openbmc.lists.ozlabs.org archive mirror
 help / color / mirror / Atom feed
* Security Working Group Meeting - Wed 14 October
@ 2020-10-13 19:06 Parth Shukla
  2020-10-15 14:14 ` Security Working Group Meeting - Wed 14 October - results Joseph Reynolds
  0 siblings, 1 reply; 4+ messages in thread
From: Parth Shukla @ 2020-10-13 19:06 UTC (permalink / raw)
  To: openbmc

[-- Attachment #1: Type: text/plain, Size: 1126 bytes --]

This is a reminder of the OpenBMC Security Working Group meeting scheduled
for this Wednesday October 14 at 10:00am PDT.

We'll discuss the following items on the agenda
<https://docs.google.com/document/d/1b7x9BaxsfcukQDqbvZsU2ehMq4xoJRQvLxxsDUWmAOI/edit>,
and anything else that comes up:

   1. (Joseph): Follow up from 2020-8-19: Gerrit code review: BMCWeb webUI
   login change: https://gerrit.openbmc-project.xyz/c/openbmc/bmcweb/+/35457
   Question: What are the security risks of using the proposed config flag
   BMCWEB_INSECURE_ENABLE_UNAUTHENTICATED_ASSETS=YES?
      1. Fingerprinting (leak information about the BMC’s manufacturer and
      version).
      2. Attackers have an easier time getting the code to find and exploit
      security bugs.
      3. May make DoS easier.
      4. More?
   2. (Joseph): Per
   https://lists.ozlabs.org/pipermail/openbmc/2020-October/023530.html do
   we agree on the approach?  What security categories seem most important?

Access, agenda and notes are in the wiki:
https://github.com/openbmc/openbmc/wiki/Security-working-group

Regards,
Parth

[-- Attachment #2: Type: text/html, Size: 1899 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2020-10-15 15:54 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-10-13 19:06 Security Working Group Meeting - Wed 14 October Parth Shukla
2020-10-15 14:14 ` Security Working Group Meeting - Wed 14 October - results Joseph Reynolds
2020-10-15 14:22   ` Security Working Group Meeting - Wed 14 October - request for security bug tracker Joseph Reynolds
2020-10-15 15:53     ` krtaylor

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).