<@q5sys:matrix.org>
15:00:36
!startmeeting
<@meetbot:fedora.im>
15:00:38
Meeting started at 2026-05-28 15:00:36 UTC
<@meetbot:fedora.im>
15:00:38
The Meeting name is 'Fedora Meeting 3'
<@q5sys:matrix.org>
15:00:46
!meetingname security-sig
<@meetbot:fedora.im>
15:00:47
The Meeting Name is now security-sig
<@py0xc3:fedora.im>
15:00:49
!hi
<@q5sys:matrix.org>
15:00:50
!link Issue Location : https://forge.fedoraproject.org/security/tickets
<@q5sys:matrix.org>
15:00:55
!link Discourse security tagged topics :https://discussion.fedoraproject.org/tag/security
<@zodbot:fedora.im>
15:00:59
Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his
<@q5sys:matrix.org>
15:01:01
!topic Open floor to discuss anything security related. (2026-05-21)
<@q5sys:matrix.org>
15:01:08
derp
<@q5sys:matrix.org>
15:01:13
!topic Open floor to discuss anything security related. (2026-05-28)
<@q5sys:matrix.org>
15:01:32
!topic Next Meeting (2026-06-24)
<@q5sys:matrix.org>
15:01:36
!info There are 4 open tickets in the main Security Forge: https://forge.fedoraproject.org/security/tickets/issues
<@q5sys:matrix.org>
15:01:39
!info There are 6 open tickets in the Security Docs Forge: https://forge.fedoraproject.org/security/docs/issues
<@decathorpe:fedora.im>
15:01:53
!hi
<@zodbot:fedora.im>
15:01:54
Fabio Valentini: Fabio Valentini (decathorpe) - he / him / his
<@py0xc3:fedora.im>
15:03:14
Unless the author is here and has a point, I see no need to discuss the ticket about the TPM issue. I left a note there: it's worth to be kept open and to keep it updated with what happens upstream, follow the case and help/test/feedback when related builds reach Fedora, or earlier if someone has and wants to invest time.
<@py0xc3:fedora.im>
15:03:52
But see no need to do more about it for now (unless someone has different thoughts about it?)
<@decathorpe:fedora.im>
15:06:06
Yeah I don't think we need to do anything here. If you want to use TPM-backed disk encryption you're on your own anyway since that's not supported by our installer(s) AFAIK
<@q5sys:matrix.org>
15:08:10
Agreed
<@py0xc3:fedora.im>
15:08:59
Even if people use it, an exploitation has noteworthy requirements. If people work with best practices, an average user of Fedora is not likely to end up in a practical attack scneario
<@decathorpe:fedora.im>
15:09:28
an average Fedora user doesn't use TPM-backed FDE 😆
<@py0xc3:fedora.im>
15:10:12
the tautologies are back 😵💫
<@decathorpe:fedora.im>
15:10:18
I don't think there's even documentation for how to do this
<@decathorpe:fedora.im>
15:10:18
ha
<@decathorpe:fedora.im>
15:10:18
<@py0xc3:fedora.im>
15:10:41
Not from us, at elast nothing official. But some magaze articles I think
<@q5sys:matrix.org>
15:10:47
Did anyone read Adam Williamson's email yesterday to the dev mailling list titled 'Inaccurate and apparently-unsupervised actions by agentic AI system under your control'
<@py0xc3:fedora.im>
15:10:56
Not from us, at least nothing official. But some magazine articles I think
<@decathorpe:fedora.im>
15:11:11
yeah
<@py0xc3:fedora.im>
15:11:16
I think that's the case of a packager whose credentaisl ahve been stolen ?
<@py0xc3:fedora.im>
15:11:26
I think that's the case of a packager whose credentials have been stolen ?
<@q5sys:matrix.org>
15:11:44
that was one claim, but as Adam points out, there's several possibilities that we have no way to confirm.
<@q5sys:matrix.org>
15:12:03
cause... to be fair... that's exactly what an attacker woudl say to hand wave away suspicion.
<@py0xc3:fedora.im>
15:12:07
Ok, yeah, I skimmed the last two emails. Not the whole case.
<@decathorpe:fedora.im>
15:12:10
right
<@decathorpe:fedora.im>
15:12:39
well he did say he's gonna treat us to dinner at Flock, so ... I think we'd notice if it's 12 roombas in a trenchcoat
<@q5sys:matrix.org>
15:13:22
he'll have the roombas at home pushing PRs why he's wining and dining you all night long. haha
<@nirik:matrix.scrye.com>
15:13:47
(They were not a packager, only in the qe group)
<@q5sys:matrix.org>
15:14:12
I just wanted to check to see if everyone was aware, since apparnetly some of those PRs hit the installer and it's possible that we might get some questions from others about it.
<@q5sys:matrix.org>
15:15:15
AI and agentic stuff is an issue all projects are going to have to take a stance on at some point. I dont personally mind AI as long as its HITL, and everything is getting reviewed well before it ever hits a git forge
<@decathorpe:fedora.im>
15:17:13
the PR for anaconda was reverted
<@q5sys:matrix.org>
15:30:30
Alright, since it seems to be a slower week, I'm going to go ahead and call the meeting here. As always, continue the conversation in the security channel.
<@q5sys:matrix.org>
15:30:35
!endmeeting