14:07:08 #startmeeting Sec Group 05/10 14:07:08 Meeting started Wed Oct 5 14:07:08 2016 UTC. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:07:08 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:07:08 The meeting name has been set to 'sec_group_05_10' 14:07:21 #topic agenda 14:07:25 #link https://etherpad.opnfv.org/p/opnfv-sec-meetings 14:07:35 please add if you wish.. 14:07:58 #topic anteater 14:08:07 thanks for testing Sona_ 14:08:12 good that you got it working 14:08:28 you are very welcome 14:08:37 now that gerrit will be mirrored to > github, it uses the github API now instead. 14:08:50 this means folk can easily use it outside of opnfv, which is good 14:08:59 is there any OPNFV project you want me to run anteater? 14:09:28 you don't have to do that, its fun to just pick random projects off github 14:09:44 just someones username and do.. 14:09:48 ok 14:10:03 anteater clone --ghuser linustorvalds 14:10:13 anteater scan all 14:10:26 haha 14:10:30 and that will scan all of linus'es github repositories 14:10:38 wow 14:10:40 in time we will be able to do: 14:10:47 anteater clone opnfv 14:10:50 that would be good 14:10:56 anteater scan all 14:11:35 Do you think its worth sharing back with the linux foundation? 14:11:50 I think it is 14:12:02 yes, I think so 14:12:11 will do, Sona_ could you email me a contact there that you spoke with before? 14:12:27 Yes, I will 14:12:46 I think Davia A wheeler would be good one to start with 14:12:50 thanks..in time I want to get some of the LF badge checks in there too. 14:12:57 I will give you his contact info 14:13:25 thx 14:16:46 irc client froze 14:16:48 back 14:16:56 #topic security scanning 14:17:11 I feel bad, but nothing new again yet, but poised to start tomorrow 14:17:42 Ashlee said on twitter that she is hacking the code, so will be interesting to see what she comes up with too. 14:17:57 anything new from yourself serverascode (totally ok if not) 14:20:33 k :) 14:20:50 #topic protection of keys 14:21:10 Ashlee was due to talk on this, but not sure she could make it today 14:22:10 We spoke to the TSC about this and they want us to investigate into advising on what can be safely stored in our repos 14:22:39 I saw some emails regarding keys issue, I didn't have time to follow all conversations 14:23:31 Ok, so you and Ashlee are looking at this 14:23:51 yep, basically people were storing private keys in repos. 14:24:14 one of them was to access a fuel server, which was really bad 14:24:34 another for accessing a Tor switch 14:25:07 ok I think we are done, unless AOB? 14:25:59 Not from me 14:26:17 I am ok too 14:33:01 k, bye all 14:33:05 #endmeeting