/artifactory/libs-release-local/status-im/status-go-ios-simulator/release-0.10.0-ga6e2e079-263/status-go-ios-simulator-release-0.10.0-ga6e2e079-263.zip">http://139.162.11.12:8081/artifactory/libs-release-local/status-im/status-go-ios-simulator/release-0.10.0-ga6e2e079-263/status-go-ios-simulator-release-0.10.0-ga6e2e079-263.zip</a>
|
|
```</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:14</div><div class="msg">thanks, I'll start taking a look at it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 14:14</div><div class="msg">on top of that, there's an upcoming interview with these guys as well, and I'd love to get in touch with the right people to go over it and provide our feedback to them - who is the right person to talk to regarding our smart contract development, past security practices etc? @jarradhope @naghdy @3esmit @igor680 ```Talk about your background
|
|
What are the biggest issues with Ethereum security (should be broad question)
|
|
Audits-- (for auditors and developers) - Walk through the audit process
|
|
What are biggest mistakes you're seeing
|
|
Is security post post smart contract audit a concern -- what steps are you taking?
|
|
How are you involved in the broader security community --
|
|
Tools
|
|
What tools / processes are you using to stay secure?
|
|
What tools are missing?
|
|
How would you create a standards body or encourage collaboration?
|
|
What type of training would be useful?
|
|
How can we improve the security landscape -- where is the low hanging fruit?
|
|
Are you attending Unconference in Berlin -- before ETHBerlin
|
|
Who else do you respect (inside or outside blockchain)
|
|
What would keep you up at night -- Security question
|
|
|
|
```</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-31 14:15</div><div class="msg">This seems specifically geared towards smart contracts. Perhaps this is something for Corey? Or is this too early?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 14:16</div><div class="msg">corey is a great idea I think, so he gets the right connections right from the start - anyone else? I'm thinking maybe @baofranca to feel them out for recruiting as well, and possibly @igor680</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 14:16</div><div class="msg">I?m in Berlin from 4 to 8 of September</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 14:16</div><div class="msg">So I?m up for it :)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 14:17</div><div class="msg">@rachel just get one of those knowledge shots on deep security and you're done</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-13/329132457109_199841cd908ca7faa97f_72.jpg" /><div class="message"><div class="username">rachel</div><div class="time">2018-07-31 14:18</div><div class="msg">Glad Igor can be there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 14:18</div><div class="msg">possibly @adamb as well - @oskarth they're indeed a little bit focused on dapp and contract security - strong rep the auditing community will be there as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 14:19</div><div class="msg">@igor680 do you have a telegram? I'll invite you to the group</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-31 14:19</div><div class="msg">Could you invite me as well? I might be able to make it and ETH Berlin in general as well, but not sure yet (a bit far right now)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 14:19</div><div class="msg">yep, im from Russia :wink:
|
|
surprisingly, <a href="http://t.me/mandrigin">http://t.me/mandrigin</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-31 14:20</div><div class="msg"><a href="http://t.me/oskarth">http://t.me/oskarth</a> here</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:20</div><div class="msg">@adamb @igor680 I see that `whisper.SelectKeyPair` resets the privateKeys store, so maybe the id doesn't need to be deterministic. every time we select an account we reset the store and we inject the key with a new id and return that id. and then `status-react` can use that id? /cc @andreap</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 14:20</div><div class="msg">idk, I'd be very glad to speak to someone who wrote this patch :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 14:22</div><div class="msg">for the app+status-go itself, I guess @adamb knows the history of security</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:27</div><div class="msg">`status-react` side works fine, we need the pk and the id, we use the pk to share the contact code, and we can use the id for any whisper communication</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 14:33</div><div class="msg">@igor680 might be hard as those people do not work at Status anymore</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 14:34</div><div class="msg">let?s just get rid of it. Can I create an issue or there is something that needs to be done first?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-26/387385772272_e2807e7b15a70664e91f_72.jpg" /><div class="message"><div class="username">baofranca</div><div class="time">2018-07-31 14:37</div><div class="msg">I was asking about this event in the events channel :stuck_out_tongue:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 14:37</div><div class="msg">I think we can create an issue for that. And maybe there is something in the history of commits or something that points to more information. </div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:39</div><div class="msg">@igor680 I had a look at the commit history, it's been there forever, and the commit is non-descriptive, I can pull it for you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:41</div><div class="msg">does status-react use the public key in the `sig` field when calling `<a href="http://shh.post">http://shh.post</a>`?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:41</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:41</div><div class="msg">cause that one should be the ID, but given that changes status-react doesn't need the ID</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:42</div><div class="msg">so we would ne a lot of changes maybe</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:42</div><div class="msg">@andreaf I don't think is a huge change</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:42</div><div class="msg">we can just return the id and the pk, and we just use the id when calling</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:42</div><div class="msg">ok so basically when status-react select an account it receives back the key id</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:43</div><div class="msg">yes, and the pk as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:43</div><div class="msg">why does react need the private key</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:43</div><div class="msg">well we have that, nevermind :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:43</div><div class="msg">public i meant</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 14:43</div><div class="msg">The app + status-go yes, but I have never worked on smart contracts security topics. I think @rramos knows stuff about that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:43</div><div class="msg">ah ok, so basically you just need the id and then you can call the API to get the public key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:43</div><div class="msg">is that correct?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 14:44</div><div class="msg">we actually have that in the first place, stored in realm I think, but otherwise yes, that works</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:44</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-06/411178710468_720d28ab1ef2ed6c3c74_72.png" /><div class="message"><div class="username">rajanie</div><div class="time">2018-07-31 14:45</div><div class="msg">we have a list of people who will be attending ETHBerlin so I can share that as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 14:45</div><div class="msg">@andreap the only point where react select the account is in the `Login` function right? passing address and password</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:00</div><div class="msg">@igor680 when do we plan to release a new version? I just wonder if we should aim for a hot fix release as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:02</div><div class="msg">@adamb as soon as these changes are well tested, then we can do that. Maybe we can speed it up a bit. @andreap is the PR to update status-go ready to be tested?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:02</div><div class="msg">@igor680 also, all users are in danger until they upgrade since anyone in a public chat can see public keys and send a link to a malicious dapp</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 15:03</div><div class="msg">@andreaf I believe so, @igor680 not yet, it still throws an error, I have to make some changes, but afk for ~3hrs, so will work on it once I get back</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:04</div><div class="msg">ok, ok
|
|
do we use this `GetPrivateKey` somewhere in status-react?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-07-31 15:05</div><div class="msg">@igor680 no never, we just need to change the provider to the new endpoints and should work</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:06</div><div class="msg">@andrey @roman can we somehow simply blacklist this one method `shh_getPrivateKey` from our provider (as a hot-fix), while we are waiting for the proper implementation?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 15:07</div><div class="msg">yes we can</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 15:07</div><div class="msg">yeah - let's not send a whole crowd I think, but a few people that have the best reason to be there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:08</div><div class="msg">@igor680 are you thinking of a hot fix release which blocks `shh_getPrivateKey` while we release `shh` blockage as a regular one?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:08</div><div class="msg">@igor680 does the hot fix release force all the app to upgrade?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-31 15:08</div><div class="msg">Depends what we mean by Smart Contract security, are we talking about overall design of contracts and their future implications? All we have is just thinking about it to the best of our ability, mostly coming from @3esmit but we have no formalization and like most things in Ethereum we're not proving it correct by construction
|
|
|
|
If we're talking about mainnet deployed code, Jordi offered to write our SNT token and contribution contracts for us because he believes in the project, we sat down and manually went over code many many times, as well as hired many auditing outfits to view the code as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:08</div><div class="msg">Ok. So my proposal is.
|
|
Take `release/0.9.23`, cut `release/0.9.24` from it.
|
|
On `release/0.9.24` we block this one method completely (on a react side).
|
|
And then we normally release `0.9.25` as usual with this new private fixup.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-31 15:09</div><div class="msg">Considering the scope, the best reason would be Corey or one of the contract devs imo (@3esmit @barry @rramos)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:09</div><div class="msg">and yeah, we shall add a test DApp that checks this. it should fail on 0.9.23, but pass on 0.9.24 and further.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:10</div><div class="msg">wdyt? @andrey @andreaf @adamb?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 15:12</div><div class="msg">i'm not sure, is it possible for dapp to get public key in 23?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:12</div><div class="msg">Sounds good :+1: maybe we can block a few more `shh_*` methods that use deterministic IDs if possible?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:12</div><div class="msg">@igor680 it's ok for me. just to understand, the does the hot fix force the app to upgrade? otherwise any client would still be in danger until it upgrades</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:12</div><div class="msg">no, we can't force upgrade, we should never be able to do that in the first place</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:13</div><div class="msg">yeah, it we must communicate it so that everyone upgrade</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:14</div><div class="msg">@andrey the DApp can just check if this method is exported or not</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:14</div><div class="msg">and also, how should we talk about this in issues pr etc? because I malicious user can just use it and hope someone in a public chat is still using an old version, and they can easily steal all ETH, tokens, etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:14</div><div class="msg">@andrey yes, if DApp knows the public key of one who opened that DApp. But as @andreaf noticed, you can collect public keys of people in a public chat, craft a DApp and send a link to it on that public chat</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:16</div><div class="msg">Theoretically if we want to cover security of Ethereum in more broad sense, then DApp browsers and wallets are also needs to be discussed.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:16</div><div class="msg">@andreaf I think we should not talk about it in details. But if someone follows the repo closely, he/she already knows that `shh` is available in DApps?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 15:16</div><div class="msg">the group is just starting, and I think we have the opportunity to affect its direction a bit as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-31 15:16</div><div class="msg">they were also asking if we want to present something at the conference</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:16</div><div class="msg">I mean we can talk about it in details when we confirm almost no one is using affected versions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:17</div><div class="msg">@andrey can you make this small patch based on `release/0.9.23`?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-31 15:18</div><div class="msg">Also worth noting it isn't a permissioned event as far as I can tell, so anyone in Berlin around that time can sign up here as far as I can tell: <a href="https://ethereum-magicians.org/t/wiki-gathering-of-security-community/433">https://ethereum-magicians.org/t/wiki-gathering-of-security-community/433</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-31 15:20</div><div class="msg">Possibly some people from Embark/Vyper might be interested? Just looking at the kind of things mentioned here: <a href="https://guidelines.secureth.org">https://guidelines.secureth.org</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 15:21</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 15:22</div><div class="msg">should i create release/0.9.24 ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:22</div><div class="msg">yes, please!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-14/363707704565_2e5e86c7fcaa985eacd9_72.jpg" /><div class="message"><div class="username">barry</div><div class="time">2018-07-31 15:26</div><div class="msg">Something I have been thinking about recently is with more DApps starting to be hosted on IPFS with DNS redirects, if the content changes the hash changes, but I don't believe any browser/wallet notifies the user that the content changed.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:27</div><div class="msg">all the DApp browsers are in a very early stage atm...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:32</div><div class="msg">@andreaf @adamb just to understand how bad that issue is, is the private key we set to Whisper the same as the one we use for transactions?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:32</div><div class="msg">yes, so it's very bad</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:33</div><div class="msg">That?s true. We talked about it in Basel a bit that one key pair is used everywhere</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 15:33</div><div class="msg">one more reason to have separate account for whisper</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:33</div><div class="msg">yeah, at least a derived key would be much better</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:36</div><div class="msg">yes I agree, we also discussed about it last week</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:37</div><div class="msg">I think it should be a kind of P0 priority for status-go to fix that, for the future</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:37</div><div class="msg">do we have a swarm around that? It feels like this topic was mentioned many times and many people have a vision how it can be fixed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:37</div><div class="msg">I think it touches status-react as well. Status-go can only offer deriving keys which is already implemented</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:38</div><div class="msg">I'll start it tomorrow, maybe with a discussion on `discuss` so that everyone can give opinions?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:38</div><div class="msg">or status-go can provide a less fragile APIs, that status-react never even sees anything like private keys</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:38</div><div class="msg">can be as well, but we need to collect all use cases</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:38</div><div class="msg">for example, we can derive a key per DApp</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:38</div><div class="msg">and that's where both status-* need to communicate</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:39</div><div class="msg">for whisper is easy though, we are already extending the original ethereum keystore, so we can add an additional key only used for whisper. with a different derivation path so that it's always derived with the same account/menmonic-phrase</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 15:40</div><div class="msg">@andreaf a post on discuss would be a great start. Just maybe let?s write a draft offline first so that we can present a version that is a bit more robust and fleshed-out</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-31 15:40</div><div class="msg">ok I'll work on this tomorrow morning</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:44</div><div class="msg">ok, also, I'd want to discuss the "doomsday scenario" tomorrow (and how do we handle that), I'll make a Discuss post tomorrow too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 15:45</div><div class="msg">essentially about how can we handle the cases like that, and it also should be pretty critical thing to do, better to have it and not having to use it than have ourselves in the situation like that again</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/6e12ebcea03f27a40c66e503f89be217.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">cologic</div><div class="time">2018-07-31 16:00</div><div class="msg">Interested in the topic, though not necessarily terribly proximate physically to Berlin.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:15</div><div class="msg">wow</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:16</div><div class="msg">i'm not sure how to hide this in Status Test Dapp for testing, because "hack this guy" looks not good</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:17</div><div class="msg">maybe something like "test" button and "result" if there is pk response</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:18</div><div class="msg">let?s not publish it atm, when we mitigate the issue, we can just call it ?test whisper pk extraction?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:19</div><div class="msg">how can QA test it then?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:25</div><div class="msg">can they run this DApp locally somehow?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:29</div><div class="msg">yes i can provide js and html files</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:30</div><div class="msg">so, let's do it locally
|
|
not cool to release exploit before we release a fix :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:42</div><div class="msg">hm i can fix it for web3 but it's still possible to call it from js, i need @roman help here</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:44</div><div class="msg">hmm, how can you call it w/o web3?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:45</div><div class="msg"><a href="https://github.com/status-im/status-react/blob/develop/resources/js/web3_init.js#L78">https://github.com/status-im/status-react/blob/develop/resources/js/web3_init.js#L78</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:46</div><div class="msg">webview native component directly call status-go</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:47</div><div class="msg">so maybe faster will be made change on the go side</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:51</div><div class="msg">there isn't any `sendRequest` method in the API exported from Go afaik</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:52</div><div class="msg">it all goes down to `(call-module #(.sendWeb3Request status payload callback))))`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:52</div><div class="msg">i don't think there is any way around this code</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:53</div><div class="msg"><a href="https://github.com/status-im/react-native-webview-bridge/blob/master/android/src/main/java/com/github/alinz/reactnativewebviewbridge/StatusBridge.java#L27">https://github.com/status-im/react-native-webview-bridge/blob/master/android/src/main/java/com/github/alinz/reactnativewebviewbridge/StatusBridge.java#L27</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:54</div><div class="msg">but it still calls `evaluateJavascript`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:54</div><div class="msg">ah, ok, this function is injected there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:56</div><div class="msg">but your own `getSyncResponse` is involved there as a shortcut, btw (@andrey)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 16:57</div><div class="msg">or you are talking about StatusBridge still being accessible to any JS?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 16:59</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-07-31 17:00</div><div class="msg">sorry i need to go</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 17:02</div><div class="msg">If that's not possible, we can easily blacklist calls from C binding reaching our JSON-RPC client. Actually it makes sense as we may easily skip some way of calling HTTP Provider when doing that on status-react side.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 17:02</div><div class="msg">I can work on that later today</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 17:04</div><div class="msg">thanks a lot!
|
|
alternatively it is possible to do that by registering a custom RPC handler like we did for `personal_sign`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 17:05</div><div class="msg">@adamb the commit you are looking for to base your patch is `a339d7ed`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 17:11</div><div class="msg">thanks! oh yeah, that's also possible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-07-31 17:33</div><div class="msg">Most of security flaws in smart contracts are logic flaws or not fully understood ethereum behavior. Some flaws don't compromise the desired flow, but are open to other uses. Smart contracts should always have clear state and the state changes should be limited to the scope, other option of state change that was not intended in the logic would be a bug.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 17:47</div><div class="msg">@igor680 oh shoot. I can't do that as I don't know if a call comes from Dapp or from status-react</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 17:49</div><div class="msg">we can always block it, status-react shouldn't call it either</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 17:49</div><div class="msg">from the RPC, I mean</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 17:53</div><div class="msg">Ah right. They said they don't use it </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-07-31 17:53</div><div class="msg">All good then :d </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 18:00</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-07-31 18:01</div><div class="msg">^ @corey122 fyi, in case you are interested/avail</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 18:03</div><div class="msg">I'm very happy this channel already exists</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 18:06</div><div class="msg">I am quite interested in this, and will have to check availabilty. One of the telegram security groups I'm apart of has been discussing this in depth. I'll send an invite if you'd like to join it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 18:10</div><div class="msg">I have a list of potential topics of interest for this event: <a href="https://docs.google.com/document/d/12ZdNqVAkv8MEkQZzcdRRSqf1pykmctyX7VJgmE4XlfI/edit">https://docs.google.com/document/d/12ZdNqVAkv8MEkQZzcdRRSqf1pykmctyX7VJgmE4XlfI/edit</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-07-31 18:15</div><div class="msg">Welcome onboard! :)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 18:16</div><div class="msg">:slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 18:17</div><div class="msg"><a href="https://medium.com/@peter_szilagyi/augur-hijack-via-dormant-service-workers-bea254258f98">https://medium.com/@peter_szilagyi/augur-hijack-via-dormant-service-workers-bea254258f98</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 18:18</div><div class="msg">I'm not sure if status infra is vulnerable to this now, or in future roadmap, but important to look out for</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-14/363707704565_2e5e86c7fcaa985eacd9_72.jpg" /><div class="message"><div class="username">barry</div><div class="time">2018-07-31 18:31</div><div class="msg">But users and contributors could be, given this delivery mechanism:
|
|
|
|
"One prevalent way nowadays to attack crypto-currency users is to get them to copy paste code from random web pages or chats into their terminal. While it may sound overly dumb, it does seem to work, especially since this particular attack doesn?t even require root access."
|
|
|
|
I guess this happens more frequently than it should because of poorly built interfaces forcing users to sometimes do things like this for legitimate reasons.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 18:43</div><div class="msg">Hopefully this is an attack of the times, and not something that proliferates, but being a "developer" in today's society becomes more and more broad, as talking with comptuers is considered common knowledge more and more.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-07-31 19:43</div><div class="msg">Welcome @corey122! I'll also be in Berlin, and can join for operational support if needed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-26/387385772272_e2807e7b15a70664e91f_72.jpg" /><div class="message"><div class="username">baofranca</div><div class="time">2018-07-31 19:47</div><div class="msg">Ill be there @arnetheduck.slack :stuck_out_tongue: @igor680 ill finally meet you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-07-31 20:48</div><div class="msg">I'm working out logistics for this. My wife will be traveling at that tie as well, so I need to plan a little more. I should be able to go though</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-01 02:40</div><div class="msg">well, the questions they wanna ask are right up there :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-01 07:17</div><div class="msg"><a href="https://status-im.slack.com/archives/C9B1T4B9B/p1533078470000017">https://status-im.slack.com/archives/C9B1T4B9B/p1533078470000017</a> follow-up on the security audit</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-01 07:25</div><div class="msg">I wanted to ask about that today :slightly_smiling_face: We said that we would send the final answer at the beginning of this week so we should do that ASAP.
|
|
|
|
Security audit of the chat is ruled out as we are rewriting it. We established that we can do audit of the wallet changes, one PR regarding HD keys and custom implementation of `personal_sign` and `personal_ecRecover`.
|
|
|
|
Overall, the goal of this audit was to verify chat e2e encryption and prepare the app to 1.0. As both things changed, in my opinion, it does not make sense to do it at all at this point.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-01 07:27</div><div class="msg">cc @oskarth @naghdy @arnetheduck.slack @corey122</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-01 07:48</div><div class="msg">btw how is it possible you can get private key without password?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-01 07:50</div><div class="msg">because it is injected into Whisper after login if I understand correctly</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-08-01 07:51</div><div class="msg">correct, whisper acts as a key value in memory store</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-01 07:54</div><div class="msg">when we want to implement separate key for whisper? do we have an issue?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-01 07:54</div><div class="msg">it looks like highest priority</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-01 07:55</div><div class="msg">we wanted to do that since forever :slightly_smiling_face:
|
|
@andreaf wanted to discuss the approach and then we need to start doing that</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-08-01 07:57</div><div class="msg">@andrey not yet, i will create one tonight, i would like to be involved as i was thinking to change contact code format and this is a good time</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-01 07:57</div><div class="msg">great, thanks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-01 08:04</div><div class="msg">Talking with Corey tomorrow. IMO it's not a big deal if we respond a bit later. They haven't pinged us or set a hard deadline or anything like this yet. Given their long lead time we don't want to prematurely say a hard no unless we 100%, even with diff scope. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-01 08:04</div><div class="msg">@andreap I'm going to open a PR in the Ideas repo this morning, as soon as I open it I'll send you the link so that we can work on it together</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-08-01 08:05</div><div class="msg">awesome</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-01 08:59</div><div class="msg">welcome @corey122!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-01 12:05</div><div class="msg">Happy to be here.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-14/363707704565_2e5e86c7fcaa985eacd9_72.jpg" /><div class="message"><div class="username">barry</div><div class="time">2018-08-01 13:25</div><div class="msg">When deploying a smart contract are there best practices we should follow? Here are some concerns that come up:
|
|
|
|
Many contracts have an owner or controller which is usually by default set to the address that deployed the contract. If the keys of the deployer are compromised then that contract is compromised. What type of environment should be used for deployments?
|
|
|
|
For security but also for decentralization, after deployment ownership of the contract should be transferred. What address or what are the requirements of the address that contract ownership should be transferred to?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-01 15:01</div><div class="msg">Idea PR opened and discuss topic posted: <a href="https://status-im.slack.com/archives/C8QP8S5UH/p1533135596000159">https://status-im.slack.com/archives/C8QP8S5UH/p1533135596000159</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-01 15:05</div><div class="msg">thanks!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-01 16:05</div><div class="msg">I will try to answer all questions I found in this channel, I'm answering in hackmd and later I paste here. There are lot of questions and I need some time to think and write about them.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-01 16:22</div><div class="msg">I'm happy to collab on the hackmd instead</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-01 16:37</div><div class="msg"><a href="https://hackmd.io/o1pD6cXpTmCO-Pzksmb1zw#">https://hackmd.io/o1pD6cXpTmCO-Pzksmb1zw#</a> I'm here, if you want to preview it.. I still need to answer most of them.
|
|
|
|
I think we should write individually those questionings and then make a common for all of us</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-01 16:39</div><div class="msg">ooh! in that case - are you interested in taking the interview with the guy directly instead? I became the point of contact simply because I happened to run into someone on ECDC and I think it's important we're part of the effort - I haven't been involved in this stuff in any qualified way, so I'm just trying to facilitate our entry</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-01 16:40</div><div class="msg">(and make sure the right people know about it :slightly_smiling_face: )</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-01 16:41</div><div class="msg">Maybe I can finish to answer them in this doc, then I go to the other questions. We can have a interview directly, if needed, but I would feel more confortable after finishing this mental organization</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-01 16:42</div><div class="msg">I also need to go to the past messages I missed :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-01 16:46</div><div class="msg">btw, what was your idea initially? maybe we can also go forward it, making a collab doc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-01 16:50</div><div class="msg">my initial idea was to get a feeling for whether we have an existing process for security at status and go from there, making an inventory of stuff we've done that touches on security - since people are generally busy, taking the interview seemed like a good way to help :slightly_smiling_face: but I think the quality will be higher if the people that actually did the work get interviewed themselves - obviously I'll leave stuff out</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-01 17:27</div><div class="msg">Do we have anything that monitors for people doing normal vulnerability testing of our endpoints?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-01 17:28</div><div class="msg">if so, don't be alarmed if they blow up over the next few weeks... its me</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-01 18:30</div><div class="msg">I don't think so, but maybe a good question to ask in #core-infra </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-01 19:13</div><div class="msg">Which endpoints do you have in mind?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-01 21:22</div><div class="msg">I'm still figuring out the lay of the land... but for starters, whatever servers we have running doing various tasks, user facing websites and portals.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-02 06:58</div><div class="msg">Ah I see. Yeah, we have a few of them. Regarding the infra that powers Status mobile app, there should be no open endpoints except for nodes devp2p ports. If you find some then we should close them I believe.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 07:07</div><div class="msg"><a href="https://status-im.slack.com/archives/C9CQMSWUE/p1533193521000248">https://status-im.slack.com/archives/C9CQMSWUE/p1533193521000248</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-02 07:16</div><div class="msg">@corey122 what do you think about CAPEC attack classification? Looks useful to me because it has some presets on mitigation techniques.
|
|
<a href="https://capec.mitre.org/data/definitions/3000.html">https://capec.mitre.org/data/definitions/3000.html</a></div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-02 07:56</div><div class="msg">```
|
|
Hi Eric,
|
|
|
|
I wanted to see if you'd be interested in connecting further, per my note below.
|
|
|
|
Please let me know either way, I appreciate the candor.
|
|
|
|
Thanks,
|
|
|
|
Topher
|
|
Topher Jordan
|
|
|
|
On Jul 25, 2018 3:03 PM, "Topher Jordan" wrote:
|
|
Hi Jakub,
|
|
|
|
I looked at <a href="http://Status.im">http://Status.im</a> today and saw that you're on the DevOps team and have experience with AWS and Docker containers. I also saw you're looking to bring on a Senior security engineer responsible for monitoring and investigating breaches and conducting continuous security audits.
|
|
|
|
We're working with similar companies that have found Threat Stack to be a force multiplier for new hires.
|
|
|
|
Threat Stack is a host-based intrusion detection platform that helps bake security into ops through native integrations with tools like Docker, Chef, AWS, etc.. We continuously audit your AWS configuration & monitor your environment for vulnerabilities and uncharacteristic file, user, network, process or package events resulting from internal or external causes. When something doesn't look right, Threat Stack answers the tough questions around who did what, where, and when for you - allowing you to investigate and remediate the issue in minutes instead of hours or days.
|
|
|
|
It would be great to learn some more about <a href="http://Status.im">http://Status.im</a> and your goals moving forward. Do you have 10 minutes in the next 2 weeks so we can connect and continue the conversation?
|
|
|
|
Best,
|
|
-Topher
|
|
Topher Jordan
|
|
```
|
|
Don't know what threat stack is, is it something we might be interested in ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 12:04</div><div class="msg">I'll look at what they offer today and see how it stacks up to other services that are similar... There's is a plethora of open source solutions.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 13:12</div><div class="msg">They tried scheduling a meeting with me but I'm too busy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 13:42</div><div class="msg">They have also hit me up. @oskarth has told me we have a ELK stack running. Depending on that, we may not need what they're offering.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-02 13:44</div><div class="msg">~at least part of an ELK stack, not sure if it's all the way there yet :stuck_out_tongue:~</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-02 13:44</div><div class="msg"><a href="https://github.com/status-im/status-cluster">https://github.com/status-im/status-cluster</a> do you have access to this @corey122?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-02 13:45</div><div class="msg"><a href="https://kibana.status.im/">https://kibana.status.im/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-02 13:47</div><div class="msg"><a href="https://grafana.status.im/login">https://grafana.status.im/login</a>
|
|
<a href="https://consul.status.im/">https://consul.status.im/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 13:48</div><div class="msg">checking now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 13:48</div><div class="msg">Yes I do</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 13:49</div><div class="msg">I love grafana</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 13:49</div><div class="msg">Who doesnt</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 13:49</div><div class="msg">crazy people</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-02 14:08</div><div class="msg">speaking of this, I realize I don't know how we deal with log rotation etc. I know there was some question on log noise for debugging. How fast are they growing and what do we do with historical data?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 14:10</div><div class="msg">what you do with it depends on what type of log</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:43</div><div class="msg">currently we aggregate only logs from docker containers via rsyslog</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:43</div><div class="msg">the status of the es cluster is here: <a href="https://es.status.im/">https://es.status.im/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:44</div><div class="msg">so far our data takes up 34 GB</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:44</div><div class="msg">but that's because I've defaulted to 5 shards and 2 replicas for every index</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:44</div><div class="msg">each host has 80gb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:44</div><div class="msg">right now every host is using ~20gb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:46</div><div class="msg">and this is for logs that go back 1 month</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:47</div><div class="msg">we should be able to store at least 2 more months, after that logs should probably be archived</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:47</div><div class="msg">or I could just get more disk space</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:47</div><div class="msg">but it's worth nothing that I should revisit this in a month or so, I'll add a reminder</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 14:47</div><div class="msg">noting*</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-08-02 15:03</div><div class="msg">During Wallet sync call we brought up the question of counterfeit Status builds that have been tampered with. E.g the scenario where someone builds their own apk files and distributes them to the victims. Obviously, we'll need some kind of a mechanism to let users verify non-store builds, however another issue that pops out from this one is error reporting. Say, if the user installs a fake Status build, how do they report it to us? Shaking the phone might be disabled too.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 15:04</div><div class="msg">isn't that part and parcel of deterministic builds?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-08-02 15:04</div><div class="msg">So, basically we'll need some kind of obvious and well known off-app communication channel for users to report incidents like that, e.g. `<mailto:abuse@status.im|abuse@status.im>`, abuse channel on riot, etc.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-08-02 15:04</div><div class="msg">how do you mean that @corey122?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 15:06</div><div class="msg">one of the current goals is deterministic builds and package dependency. If someone build from source, or receives a built product, they should be able to verify (through hash) that is done correctly.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-08-02 15:07</div><div class="msg">yep, perfect, that's more or less what I had in mind</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 15:07</div><div class="msg">but yes, and avenue for reporting would be helpful... maybe <mailto:security@status.im|security@status.im> @oskarth@jakub?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:08</div><div class="msg">ah yes, deterministic build, the great pie in the sky</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:09</div><div class="msg">I'd love to have them, but I can just see how much work it's gonna take</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-02 15:09</div><div class="msg">I understand that packages make that a nightmare.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:09</div><div class="msg">yeah, it's gonna be fun</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-02 15:11</div><div class="msg">well, we might isolate the environment with pre-installed packages into a Docker image and use a specific Docker image to build something (as a last resort) :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:11</div><div class="msg">or use Nix</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:11</div><div class="msg">or Gitian</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:11</div><div class="msg"><a href="https://github.com/devrandom/gitian-builder">https://github.com/devrandom/gitian-builder</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:12</div><div class="msg">gitian is pretty heavy since it uses qemu for isolating the build env</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:12</div><div class="msg">Nix is much more lightweight and pretty neat way of controling your build env</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-02 15:12</div><div class="msg">yeah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:12</div><div class="msg">but doekr would work too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-02 15:12</div><div class="msg">docker*</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-02 16:09</div><div class="msg">Building something on docker would be nice for local development I guess. So that I don't need to deal with the whole npm and dependencies nightmare and just build the app quickly locally. Is that correct?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-02 17:07</div><div class="msg">Yes, If we will have a ready to use image in a repository.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-03 05:30</div><div class="msg">Is this from a Kevin S? He reached out to me too so want to check if it's the same thing (guessing it is?)</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-03 09:57</div><div class="msg">I don't know if that can be solved without educating users because any UX solution can be countered by a fake build</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-03 15:05</div><div class="msg">yeah, kevin</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-03 17:29</div><div class="msg">trail-of-bits curated repo of security contacts: our wallet missing: <a href="https://github.com/trailofbits/blockchain-security-contacts">https://github.com/trailofbits/blockchain-security-contacts</a> (@goranjovic @igor680)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-03 18:08</div><div class="msg">wait, there is a mention of <mailto:security@status.im|security@status.im>, but only as a token </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-03 18:09</div><div class="msg">indeed.. good to have the wallet in there as well, just want to make sure that the right address gets used..</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-03 18:18</div><div class="msg">speaking of that contact... I should probably be a part of that somehow</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-03 18:22</div><div class="msg">^ @adamb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-03 18:53</div><div class="msg">Definitely! @oskarth do you have permissions to add @corey122 to <mailto:security@status.im|security@status.im>?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-05 15:30</div><div class="msg"><a href="https://www.sociosploit.com/twitter-remote-access-trojan-twittersploit.html">https://www.sociosploit.com/twitter-remote-access-trojan-twittersploit.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/411838218004_c7eba2c8e4f6b1a5ba77_72.png" /><div class="message"><div class="username">graeme</div><div class="time">2018-08-06 10:33</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-06 10:34</div><div class="msg">Do not, we talked about it in call and I believe Jakub or people ops should have, if neither then Nabil has it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-06 14:34</div><div class="msg">```
|
|
Hi,
|
|
|
|
I think that I've found a bug in the add existing account functionality in status that is probably tied into the account generation routine in general. It generates the wrong account for specific mnemonics.
|
|
|
|
Steps to Reproduce
|
|
To reproduce, follow these steps:
|
|
|
|
Go to the Add existing account function in status (Logout if currently logged in, then choose other accounts)
|
|
Apply the mnemonic radar blur cabbage chef fix engine embark joy scheme fiction master release
|
|
Actual Result
|
|
The generated account is 0xc154991dd4c2ddb5c089cf2e0fd23f5f1e41ba72. This is not the expected address for the derivation path m/44'/60'/0'/0.
|
|
|
|
Expected Result
|
|
According to <a href="https://iancoleman.io/bip39/">https://iancoleman.io/bip39/</a> the expected account for this mnemonic with derivation path m/44'/60'/0'/0 is 0xaC39b311DCEb2A4b2f5d8461c1cdaF756F4F7Ae9.
|
|
|
|
If you try another mnemonic (eg. cousin omit link stone excuse release drill brown buzz print junior throw) the accounts match between status and <a href="https://iancoleman.io/bip39/">https://iancoleman.io/bip39/</a>: They both are 0x11605B108bf9F48dfA783f7215D8069Ee0A53214.
|
|
|
|
Environment
|
|
I've seen this bug on Android (v8.1.0), Status version 0.9.24 (6291) node 7ebe0c3 connected to mainnet.
|
|
|
|
Note
|
|
I?m sending this bug as an email according to <a href="https://gist.github.com/adambabik/7e1c9148610a64fbeb953eaf1b742456">https://gist.github.com/adambabik/7e1c9148610a64fbeb953eaf1b742456</a> and haven't filed a github issue yet. I thought you might wanna look at it first. I can file an issue for it too.
|
|
|
|
Best regards
|
|
Christoph```
|
|
|
|
cc @corey122 @adamb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 14:43</div><div class="msg">@naghdy I'm going to check this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 14:43</div><div class="msg">of course help from @corey122 and @adamb is very welcome :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-06 14:48</div><div class="msg">I'll be available to help in a few hours. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-06 14:48</div><div class="msg">That?s a nice and clear submission. Thanks @andreaf :+1: Please do as you gained a lot of experience recently working with that piece of code</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 16:35</div><div class="msg">update on this, so far I proved that:
|
|
? what Christoph is saying is true, our implementation generates a different address for that specific mnemonic, but it's generating the right one for the second one.
|
|
? another `go` package (<a href="http://github.com/tyler-smith/go-bip32">http://github.com/tyler-smith/go-bip32</a> together with <a href="http://github.com/tyler-smith/go-bip39">http://github.com/tyler-smith/go-bip39</a>), generates the same address generated with `<a href="http://iancoleman.io/bip39">http://iancoleman.io/bip39</a>`
|
|
? myetherwallet generates the same "right" address
|
|
I also debugged some intermediate step and I found out that the initial seed and master key are the same in our implementation, so that's definitely something wrong with our implementation of the derived keys.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 16:43</div><div class="msg">mmmm, I see that we generate the right one at `m/60'`, I'm going to debug the reset of the derivation path tonight but I need to leave for some hours</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-06 17:36</div><div class="msg">great steps forward! keep us posted please :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-06 18:30</div><div class="msg">@andreaf I'll loop you into the email, and acknowledge his input. If you can all please think about the expected reward so that we can pay him out once fixed (cc @gdoly @jason)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 22:53</div><div class="msg">I found the bug in our code. I still need to check again the technical specs of the bip32 to be sure, but at least I see the differences between our code and the one used in the above implementations in go and js.
|
|
It's a part of the code that has been written 2 years ago, so I would like to research more for the next days.
|
|
I don't think we have a security problem with this one (but please help me @corey122 and @adamb), but it means that after fixing it, some users might recover a different wallet from the one that they have now.
|
|
I'll write something more tomorrow about that!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 23:47</div><div class="msg">this PR is WIP but it fixes the generation of that specific key/mnemonic:
|
|
<a href="https://github.com/status-im/status-go/pull/1139">https://github.com/status-im/status-go/pull/1139</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 23:51</div><div class="msg">@adamb @corey122 if you want to try it you can do it with this simple go file:
|
|
|
|
<a href="https://gist.github.com/pilu/07c6da17bc9d2c14c4de29e005ded567">https://gist.github.com/pilu/07c6da17bc9d2c14c4de29e005ded567</a>
|
|
|
|
with the current `go-status:develop` it derives the wrong address (the first one printed).
|
|
with `go-status:fix/bip32-keys-derivation` it derives the right one as he says.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-07 00:57</div><div class="msg">So it seems the previous code only lacked padding?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-07 01:00</div><div class="msg">we need to think of the repercussions to users and their current keys/new keys after this change.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 06:44</div><div class="msg">Btw. it's interesting that Ethereum still has no established standard for HD wallet derivation paths <a href="https://github.com/ethereum/EIPs/issues/84">https://github.com/ethereum/EIPs/issues/84</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 07:52</div><div class="msg">> we need to think of the repercussions to users and their current keys/new keys after this change.
|
|
|
|
We can announce at Town Hall that after release X, the recovered account might be different due to a bug (we did that before when we broken backward compatibility). We still should provide a way to recover it using the old buggy way. @igor680 do we have an archive of old releases? Let?s say I want to install release Y, can I do that easily?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-07 07:56</div><div class="msg">I don't think it is that easily possible, at least not on iOS where we use TestFlight.
|
|
So we probably need to fix it programmatically or on UX level somehow...
|
|
|
|
Also, we need a good set of test addresses to actually cover it with better tests, since we are still finding issues there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 08:27</div><div class="msg">I guess we can release a version where we check if a derived key is different and notify user appropriately?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-07 08:40</div><div class="msg">yeap
|
|
we can also ask if the user is restoring a Status key or not</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 08:52</div><div class="msg">I think we need to do that on login. Otherwise, user might not be aware that their mnemonic phrase generate a different address for weeks.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-07 09:25</div><div class="msg">@adamb though at login we don't have the mnemonic or seed or master key, so we can't try to re-derive the key and compare</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 09:27</div><div class="msg">Ah right :face_palm: So it's only when recovering. So the best we can do is to notify people in a blog post or somehow in the app.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 09:28</div><div class="msg">However, something like ?Check out your mnemonic phrase to see if it generates a correct account? sounds like a scam :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-07 09:28</div><div class="msg">we can also derive the "old" one, see if there's value and tell something to the user but maybe it's too complecated</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 09:31</div><div class="msg">Btw. when we call `Login` and then `SelectAccount`, we get that derived key rather than the master key, right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-07 09:32</div><div class="msg">yes, master key is never saved, it's only generated at the beginning on the fly to derive the final key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 09:32</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-07 09:38</div><div class="msg">Also, before all that. Let?s make sure that we do everything possible to prevent similar problems in the future </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-07 09:40</div><div class="msg">I can do a full review of that part of the code in the next days. but the more people we are the better</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-07 10:01</div><div class="msg">@corey122 did you manage to get access to <mailto:security@status.im|security@status.im> from Jakub or people ops?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-07 10:02</div><div class="msg">if not, I believe @naghdy is a google account admin</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-21/367025375940_c77cc650cdbe3bf5be5f_72.jpg" /><div class="message"><div class="username">ceri</div><div class="time">2018-08-07 10:29</div><div class="msg">I checked to see if I?m able to add users to that Google Group and it doesn?t look like I can :disappointed: Sorry. @rajanie did you manage to do this at one point in time iirc?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-06/411178710468_720d28ab1ef2ed6c3c74_72.png" /><div class="message"><div class="username">rajanie</div><div class="time">2018-08-07 10:44</div><div class="msg">I did help Jakub create it but I think he removed me from the group. Let me check :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 11:54</div><div class="msg">No, you helped me create <mailto:auto@status.im|auto@status.im></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-06/411178710468_720d28ab1ef2ed6c3c74_72.png" /><div class="message"><div class="username">rajanie</div><div class="time">2018-08-07 11:56</div><div class="msg">yes that right! Sorry only owners of the group can add people</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 12:55</div><div class="msg">Could this be the reason I can't recover my account?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 13:15</div><div class="msg">Did you create your account in Status or somewhere else?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:16</div><div class="msg">in Status</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-07 13:17</div><div class="msg">can you also check that each of your words is in this list? <a href="https://github.com/bitcoin/bips/blob/master/bip-0039/english.txt">https://github.com/bitcoin/bips/blob/master/bip-0039/english.txt</a>
|
|
I had a problem one day because one words was wrong</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:17</div><div class="msg">thanks!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-07 13:18</div><div class="msg">Then it should recover the same account :disappointed: Recovering it in a different wallet would result in a different account</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:18</div><div class="msg">yeah, all are there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-07 13:20</div><div class="msg">I don't remember, you also tried the mnemonics in metamask? which address does it show?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:20</div><div class="msg">oh, good idea, will try</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:23</div><div class="msg">yeah, metamask is also giving me a wrong account</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:23</div><div class="msg">but the same one as status</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:24</div><div class="msg">I still don't get how I can log into an account with wrong seed phase with my password</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:24</div><div class="msg">shouldn't it just tell me that I used the wrong password?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-07 13:25</div><div class="msg">password is always valid, it's a new password generated to encrypt the keys.
|
|
any mnemonic phrase generates a valid key pair, so wrong words generate different address, but not wrong</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 13:25</div><div class="msg">i see</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-07 20:03</div><div class="msg">Yeah I haven't gotten access to this just yet I don't think.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-07 20:52</div><div class="msg">Done. You've been added now @corey122</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 21:02</div><div class="msg">Thanks Nabi?!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 21:02</div><div class="msg">L*</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 21:03</div><div class="msg">Heh, Nabi? in polish means to scewer something</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-07 21:08</div><div class="msg">thats pretty awesome</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-07 21:09</div><div class="msg">it can also mean putting tobacco in a pipe, or a bullet in a gun</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-07 21:11</div><div class="msg">All cool things, thanks guys for adding me.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-08 16:45</div><div class="msg">@jakub are you the right man to restrict access to such directories?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:46</div><div class="msg">yeah, but this is nonsense</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:46</div><div class="msg">there is no danger here</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:46</div><div class="msg">it's just a static website, what's the harm of `.git/config` being available? the repo is private(for some reason?), so the info in `.git/config` is useless</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:47</div><div class="msg">I really don't see how this is a vulnerability</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:47</div><div class="msg">I can fix it(i have in plans remaking the setup for <a href="http://cn.status.im">http://cn.status.im</a>)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-08 16:47</div><div class="msg">you are correct, there is no valuable information here, just relaying info from people sending in reports.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:47</div><div class="msg">but I have bigger priorities right now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:47</div><div class="msg">sure thing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:47</div><div class="msg">i have in my TODO setting up proper CI for <a href="http://cn.status.im">http://cn.status.im</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:47</div><div class="msg">and that's when ill probably overhaul the whole setup there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:47</div><div class="msg">but that's in the future</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:48</div><div class="msg">I need to finish setting up desktop builds, rendezvous for eth.staging, swarm fleet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/352364450583_84860327a35f2a5b0e5f_72.jpg" /><div class="message"><div class="username">jakub</div><div class="time">2018-08-08 16:48</div><div class="msg">and so on</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-08 16:49</div><div class="msg">Does anyone know of the track record we have with this particular person, he alludes to previous communication.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-08 16:50</div><div class="msg">@naghdy?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-08 16:51</div><div class="msg">Yeah it was another small bounty </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-08 23:53</div><div class="msg"><a href="https://www.ccn.com/white-hat-hacker-finds-major-vulnerability-in-ethereum-dapp-augur/">https://www.ccn.com/white-hat-hacker-finds-major-vulnerability-in-ethereum-dapp-augur/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-09 07:35</div><div class="msg">Ouch</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-09 09:26</div><div class="msg">@corey122 @adamb @igor680 I found a 3rd list of test vectors specified in the BIP32 document. They have been added in 2017, but our code was written the previous year so it doesn't have them.
|
|
It's related to "leading zeros", so I'm going to test now if it's exactly our case: <a href="https://github.com/bitcoin/bips/commit/6f94288741fb05d1ea6691675574dcb89d7b7602#diff-a9bb6d2ecee25c39945d164449e1e088R263">https://github.com/bitcoin/bips/commit/6f94288741fb05d1ea6691675574dcb89d7b7602#diff-a9bb6d2ecee25c39945d164449e1e088R263</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-09 10:44</div><div class="msg">also article about that specific case
|
|
<a href="https://medium.com/@alexberegszaszi/why-do-my-bip32-wallets-disagree-6f3254cc5846">https://medium.com/@alexberegszaszi/why-do-my-bip32-wallets-disagree-6f3254cc5846</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-09 10:46</div><div class="msg">the weird thing is that with the patch we generate the right one, but the "wrong" one is different from their wrong one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-09 12:52</div><div class="msg">any single bit that is off will generate something different, I'm curious as to where that bit is different. endian-ness? probably not.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-09 13:57</div><div class="msg">we make a sha512 of a seed that is 37 bytes, the first byte is 0, 32 for the key, 4 for the child index.
|
|
in our case when the key is represented as a number of 31 bytes or less, it's shifted to left in that 32 bytes space. does it make sense?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-09 13:59</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-09 14:35</div><div class="msg">@corey122 that specific mnemonic is already published in that article and many issues and repos. is it a good "thing" to add it in our tests? I see balance is zero but it has been used</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-09 16:40</div><div class="msg">@naghdy @corey122 @adamb @igor680 I finished adding more tests and documentation on the PR for the reported bug: <a href="https://github.com/status-im/status-go/pull/1139">https://github.com/status-im/status-go/pull/1139</a> (feedback is welcome so we can continue adding changes if needed).
|
|
|
|
I can't quantify the reward, so I need help with this /cc @gdoly @jason
|
|
|
|
This bug was already found on Sep 11, 2016 (our implementation was finished a month earlier), so we could have fixed it in the last 2 years. I think the wallet ring can be an important way to discuss about these general bugs and have a list of bugs/problems that we all together report/list/fix. /cc @jarradhope</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-09 16:47</div><div class="msg">great work, had one short comment on referencing where you got that 3rd test from for future folks.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-09 16:52</div><div class="msg">thank you, I changed the description to be clear about it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-09 17:28</div><div class="msg">The reward is calculated based on <a href="https://gist.github.com/adambabik/7e1c9148610a64fbeb953eaf1b742456#file-risk-matrix-png">https://gist.github.com/adambabik/7e1c9148610a64fbeb953eaf1b742456#file-risk-matrix-png</a>. Likelihood is low as it's below 1% of accounts that could suffer this issue. Impact is also low I guess. It results in a wrong account but does not block access to funds in any way. However, it might bring confusion if a single account is recovered outside Status and it turns out that there are no funds.
|
|
|
|
?Low threats = up to $2,000 worth of ETH or SNT? ? I would suggest $2k because it caries no security implications but it's a crucial part of the codebase that is buggy. We would probably never verified that part on our own, especially as it was audited.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-09 17:31</div><div class="msg">cc @corey122 ^^^</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-09 17:42</div><div class="msg">thank you for that reference on calculating those things, which is what I was looking for earlier.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-09 19:52</div><div class="msg">In lieu of other bug bounty discussions, a friend of mine at bcoin is attempting to put together a community wide Responsible Disclosure document that outlines the proper procedure and expectations around disclosure. Would people mind giving it a run down to add comments on how you feel about it, and add any comments/concerns/etc to it. He has made this with a lens of bcoin and how it works, but our perspective as ETH developers could broaden it: <a href="https://docs.google.com/document/d/1qOBquYOSwK3f2bI84U6OaliecfkLUUghw9miVUNPA3o/edit?usp=sharing">https://docs.google.com/document/d/1qOBquYOSwK3f2bI84U6OaliecfkLUUghw9miVUNPA3o/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-09 20:40</div><div class="msg">Have commented.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-10 04:48</div><div class="msg">Can you see this in our GH @corey122 ?
|
|
|
|
```
|
|
We found potential security vulnerabilities in your dependencies.
|
|
Some of the dependencies defined in desktop_files/package-lock.json and mobile_files/package-lock.json have known security vulnerabilities and should be updated.
|
|
|
|
Only users who have been granted access to vulnerability alerts for this repository can see this message.
|
|
Learn more about vulnerability alerts
|
|
```</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-10 04:50</div><div class="msg">ah, I gave you access to vulnerability alerts on GH, should be visible now
|
|
|
|
e.g <a href="https://github.com/status-im/status-react">https://github.com/status-im/status-react</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-10 09:35</div><div class="msg">check out this piece from cory fields:
|
|
|
|
<a href="https://medium.com/@coryfields/http-coryfields-com-cash-48a99b85aad4">https://medium.com/@coryfields/http-coryfields-com-cash-48a99b85aad4</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-10 11:46</div><div class="msg">I see it now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-10 11:46</div><div class="msg">thank you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-10 17:43</div><div class="msg"><a href="https://twitter.com/find_evil/status/1027972886034710528">https://twitter.com/find_evil/status/1027972886034710528</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-10 17:44</div><div class="msg">I see you already opened a ticket for that one, and it's gone stale on SOB, so I added a comment and am gonna see if I can get some life into it...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-13 06:08</div><div class="msg">@jakub can you please take a look today at email `Another security report!` about `Git repository found`? I would not treat that as a security issue because it's an open source project and it's available for anyone anyway. @corey122 did you get that email? Not sure if someone was able to add you to `security@`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-13 06:36</div><div class="msg">@corey122 FYI here is a list of reported security issues <a href="https://docs.google.com/spreadsheets/d/15f3rkXK9hzgIKMrhxJw8h1hHhRMoSYNxpA2fzBBcKBU">https://docs.google.com/spreadsheets/d/15f3rkXK9hzgIKMrhxJw8h1hHhRMoSYNxpA2fzBBcKBU</a>. We have two pending, one of them I describe above and one more is related to text injection in 404 pages due to default having default Apache 404 pages</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-13 09:12</div><div class="msg">it's a bit of an annoying one imo, but we should probably respond. Perhaps make it smallest possible reward? or nothing, if we think that's more appropriate.
|
|
|
|
@corey122 would you mind replying to them?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 10:35</div><div class="msg">Me and @jakub talked about it, there is no security threat whatsoever. Not sure about a reward on this one, but I'd like to continue him looking for things.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 10:35</div><div class="msg">thoughts on response?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 10:36</div><div class="msg">While it is good practices to do what he says, it doesn't really matter in this scenario, and Jacob is going to be redoing that anyway.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 10:36</div><div class="msg">oh I didn't know that, i will look into them today, thank you.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-13 10:37</div><div class="msg">We can reply with that. For git we assume all our projects to be open source so it's not a threat </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 10:40</div><div class="msg">that as well. I will send the message</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-13 11:03</div><div class="msg">I?m not sure if this is an issue, but wanted to flag it here. Today we discovered that one of our dependencies calls home <a href="https://github.com/status-im/status-react/issues/5465">https://github.com/status-im/status-react/issues/5465</a>
|
|
|
|
It looks like we can fix this particular issue by setting a flag, but is this widespread? Something that we should audit and look out for?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 11:14</div><div class="msg">yes, I feel we should know when things are calling out, and in what scenarios they encompass.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 11:17</div><div class="msg">The fix is appropriate. potentially we could have some type of config window that opts in/out these things. I have it on my todo list to run wireshark on the desktop app to find all odd calls and address them.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-13 11:18</div><div class="msg">Ok great. And mobile too?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 11:18</div><div class="msg">yes, just more low hanging fruit with the desktop</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-13 11:20</div><div class="msg">Mobile has a few thousand users and desktop has a handful of status org users. So the severity and exposure is definitely on the mobile side</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 11:31</div><div class="msg">very much so... I asked if people have objections to running my old job's product on the app in #mobile-app. Let's see how that goes, and I could get that done today.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 11:31</div><div class="msg">also, thank you for submitting this issue in the first place, it helps me greatly.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-13 11:32</div><div class="msg">:+1:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-13 14:51</div><div class="msg">@corey122 <a href="https://github.com/status-im/status-react/pull/5479">https://github.com/status-im/status-react/pull/5479</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-13 15:21</div><div class="msg">approved, OCD kicked in with the single space :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-14 03:47</div><div class="msg">Open letter to the Hacker Community. ? Marc's Security Ramblings
|
|
<a href="http://marcrogers.org/2018/08/13/open-letter-to-the-hacker-community/">http://marcrogers.org/2018/08/13/open-letter-to-the-hacker-community/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-14 20:15</div><div class="msg">Who created this? I'd like to know the conversation around the one that hasn't been resolved if that exists</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-14 20:15</div><div class="msg">the 404 page one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-14 20:21</div><div class="msg">@oskarth any idea?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-14 20:59</div><div class="msg">I know details. I will try to find the original email and forward it to you </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-14 21:04</div><div class="msg">thank you, I'd like to squash this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-14 22:47</div><div class="msg"><a href="https://twitter.com/notgrubles/status/1029416966619103234?s=12">https://twitter.com/notgrubles/status/1029416966619103234?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-14 22:52</div><div class="msg">that referring to gun sirer's implementation?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-14 22:53</div><div class="msg">yes, and the twitter comment trying to rhyme his name is hilarious</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-14 22:55</div><div class="msg">:stuck_out_tongue_winking_eye:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-15 16:15</div><div class="msg">fun (probably not fun) security reading for today, a presentation on threat modeling. The slide formatting is simplistic and ugly but the message is simple and understandable. It is centered around centralized thinking, but the take-aways are great: <a href="https://users.encs.concordia.ca/~clark/courses/1601-6150/scribe/L04c.pdf">https://users.encs.concordia.ca/~clark/courses/1601-6150/scribe/L04c.pdf</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-15 19:45</div><div class="msg">what is testfairy and who handles the keys to it.. i've found a secret_key in old git commits.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-15 19:46</div><div class="msg"><a href="https://github.com/status-im/status-react/blob/27b3f1b87b1408da7fd2e4f1a20a5ca69a0b863a/.env">https://github.com/status-im/status-react/blob/27b3f1b87b1408da7fd2e4f1a20a5ca69a0b863a/.env</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-15 19:46</div><div class="msg">that is only for builds that QAs use
|
|
but hopefully the key is changed... but we need to check</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-15 19:49</div><div class="msg">mixpanel and instabug are also on there... we should check those tokens as well, although we no longer use mixpanel.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-15 20:08</div><div class="msg">thats a great resource.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-15 20:27</div><div class="msg">Agree, this kind of info should be passed from somewhere outside the repo</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-15 21:34</div><div class="msg">for something like mixpanel id, there's no real difference if it's in the source or not - it ends up in the in the binary where it can be trivially read.. arguably, it's more honest to put it in the source at that point</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-16 05:50</div><div class="msg"><a href="https://twitter.com/stephendpalley/status/1029732345098764288?s=12">https://twitter.com/stephendpalley/status/1029732345098764288?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-08-16 06:19</div><div class="msg">This is an issue not only with crypto. In Poland there were recently a few cases where attackers managed to duplicate a SIM card and stole money from bank accounts.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-16 14:06</div><div class="msg">I called my provider and specifically told them to put a note on my account that does not allow me to do that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-16 21:56</div><div class="msg"><a href="https://twitter.com/mikeraymcdonald/status/1030151732859428864?s=12">https://twitter.com/mikeraymcdonald/status/1030151732859428864?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-17 12:27</div><div class="msg"><a href="https://boingboing.net/2018/08/16/who-left-open-the-cookie-jar.html">https://boingboing.net/2018/08/16/who-left-open-the-cookie-jar.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-17 14:39</div><div class="msg"><a href="https://duo.com/decipher/dissecting-security-hardware-at-black-hat-and-def-con">https://duo.com/decipher/dissecting-security-hardware-at-black-hat-and-def-con</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-17 21:40</div><div class="msg"><a href="https://twitter.com/antitree/status/1025122856584335361?s=12">https://twitter.com/antitree/status/1025122856584335361?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-17 21:50</div><div class="msg">sandboxing javascript <a href="https://twitter.com/agoric/status/1030569395305603072?s=12">https://twitter.com/agoric/status/1030569395305603072?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-17 21:58</div><div class="msg">and tried to stab EVERYTHING</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-18 05:51</div><div class="msg"><a href="https://twitter.com/kennyog/status/1030584058206552064?s=12">https://twitter.com/kennyog/status/1030584058206552064?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-19 13:34</div><div class="msg">How do we do random number generation, wherever we do it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-19 13:46</div><div class="msg">Mobile: for keys, we use either go-ethereum or platform functions. I?m interested though where unsafe randoms issue in Android comes from</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-09/326673504257_0c3a20675ee30675e2c5_72.png" /><div class="message"><div class="username">eugene.kabanov</div><div class="time">2018-08-19 15:53</div><div class="msg">Nimbus using system CSPRNG:
|
|
* Windows - `BCryptGenRandom` (if available), `CryptGenRandom` (if available), `RtlGenRandom`.
|
|
* Linux/Android - using `genrandom` (if available), `/dev/urandom`.
|
|
* Macos/iOS - using `/dev/urandom`.
|
|
* BSDs - using `/dev/urandom`.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-08-20 21:17</div><div class="msg">One of the greatest information security sins in the industry is that to this day every mainstream desktop operating system is still giving any application unrestricted access to all user data by default ? in 2018, more than 3 decades after the first implementations of mandatory access control/host-based application firewalls.
|
|
|
|
There is no technical reason why applications couldn't come with predefined profiles for the resources they require access to and have those enforced by the operating system by default so that a remote code execution vulnerability or a rogue/malware-infected application doesn't automatically mean potential disaster. Tools like this do in fact exist, but they are by no means trivial to use and completely inaccessible to the average user.
|
|
|
|
Here's one for macOS that I have been using for close to two years now for anyone who might be interested in trying it out:
|
|
|
|
<a href="https://campaigns.f-secure.com/xfence/">https://campaigns.f-secure.com/xfence/</a>
|
|
|
|
It's F-Secure's X-Fence ? essentially a re-brand of Jonathan Zdziarski's Little Flocker, which F-Secure acquired some time ago.
|
|
|
|
It's definitely a hassle the first few days/weeks until one has figured out the right trade-off between usability and security, but I consider something like this essential for a secure workstation. If anyone decides to check it out, I'm available if you have any questions about setup / day to day usage.
|
|
|
|
I'd love to see a predefined configuration / set of rules for this, adapted to a developer's workflow to reduce the initial investment to a minimum and maybe have people actually use it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-08-20 21:26</div><div class="msg">Thoughts/corrections/criticisms/links to related internal discussions/documents?
|
|
|
|
Snippet moved to #core-security:
|
|
<a href="https://status-im.slack.com/archives/GCDGY32EB/p1534869675000100">https://status-im.slack.com/archives/GCDGY32EB/p1534869675000100</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-20 21:38</div><div class="msg">I'd invite you to take a look at the following two compendiums (both works in progress / open to editing):
|
|
|
|
? <a href="https://hackmd.io/mMXVubGDQaWjCf6etQ6nuA#">https://hackmd.io/mMXVubGDQaWjCf6etQ6nuA#</a> about coercion resistance - the "start here" link is really a good starting point
|
|
? <a href="https://hackmd.io/2MDws3OvSZ2wz-ULI6tpLQ?both#">https://hackmd.io/2MDws3OvSZ2wz-ULI6tpLQ?both#</a> goes over secure messaging in general
|
|
|
|
@corey122 you might be interested in these also :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-20 21:50</div><div class="msg">Very, thank you.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-20 22:59</div><div class="msg">Regarding the translation of Pyramid of Pain to dentralized context, I agree is indeed totally different, however it SHOULD be much more simplier "pyramid" then in web2, and in a fast thinking I would sum in "TTPs, Tools, ENS(?), and hashes". Network artifacts and IP address become irrelevant as this both two become one and "cancel itself risks".
|
|
|
|
I am happy to discuss more about this, btw is first time im learning about Pyramid of Pain and it logically makes sense</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-21 02:18</div><div class="msg">Regarding Personal attacks and Scams..
|
|
6 jul someone requested to reset my <a href="http://gate.io">http://gate.io</a> password, which I don't use, I registered this and never used.
|
|
10 jul I received a email from miningpool <a href="http://suprnova.cc">http://suprnova.cc</a> for ETH and ZEC stating my account "auto-locked" due too many pin attempts, however there was no funds in this pool accounts, I also created and never used them. Strange that both happen exactly at the same time.
|
|
Strange that the email was not sent by <a href="http://suprnova.cc">http://suprnova.cc</a>, but instead ` from <a href="http://fr-db1.sup.rnova.cc">http://fr-db1.sup.rnova.cc</a> (<a href="http://fr-db1.sup.rnova.cc">http://fr-db1.sup.rnova.cc</a>. [46.105.114.185])`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-21 06:36</div><div class="msg">youre about half as paranoid as some devops people i've worked with, george. i like the todos very much, particularly onboarding standards and EOL device /os purging. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-08-21 09:58</div><div class="msg">Oh, this is just the tip of the iceberg of crazy, I'm just used to letting it out one bit at a time so as to not freak out sane people. No need to worry about that here, clearly, so point taken. :slightly_smiling_face:
|
|
|
|
So what would be a good next step for something like this ? discuss.status? (After reading up on the related documents to make sure there's no unneccessary overlap)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-21 11:12</div><div class="msg">@george952 imo, we dont need a discussion about if, we need suggestions for what to do; my suggestion: start compiling some best practices documents on hackMD with @corey122 , THEN make a discuss post linking to them as collaborative documents which will be put up on people-ops handbook once you have consensus and input from core contributors. set a timeframe and deadline for deliverable doc; once they are up on the handbook, do a blogpost about it. Dont aim for perfect standards / best practices, aim for "doable" ... then we'll iterate forward. cc: @ceri @stefania </div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-21 11:33</div><div class="msg">I wonder if we shouldn't be more careful about this type of discussions until a solution is found because #watercooler channel for instance is also public, but hopefuly slack doesn't share files through the bridge with riot so your doc isn't visible <a href="https://status-im.slack.com/archives/C846J9HTJ/p1534850172000100">https://status-im.slack.com/archives/C846J9HTJ/p1534850172000100</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-21/367025375940_c77cc650cdbe3bf5be5f_72.jpg" /><div class="message"><div class="username">ceri</div><div class="time">2018-08-21 11:38</div><div class="msg">Ready to help with posting to the handbook / giving guidance on blogging when the time comes! :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-21 12:36</div><div class="msg">I guess smart contracts have their own :small_red_triangle:of pain or they fit inside some other context?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-08-21 12:51</div><div class="msg">@exiledsurfer Yup, I wasn't planning on just throwing it out there without a concrete plan for moving forward, but this is definitely helpful, thank you.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-08-21 12:55</div><div class="msg">I agree that this is probably not a conversation that should be held in public at this point.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-08-21 12:55</div><div class="msg">Is there a document on which Slack channels are public / bridged with riot?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-21 12:56</div><div class="msg">I think there is a way to know that @naghdy might know ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-21 13:18</div><div class="msg">I've been advocating for those channels to be marked `-riot` but not all are - jungle lore I think</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-21 13:19</div><div class="msg">the alternative, which perhaps makes more sense, is to flip the coin and name the channels that are private, defaulting to public/bridged</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-21 15:55</div><div class="msg">This has been discussed time and time again. The argument is that we shouldn't be having conversations that are 'public' in Slack, but are not public to the entire community. The best option imo is to create a private Slack channel that you can guarantee is private (as you would likely do when we migrate to Slack). e.g. a #security-core Slack channel that has the relevant people included.
|
|
|
|
There are people getting added and removed from Slack all the time. Assume there is always ~10 people who aren't status core contributors who are around.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-08-21 16:20</div><div class="msg">I just went ahead and created the invite only #core-security, inviting everyone in this thread and Corey. If everyone's okay with that, just go ahead and add everyone you think needs to be in it.
|
|
|
|
I don't think we need to mark them explicitly as private channels are recognisable as such from the lock symbol instead of the `#`.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-21 16:23</div><div class="msg">agree. Thanks @george952!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-08-21 16:26</div><div class="msg">I think we should add a note to the handbook that for all intents and purposes `#`-channels should be generally assumed to be public, because it's certainly not as obvious as it should be. Any thoughts on this before we tag PeopleOps?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-21 16:29</div><div class="msg">Good idea. @ceri see ^ for something we can add about Slack usage :slightly_smiling_face:.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-21 16:32</div><div class="msg">how should it be formulated though ? "keep in mind that anything posted on slack is publicly available, use private channels if you have to say something that should only be seen by status core contributors and actors that gained access to these channel by legal or illegal means" ?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-21 16:34</div><div class="msg">I mean when you really think about it there is no such thing as a clear dichotomy between public or private. Even once we migrate to Status it will only give end to end privacy but the endpoints can still be compromised</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-21 16:35</div><div class="msg">There's very few topics imo that should be restricted.
|
|
1. Anything that has PII (finance, HR, recruiting, etc.)
|
|
2. Security vulnerabilities that threaten our network
|
|
3. Marketing/business/partnerships under embargo
|
|
|
|
imo - having private discussions should be an exception, and we should be highlighting that all conversations and work is done in the public arena</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-21 20:40</div><div class="msg">USBHarpoon Is a BadUSB Attack with A Twist
|
|
<a href="https://www.bleepingcomputer.com/news/security/usbharpoon-is-a-badusb-attack-with-a-twist/">https://www.bleepingcomputer.com/news/security/usbharpoon-is-a-badusb-attack-with-a-twist/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-22 15:33</div><div class="msg">
|
|
|
|
"The protocol is designed in a way that limits the server-side [authentication service (AS) and DS] metadata footprint," the document said. "The DS must only persist data required for the delivery of messages and avoid Personally Identifiable Information (PII) or other sensitive metadata wherever possible. A Messaging Service provider that has control over both the AS and the DS, will not be able to correlate encrypted messages forwarded by the DS, with the initial public keys signed by the AS."
|
|
|
|
<a href="https://www.theregister.co.uk/2018/08/22/ietf_draft_proposes_encrypted_message_security_for_all/">https://www.theregister.co.uk/2018/08/22/ietf_draft_proposes_encrypted_message_security_for_all/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-23 14:25</div><div class="msg">@corey122 I'd really love if you take a look at that PR
|
|
<a href="https://github.com/status-im/status-react/pull/5617">https://github.com/status-im/status-react/pull/5617</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-23 14:26</div><div class="msg">Will do, give me a bit though, I have furniture being delivered right now.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-23 14:27</div><div class="msg">it's wip, so it won't be merged today anyways :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-23 14:30</div><div class="msg">Ok great then I'll dig in today after these guys leave. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-08-24 15:01</div><div class="msg">@corey122 also we have this as one of the top Wall Of Shame entries
|
|
> 2. Weak certificate checks
|
|
|
|
so MITM is pretty possible now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-05/252830689991_12aab4b68577596e7564_72.png" /><div class="message"><div class="username">gdoly</div><div class="time">2018-08-24 15:25</div><div class="msg"><a href="https://status-im.slack.com/archives/C8QP8S5UH/p1535120353000100">https://status-im.slack.com/archives/C8QP8S5UH/p1535120353000100</a>
|
|
Unfortunately, their email is in German:
|
|
"Lieber Yessin
|
|
|
|
Ich hoffe bei euch l�uft auch im Sommer alles bestens!
|
|
|
|
Ich m�chte dir Robert (in CC) vorstellen, der als Kryptographie-Experte bei uns ist. Da wir nun auch Projekte im Bereich dezentraler Anwendungen, die ueber Blockchain hinausgehen verfolgen, hat sich Robert dazu zunaechst natuerlich auch Status angesehen. Ein Punkt, der bei genauerer Durchsicht des Status Protokolls aufkam, sind ein paar zentralistischere Ansaetze, als wir sie erwartet haetten aber auch ein moegliches man-in-the-middle Szenario.
|
|
|
|
Waere es moeglich, das Robert einen Call mit einem Eurer Protokoll-Designer fuehren koennte, um einige dieser Punkte zu besprechen?
|
|
|
|
Beste Gruesse aus der Post,
|
|
Sebastian"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-05/252830689991_12aab4b68577596e7564_72.png" /><div class="message"><div class="username">gdoly</div><div class="time">2018-08-24 15:27</div><div class="msg">Basically, he introduces me to Robert who is their crypto expert. Robert saw several unexpected central elements and a potential man-in-the-middle scenario.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-05/252830689991_12aab4b68577596e7564_72.png" /><div class="message"><div class="username">gdoly</div><div class="time">2018-08-24 15:28</div><div class="msg">He is asking if a call with the protocol designer would be feasible.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-24 15:57</div><div class="msg">^ @andreap @yenda @janherich (I can join the call as well probably)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-24 16:07</div><div class="msg">I'd like to be there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-24 16:08</div><div class="msg">but if he thinks it's at the protocol level then I'm curious if the certificate checks is what he's referring to</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-24 16:09</div><div class="msg">Let's try and set this up asap, what are timeframes that WONT work for everyone involved here?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-24 16:10</div><div class="msg">above folks are in europe</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-24 16:10</div><div class="msg">I don't have to be there, but can</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-05/252830689991_12aab4b68577596e7564_72.png" /><div class="message"><div class="username">gdoly</div><div class="time">2018-08-24 16:12</div><div class="msg">Keep it simple, one or two can catch up with them and record the issues to share on this channel. If there is flesh to the bone then more people can get involved still.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/8f5d17c2210ba9813f6612330fc0fc66.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0014-72.png" /><div class="message"><div class="username">janherich</div><div class="time">2018-08-24 16:13</div><div class="msg">I'm pretty flexible time-wise, so include me in the call for sure.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/4f643ff2e520e1b103a3c81fe6d4267c.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F3654%2Fimg%2Favatars%2Fava_0023-72.png" /><div class="message"><div class="username">andreap</div><div class="time">2018-08-24 16:20</div><div class="msg">i am also available if needed, i am missing some context though, can anyone explain what is it about?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-24 16:33</div><div class="msg">We can set up a conf call. Only MITM I can think of is if I ask you the contact code of someone and you give me yours instead and forward the conversation. I wonder what he found out</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-24 16:46</div><div class="msg">I'm with @gdoly here - good to have someone triage the issue before we go full steam</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-24 16:47</div><div class="msg">that starts with us hearing him out.. I don't want to put things on our wall of shame until we discuss it internally and assess it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-24 16:47</div><div class="msg">of course, just saying that we don't need to put 6 ppl on the call :wink:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-24 16:49</div><div class="msg">so anyway - who will follow up? I'm least qualified so I'll pass, since the rest of you are around :wink:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-24 16:52</div><div class="msg">@yenda and @corey122?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-24 16:53</div><div class="msg">or @janherich gets first dibs for answering thread early</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-25 03:14</div><div class="msg"><a href="https://discuss.status.im/t/proper-key-exchange-with-push-notification-providers/321">https://discuss.status.im/t/proper-key-exchange-with-push-notification-providers/321</a> is it this one by any chance? If so the diagram is out of date/misleading</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-25 13:12</div><div class="msg">me, @janherich, and @yenda should be ok to handle it initially.. we can escalate if need be, hopefully not.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-25 13:12</div><div class="msg">@gdoly considering you got this do you want to help set this up?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-25 13:29</div><div class="msg">I think that is it @oskarth it seems that he missed the fact that the wnode only caches encrypted messages, so a mitm would just do the same</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/8f5d17c2210ba9813f6612330fc0fc66.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0014-72.png" /><div class="message"><div class="username">janherich</div><div class="time">2018-08-25 13:34</div><div class="msg">Most probably, but let's see, maybe it's something completely else :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-25 13:37</div><div class="msg">if that's the case, it's a short call, but we'll see.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-25 13:47</div><div class="msg">I think it's in the context of the new push notifications system because the wnodes are more involved</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-25 15:06</div><div class="msg">thanks! I'll be curious to hear the outcome :wink:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-28 16:12</div><div class="msg">>Some members of the US House of Representatives are pressing for reform of the Common Vulnerabilities and Exposures database. The Department of Homeland Security has become increasingly unable to keep pace with rising demands for vulnerability information.
|
|
|
|
- The CyberWire</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-28 16:13</div><div class="msg">sorry, I'm unclear on who will set this up... has anyone taken the lead on this? I can if no one has yet.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-05/252830689991_12aab4b68577596e7564_72.png" /><div class="message"><div class="username">gdoly</div><div class="time">2018-08-28 16:26</div><div class="msg">Yes please. Thank you, @corey122</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-28 16:28</div><div class="msg">ok, i'll send out the email in a bit</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-28 16:29</div><div class="msg">thanks!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 15:46</div><div class="msg">One note : when the user is creating a status account with a hardwallet light (javacard), the current plan is to use the RNG of the javacard itself to generate the mnemonic</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-29 18:40</div><div class="msg">nice, i like moving all things to the javacard/pro</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-09/326673504257_0c3a20675ee30675e2c5_72.png" /><div class="message"><div class="username">eugene.kabanov</div><div class="time">2018-08-29 18:43</div><div class="msg">@guylouis how javacard generates random numbers? Is it uses opensource solution, or uses some closed source chip?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 18:45</div><div class="msg">it's not open source for sure, I cc @micheleb who developed our javacard applet provide details</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-09/326673504257_0c3a20675ee30675e2c5_72.png" /><div class="message"><div class="username">eugene.kabanov</div><div class="time">2018-08-29 18:50</div><div class="msg">If it's closed source then this is a problem. Because most of the hardware closed source onchip solutions is not very trusted...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-29 19:10</div><div class="msg"><a href="https://www.securityweek.com/exploit-published-windows-task-scheduler-zero-day">https://www.securityweek.com/exploit-published-windows-task-scheduler-zero-day</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-29 19:12</div><div class="msg">tl;dr be extra weary of apps that want to change the system settings... this vuln doesn't work unless you install a malicious app on your windows machine.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 13:36</div><div class="msg">@eugene.kabanov it is a hardware Secure Random Number generator. It is closed source, like everything in smart cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 13:36</div><div class="msg">however they are certified</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-30 13:46</div><div class="msg"><a href="https://www.researchgate.net/publication/235344028_Pseudorandom_Number_Generation_in_Smart_Cards_An_Implementation_Performance_and_Randomness_Analysis">https://www.researchgate.net/publication/235344028_Pseudorandom_Number_Generation_in_Smart_Cards_An_Implementation_Performance_and_Randomness_Analysis</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-30 13:49</div><div class="msg">Note: published in 2012...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 13:52</div><div class="msg">unfortunately the chip specs are also not publicly available, so I cannot check all details. But 2011-2016 I have worked for a smartcard manufacturer, what I know is that chips have been constantly improving with regards to security aspects, including random number generator</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 13:53</div><div class="msg">so I do not know if everything in this paper is still up to date</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-30 13:53</div><div class="msg">resources as well... so the "scarcity" factor mentioned is less than it used to be</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-30 13:55</div><div class="msg">my main question would be whether the entropy source has changed over time... I'd imagine so but am not sure.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 13:57</div><div class="msg">maybe we can try to understand from the supplier which chip they are using. Main producers are ST, Infineon, NXP and Samsung. They might implement this differently</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 13:58</div><div class="msg">@guylouis did ACS give any details on the chip?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-09/326673504257_0c3a20675ee30675e2c5_72.png" /><div class="message"><div class="username">eugene.kabanov</div><div class="time">2018-08-30 13:58</div><div class="msg">It looks like PRNG (pseudo random number generator) is used, so i don't see a reason for recommendation of using javacard PRNG. The only reason to use javacard RNG is when this RNG is TRNG (true random number generator).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 13:59</div><div class="msg">I don't think it is a PRNG, the 3.0.4 API has two explicit version of RandomData: Pseudo-Random and Secure Random.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 13:59</div><div class="msg">I will ask to ACS. Just to be 100% inline can you suggest what to ask what to ask exactly ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 14:00</div><div class="msg">you can ask which chip they are using and if they use a PRNG or TRNG</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-09/326673504257_0c3a20675ee30675e2c5_72.png" /><div class="message"><div class="username">eugene.kabanov</div><div class="time">2018-08-30 14:02</div><div class="msg">and doesn't matter if it PRNG or StrongRandom (which i think can be called cryptographic secure random number generator), but it still PRNG.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-09/326673504257_0c3a20675ee30675e2c5_72.png" /><div class="message"><div class="username">eugene.kabanov</div><div class="time">2018-08-30 14:06</div><div class="msg">If chip has only PRNG or CSPRNG, then better recommendation can be to use chip RNG as entropy source and combine it with OS specific RNG to seed open-source CSPRNG.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 14:06</div><div class="msg">it could be, it has to be checked. Unfortunately I don't have access to current specs. The advantage with a SmartCard is that it has no external interface (it doesn't even know the time and runs from an externally provided clock) so it is harder to insert a backdoor there without getting caught when analysing the output of the generator. With a full-fledged device, in theory, a backdoor can be added to any generator</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 14:11</div><div class="msg">I am now checking the specs of the STM32L476 chip, which is what we are using for the prototype of the hardware wallet pro. It is not a Secure Element, yet it claims to have a TRNG. I would be surprised if a secure element chip had a PRNG instead</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-31 11:41</div><div class="msg">Regarding "the audit of smart contracts", I see smart contracts as oriented programming language easier than Java and PHP, the only major difference being that the API is always exposed, and usually upgrade (if possible) can have consequences (such as complexity, money loss, trust loss) and so should be minimized to technical improvements when strongly needed (and accumulated), similar to Ethereum hardfork process.
|
|
Before the smart contract audit we can, and should, change as we need. Changes in smart contract mostly would not impose great impact in UI, which at usually would become less complete with the new features.
|
|
After audit, a change in contract, traditionally, would require a new (or upgrade/diff?) audit to responsively release the product to public.
|
|
The root feature smart contracts can provide are as *public truth* and *public asset* , any other thing in smart contracts usually is bloat that could be better stored offchain (hello hashes!). It's utility as *public authority* also becomes it's own weakness, as rules written in that system are enforced by the program itself, which better be good behaving, or...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-31 13:01</div><div class="msg">i def agree with this, particularly the before/after audit process of this. Functionality should be set and long-term at deployment, which is the appropriate time to audit considering any upgrade/change to the contract could partially/fully nullify the auditing.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-31 14:21</div><div class="msg"><a href="https://twitter.com/spudowiar/status/1035269363903946755">https://twitter.com/spudowiar/status/1035269363903946755</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-31 14:24</div><div class="msg">the console messages are wonderful</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-31 15:31</div><div class="msg">saw that yesterday & chuckled. love how saleem's been trolling them for weeks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-01 12:49</div><div class="msg"><a href="https://www.reddit.com/r/announcements/comments/9bvkqa/_/">https://www.reddit.com/r/announcements/comments/9bvkqa/_/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-01 12:50</div><div class="msg">Guess they never looked at crypto subreddits before...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-03 09:00</div><div class="msg">so ACS (preferred supplier for our hwallet light) confirmed that it's TRNG embedded in the javacard, like michele presumed.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-05 04:27</div><div class="msg"><a href="https://wiki.mozilla.org/Security/Binary_Transparency">https://wiki.mozilla.org/Security/Binary_Transparency</a></div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/6e12ebcea03f27a40c66e503f89be217.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">cologic</div><div class="time">2018-09-05 15:02</div><div class="msg">A good way (plus open source, etc) of ensuring that updates (necessary for security, etc) don't become a law enforcement backdoor mechanism.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-06 08:04</div><div class="msg">Sharing with deterministic builds swarm. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-06/430098664084_d320a9b17f9da6b75744_72.png" /><div class="message"><div class="username">easye</div><div class="time">2018-09-06 11:33</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-07 13:52</div><div class="msg">Trying to find out what is was they reported and where..</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-07 14:14</div><div class="msg">I have not seen this. How did they report it? How can I get in contact with them?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-07 14:15</div><div class="msg"><mailto:Security@status.im|Security@status.im> </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-07 14:15</div><div class="msg">That?s where he said he reached out </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-07 14:16</div><div class="msg">He?s chatting in our telegram <a href="https://t.me/StatusNetworkChat">https://t.me/StatusNetworkChat</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-07 14:16</div><div class="msg">I will join that now. Thanks. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-07 14:27</div><div class="msg">Thanks @corey122!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-01-24/304281668629_99d09ae86c8e0a04b52d_72.png" /><div class="message"><div class="username">growbot</div><div class="time">2018-09-07 14:28</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-07 14:28</div><div class="msg">Kudos @corey122 for jumping into a security question so quickly.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-07 14:44</div><div class="msg">Kudos @hutch for relaying. It seems like it was stuck in spam or something for some reason :confused:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-08 10:38</div><div class="msg">big ups to @hutch</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-09 05:05</div><div class="msg">Quite interesting to skim through these security reports by Trail of Bits, especially "Severity: High" ones. It might seem daunting but if you focus on the juicy bits it doesn't take that much time, and you can go deeper as guided by curiosity.
|
|
|
|
<a href="https://www.trailofbits.com/reports/sai.pdf">https://www.trailofbits.com/reports/sai.pdf</a>
|
|
<a href="https://www.trailofbits.com/reports/livepeer.pdf">https://www.trailofbits.com/reports/livepeer.pdf</a>
|
|
<a href="https://www.trailofbits.com/reports/RSKj.pdf">https://www.trailofbits.com/reports/RSKj.pdf</a>
|
|
|
|
Gives you some intuition of the class of things that can go wrong. For example, I didn't realize there was (is?) a race condition security flaw in the ERC20 API. Also minor things like the fact that block hashes can't be used as a source of randomness.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-09-09 08:23</div><div class="msg"><a href="https://twitter.com/Fluffyratz/status/1038582045830774785">https://twitter.com/Fluffyratz/status/1038582045830774785</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-09-09 08:24</div><div class="msg">Someone on twitter questioning our security :scream:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-09-09 08:58</div><div class="msg">I think we specifically don't recommend ppl to keep large amounts of assets in Status right now. But I asked him a question. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-09/311993097408_4a03c687a383ac3bfb71_72.jpg" /><div class="message"><div class="username">stefania</div><div class="time">2018-09-11 10:49</div><div class="msg">Hi all! Sorry for the invasion :simple_smile:
|
|
|
|
As mentioned in the TH yesterday - it would be amazing if each team could spend some time thinking about how the principles relate to the specifics of their work, and writing their own versions of that - it's a way to make it easier for us all to stay truthful to what we want to do, and to find answers when the questions get hard.
|
|
|
|
We gave it a shot with our team first - and this is our doc: <a href="https://people-ops.status.im/applying-our-principles-to-people-ops/">https://people-ops.status.im/applying-our-principles-to-people-ops/</a>
|
|
|
|
We expect that -just like everything - it will keep evolving over time, and it's but a V1.
|
|
|
|
For more details and the HackMD versions for each function, please see: <a href="https://docs.google.com/document/d/17ZvEIzBM8avDOkRjbIYcex3jNoeSoNVW5_gntvV-ov4/edit#heading=h.goptamqfghgx">https://docs.google.com/document/d/17ZvEIzBM8avDOkRjbIYcex3jNoeSoNVW5_gntvV-ov4/edit#heading=h.goptamqfghgx</a>
|
|
|
|
Thanks, y?all!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-11 22:45</div><div class="msg">Registration - DeepSec IDSC 2018 Europe
|
|
<a href="https://deepsec.net/register.html">https://deepsec.net/register.html</a> friend of mine does this conference, and it's awesome</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-12 10:28</div><div class="msg">I'll start the security version of this. Do you have a specific preference on where that copy should live?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-09/311993097408_4a03c687a383ac3bfb71_72.jpg" /><div class="message"><div class="username">stefania</div><div class="time">2018-09-12 10:44</div><div class="msg">you can start it on the HackMD link - <a href="https://hackmd.io/aZV2tUmwS1udpKE_gATzcA?both">https://hackmd.io/aZV2tUmwS1udpKE_gATzcA?both</a> , and perhaps get others involved to collaborate on it. Once finalized it will live...... in many places, I expect, like the people-ops handbook, our Ghost site, etc......</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-12 11:05</div><div class="msg">I'll have to check with my schedule to see if this is appropriate... also whether or not this is something I can further expense as ethberlin and devcon cover my allotted travel.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-12 11:57</div><div class="msg">i guarantee you youll meet the highest quality of peers. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-12 21:50</div><div class="msg">@corey122 got pinged about that security email on telegram ? was it anything worth investigating or in progress? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-12 22:13</div><div class="msg">when? we've been discussing today</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-12 22:14</div><div class="msg">he just gave his address to be paid out, and @jason is CCed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-05/310886360359_5346fd4529b6d0a8ed28_72.jpg" /><div class="message"><div class="username">jason</div><div class="time">2018-09-12 22:14</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-12 22:16</div><div class="msg">I'm assuming you're referring to Akash?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-12 22:51</div><div class="msg">Yes </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-12 22:51</div><div class="msg">Ok it was earlier today he pinged me </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-13 02:11</div><div class="msg"><a href="https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html">https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-09-13 07:28</div><div class="msg"><a href="https://mobile.twitter.com/justMaku/status/1039849820226289665">https://mobile.twitter.com/justMaku/status/1039849820226289665</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-13 11:37</div><div class="msg">Yikes
|
|
<a href="https://discuss.status.im/t/personal-and-company-security-week/360/5?u=oskarth">https://discuss.status.im/t/personal-and-company-security-week/360/5?u=oskarth</a>
|
|
|
|
hope you have good backups @corey122</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-13 11:38</div><div class="msg">yeah, it's being restored to the 8th of Sept.. we only lost a few days of work.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-13 11:38</div><div class="msg">it'll be more work to figure out who the weak link was and getting them to change all their passwords associated with the hacked one.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-13 11:39</div><div class="msg">happy to be made an example of if it gets people on board this company to prevent that. I have decent enough practices to not get completely pwned (hopefully).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-13 19:06</div><div class="msg"><a href="https://twitter.com/exiledsurfer/status/1038052975451758592">https://twitter.com/exiledsurfer/status/1038052975451758592</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-13 19:15</div><div class="msg">who will watch the watchers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-05/252830689991_12aab4b68577596e7564_72.png" /><div class="message"><div class="username">gdoly</div><div class="time">2018-09-13 19:43</div><div class="msg">@corey122 Hints from the most gifted Jordi Baylina: ?1) Chose the person who does the security audit, not the audit firm! 2) Put up bug bounties to the community!?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-13 19:45</div><div class="msg">if 1.) has value, then the decision we've made for the ENS contract is a quality one.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-13 19:45</div><div class="msg">my first choice isn't available due to time constraints</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-14 03:04</div><div class="msg">there's a guy to your left and a guy to his left, and so on - it's all snake biting itself</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-09-14 06:50</div><div class="msg"><a href="https://status-im.slack.com/archives/C801W3L86/p1536907456000100">https://status-im.slack.com/archives/C801W3L86/p1536907456000100</a>
|
|
Logs with keys are being posted here and Google
|
|
<a href="https://github.com/status-im/status-react/issues/5816">https://github.com/status-im/status-react/issues/5816</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-09-14 06:50</div><div class="msg">@maxr Can we delete those logs? Make the repo private? <a href="https://github.com/status-im/status-react-desktop-reports/issues">https://github.com/status-im/status-react-desktop-reports/issues</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-11/363235195815_bbe7d055e1883e756d9b_72.jpg" /><div class="message"><div class="username">maxr</div><div class="time">2018-09-14 06:50</div><div class="msg">has joined #security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-14 08:40</div><div class="msg">Coreybourous</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-14 08:52</div><div class="msg"><a href="https://giphy.com/gifs/alternative-shame-bell-PAbB4v61QWi9W">https://giphy.com/gifs/alternative-shame-bell-PAbB4v61QWi9W</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-14 11:08</div><div class="msg">Any chance we can make the Threat Stack notifications less noisy?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-14 12:10</div><div class="msg">I'll be working on silencing unwanted messages over the next few days. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-14 12:10</div><div class="msg">It's a firehose at this point, but I wanted to see what unadulterated looked like. Lol</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-14 12:10</div><div class="msg">For instance, a lot of Jenkins stuff can be silenced. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-24/217825278711_78582e61a53927136266_72.jpg" /><div class="message"><div class="username">adamb</div><div class="time">2018-09-14 14:49</div><div class="msg">for now I used gmail filters to filter them out but that means I don't pay attention :disappointed:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-14 14:56</div><div class="msg">yeah, its part of the trial process... figuring out what it does naturally, then how it looks after the filtering is done, and then whether or not we'd like their additional service of monitoring that and reporting what they choose to be escalated issues.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-14 14:57</div><div class="msg">I'm stopping email notifications for now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-14 15:08</div><div class="msg">would anyone like access to the platform dashboard, it's quite nice, and I'm now starting to spend some time to filter out stuff we don't care about.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-14/363707704565_2e5e86c7fcaa985eacd9_72.jpg" /><div class="message"><div class="username">barry</div><div class="time">2018-09-17 21:21</div><div class="msg">Should core contributors use a VPN service?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-17 21:24</div><div class="msg">I think everyone should use a VPN service, but I don't see how being a core contributor would make that escalate to a requirement.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-14/363707704565_2e5e86c7fcaa985eacd9_72.jpg" /><div class="message"><div class="username">barry</div><div class="time">2018-09-17 21:26</div><div class="msg">any you recommend?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-17 21:27</div><div class="msg">i like privateinternetaccess personally</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2018-09-18 06:05</div><div class="msg">Can you elaborate why everyone should use a VPN?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-09-18 09:09</div><div class="msg">I'm using ExpressVPN... I did my research, but @corey122 wdyt?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 12:44</div><div class="msg">because it increases the amount of privacy you have as an individual. From a security standpoint, it decreases many things someone can do to infect your computer as well.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 12:45</div><div class="msg">yeah they're fine</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 12:46</div><div class="msg">they don't hold logs, have plenty of clients to set you up on whategver device you want, good speeds and server availability across theh globe, relatively cheap,</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 12:47</div><div class="msg">I'm also interested in this. so do you use a vpn all the times?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-14/363707704565_2e5e86c7fcaa985eacd9_72.jpg" /><div class="message"><div class="username">barry</div><div class="time">2018-09-18 13:02</div><div class="msg">Do you think some of these points are flat out wrong or at least overly paranoid? <a href="https://gist.github.com/joepie91/5a9909939e6ce7d09e29">https://gist.github.com/joepie91/5a9909939e6ce7d09e29</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 13:06</div><div class="msg">from the start, overly paranoid</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 13:07</div><div class="msg">here's a simple question: Do you prefer your user data being guaranteed to be harvested by your ISP, or possibly from a lying VPN provider?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 13:09</div><div class="msg">the IP part... wrong</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 13:11</div><div class="msg">but the point that it isn't a catch all to security and privacy is true</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 13:25</div><div class="msg">I used to have it set up on my router, but it broke and I haven't set up a new one (that plan is in action). I do use a piHole and redirect most everything to cloudflare DNS for now. I turn on and off VPN on various machines when I'm using them (I have lots of computers and stuff) and my servers runs it all the time.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 13:26</div><div class="msg">I'll add it to the security week stuff so people can walk through it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 13:26</div><div class="msg">btw, pihole is amazing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 13:27</div><div class="msg">nice, I'll check it out, thank you!
|
|
I was looking at protonvpn some weeks ago, I don't know if you have looked at it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 13:27</div><div class="msg">I haven't done a good search through of vpn providers because I just stopped when I found the one I use.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-09-18 13:58</div><div class="msg">I don't quite see the distinction tbh, if you go with an ISP that claims not to harvest or a VPN provider that claims not to harvest.. seems like the safer option is to assume your stuff is being harvested always and act accordingly - if it's not the isp or the vpn, it's the site you're visiting and its multitude of trackers - ie amazon will know your wife is pregnant before you, anyway.. it's a bit like tor back in the good old days when unencrypted pop3 was the norm - man, the things you got to see when running an exit node, simply because people thought tor was a magic security fairy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 14:00</div><div class="msg">some people don't have an option on the ISP they have, and the endpoints you go to will at least not get location data/other metadata involved with your connection.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/412069438306_115e95832b53d8b4a242_72.png" /><div class="message"><div class="username">george952</div><div class="time">2018-09-18 18:15</div><div class="msg">@george952 set the channel topic: Bridged to Riot / public channel => discussions about internal security issues and vulnerabilities should be held on #core-security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-09-18 18:23</div><div class="msg">@corey122 @jakub what happened with threatstack btw?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 18:24</div><div class="msg">we are currently in a trial with them looking at 3 of our hosts... today we had a check in call to see if they could help us with some stuff, and the trial will be over this Friday, which by then i should have a good evaluation of the platform. Would you like an invite to the platfrom to see how it look and play around with it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-09-18 18:25</div><div class="msg">hm, sure why not</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-18 18:25</div><div class="msg">incoming email invite</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-19 14:33</div><div class="msg"><a href="https://twitter.com/el33th4xor/status/1042420272488435713">https://twitter.com/el33th4xor/status/1042420272488435713</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-21 13:04</div><div class="msg">which repo is this, I'm not seeing it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-09-21 13:55</div><div class="msg">status-react - I think only those with enough github superpowers see</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-09-21 13:55</div><div class="msg">what's your github user? I can try to give you some</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-21 14:27</div><div class="msg">I shoul dhave it, because I've seen those before</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-21 14:27</div><div class="msg">yep, all good</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-03-08/150717543185_46c3b78ed6fd88d4b338_72.jpg" /><div class="message"><div class="username">anna</div><div class="time">2018-09-27 11:27</div><div class="msg">@corey122 what does `a pin on the account` mean in <a href="https://hackmd.io/w05YbPzJSHG1lnS5fSS4Eg">https://hackmd.io/w05YbPzJSHG1lnS5fSS4Eg</a> ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-27 13:13</div><div class="msg">a security pin that is required to be recited to change something on the account</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-27 13:13</div><div class="msg">like your 4-6 digit pin you use for your debit card... similar situation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-27 13:15</div><div class="msg"><a href="https://www.buzzfeednews.com/article/nicolenguyen/how-to-prevent-mobile-account-hacking">https://www.buzzfeednews.com/article/nicolenguyen/how-to-prevent-mobile-account-hacking</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-09-28 08:43</div><div class="msg">PIN to sim card, yes, thats indeed a good reminder, as everyone nowadays use the smart phone to lock.
|
|
However, I am personally against the use of SMS as recovery option, as it can be easily attacked by bribing a worker at mobile company, happens a lot in Brazil, recently this was used to hack into Facebook accounts related to candidates in presidential election.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 14:05</div><div class="msg">you are absolutely right, but some things don't give you an option. The PIN to the sim is a way for you to have out of band security with your cell phone provider so that your SIM or account can't be ported by an attacker</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 17:57</div><div class="msg"><a href="https://thehackernews.com/2018/09/facebook-account-hack.html">https://thehackernews.com/2018/09/facebook-account-hack.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-29/291837550193_7c75b6459537f373c8e1_72.jpg" /><div class="message"><div class="username">igor680</div><div class="time">2018-09-28 19:57</div><div class="msg">Also Facebook earlier this week: <a href="https://9to5mac.com/2018/09/28/facebook-ad-targeting-2fa/">https://9to5mac.com/2018/09/28/facebook-ad-targeting-2fa/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-28 20:55</div><div class="msg"><a href="https://www.bloombergquint.com/gadfly/bitcoin-security-does-not-depend-on-strength-or-government#gs.dtgKdKE">https://www.bloombergquint.com/gadfly/bitcoin-security-does-not-depend-on-strength-or-government#gs.dtgKdKE</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-30 12:50</div><div class="msg">A Modest Privacy Protection Proposal ? Jameson Lopp
|
|
<a href="https://medium.com/@lopp/a-modest-privacy-protection-proposal-5b47631d7f4c">https://medium.com/@lopp/a-modest-privacy-protection-proposal-5b47631d7f4c</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-30 14:05</div><div class="msg">what a fantastic article from Lopp</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-30 16:23</div><div class="msg">yeah, @corey122; thought u could integrate a lot of it with your security week / peopleops handbook</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-30 16:27</div><div class="msg">I will be, thank you. </div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/6e12ebcea03f27a40c66e503f89be217.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">cologic</div><div class="time">2018-09-30 16:27</div><div class="msg">My critique is the lack of distinction between expensive ($15k/year is on the order of 1/2 or 1/3 of the median individual American income; median family/taxpayer-unit income is ~$50k/year) mediations and inexpensive/cheap mediations. They're just randomly scattered, and he even more or less leads with the LLC stuff. Sure, good idea, but but he only gets to more widely practical things -- using cash, using adblocking, etc -- near the end.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/6e12ebcea03f27a40c66e503f89be217.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">cologic</div><div class="time">2018-09-30 16:28</div><div class="msg">And he doesn't formally consider any particular threat model with regard to any specific approach. Of his four proposed threat models, which ones do which privacy proposals address?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/6e12ebcea03f27a40c66e503f89be217.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">cologic</div><div class="time">2018-09-30 16:28</div><div class="msg">It's borderline unactionable as written.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/6e12ebcea03f27a40c66e503f89be217.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">cologic</div><div class="time">2018-09-30 16:29</div><div class="msg"><a href="https://money.cnn.com/2018/05/22/pf/emergency-expenses-household-finances/index.html">https://money.cnn.com/2018/05/22/pf/emergency-expenses-household-finances/index.html</a></div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/6e12ebcea03f27a40c66e503f89be217.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">cologic</div><div class="time">2018-09-30 16:32</div><div class="msg">HTTPS everywhere is nice, but may create more of a trace than the other way around given the rapid shift by websites to requiring HTTPS regardless -- tradeoff between fingerprinting (panopticlick, bits of entropy per detected browser feature/property/etc by which HTTPS Everywhere reveals itself) and SSL. Again, muddy thinking on threat models.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-10-01 19:59</div><div class="msg">Key pairing over BN-curves ? ASecuritySite: When Bob Met Alice ? Medium
|
|
<a href="https://medium.com/asecuritysite-when-bob-met-alice/key-pairing-over-bn-curves-4ab4d032738a">https://medium.com/asecuritysite-when-bob-met-alice/key-pairing-over-bn-curves-4ab4d032738a</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-01 20:27</div><div class="msg">I like Bob's tophat</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-01 20:27</div><div class="msg">also, straightforward explanation of the concepts used.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-01 20:28</div><div class="msg">the math can get hairy quickly when you dive into it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-10-01 21:01</div><div class="msg"><a href="https://youtu.be/W6OaYPVueW4">https://youtu.be/W6OaYPVueW4</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-02 15:29</div><div class="msg">have been evaluating web-app managers lately. I've come to the conclusion that <a href="http://wavebox.io">http://wavebox.io</a> takes the cake, and will be adding tuts and reasons for them into security week.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-02 15:29</div><div class="msg">thank you @george952 for the rec... it's far superior than others I've tried.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-10-03 13:30</div><div class="msg">heya. I?m doing a little tool to archive our slack and make it browsable. aside from private channels are there any that should be private?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-03 13:39</div><div class="msg">as far as I know, everything is public domain unless it is in a DM or private channel</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-03 13:39</div><div class="msg">but there are a tremendous amount of channels, and I can't account for everyone's use of them appropriately</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-10-03 13:43</div><div class="msg"><a href="https://status-im.github.io/slack-export-viewer/">https://status-im.github.io/slack-export-viewer/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-10-03 13:43</div><div class="msg">a lot of channels!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-03 13:45</div><div class="msg">@jakub</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-03-08/150717543185_46c3b78ed6fd88d4b338_72.jpg" /><div class="message"><div class="username">anna</div><div class="time">2018-10-03 16:00</div><div class="msg">besides #security? :slightly_smiling_face: imo all bridged to riot is public, however #instabug contained users email before we removed this filed from integration? also in some other channels like #core-wallet or #core-releases we were sharing some logs, including geth.log of the users for extra investigation of the issues that might contain some user-private data?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-10-03 16:01</div><div class="msg">I killed the slack archive, but will bring it back once it is behind a Google Auth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-10-03 19:45</div><div class="msg">hey @chad, what if the slack exporter wrote the thing in mailbox format? so as to import the conversations back into status? this is very close to what the bridge would do as well.. @noman</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-03 19:47</div><div class="msg">so slack `#<channel>` pushes messages to status `#status-<channel>`?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-10-03 19:48</div><div class="msg">well, that's already being worked on, afaik.. ie a riot-status bridge (not slack).. what I mean is that the archive, that contains a whole bunch of work that we've spent a lot of time, effort and money producing, could perhaps be available through status as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-10-03 20:01</div><div class="msg">could it be done via matrix; if we want to do it, think of all the others in our ecosystem who would want to. a classic use case of dataportability. would be awesome to have this scripted and available to draw people in behind us into the void.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-10-03 21:33</div><div class="msg">Behold: the "cryptocosm"
|
|
|
|
<a href="https://twitter.com/stanfordvideo/status/1044287366041501697?s=21">https://twitter.com/stanfordvideo/status/1044287366041501697?s=21</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-10-05 09:11</div><div class="msg">@corey122 not sure if this has been on your radar but have you seen this repo for universal links? <a href="https://github.com/status-im/universal-links-handler">https://github.com/status-im/universal-links-handler</a>
|
|
|
|
It is responsible for get <a href="http://get.status.im">http://get.status.im</a> domain which handles universal links <a href="https://wiki.status.im/Universal_Links">https://wiki.status.im/Universal_Links</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-05 12:41</div><div class="msg">? something particular about this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-05-14/363707704565_2e5e86c7fcaa985eacd9_72.jpg" /><div class="message"><div class="username">barry</div><div class="time">2018-10-09 10:16</div><div class="msg"><a href="https://medium.com/spankchain/we-got-spanked-what-we-know-so-far-d5ed3a0f38fe">https://medium.com/spankchain/we-got-spanked-what-we-know-so-far-d5ed3a0f38fe</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-09 12:53</div><div class="msg">I'm glad it wasn't catastrophic, and they'll be able to potentially fix issues and make the tech more robust</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-09 12:53</div><div class="msg">this was only a matter of time</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-10-10 06:55</div><div class="msg">Status generates universal links and they are served from this server. UL have the ability to open Status and deep link to a view within the app. Could be nasty if this was compromised. Thought it could be good for you to be aware</div></div></div><br/>
|
|
</div></body></html> |