Minutes of the SIPB Meeting of 2021-11-01 The meeting was called to order at 19:30 by kjchen. In attendance were Student keyholders: kjchen, cela, bds, cjq, asahteck, jnwagner, jeffery, huydai Associate keyholders: '() Members: jmvidal, mitimmy, javsolis, agrebe, markchil Guests: '() Administrivia: kjchen: There will be an EC meeting after this SIPB meeting because it's the first Monday of the month. If you're not on the EC you're welcomed to join us! If you're on the EC you don't have a choice. :) Project Reports: cela: HWOPS continues to meet. We-waste pickup scheduled for tomorrow morning. So I'll be here early tomorrow. If you are one of the people who asked to pick something up from the SMR, we've emailed you about it. It's over there. *points to the back of the room* cjq: I was talking to Edfan about Firehose and as the unofficial maintainer. Last Wednesday we talked about the future of Firehose, and the agreement we came upon is that Edfan would still own the website and do the hosting, but he would give me and by extension SIPB to deploy and make small changes. However, he would still remain as the main author and retain executive decisions on big updates. cela: I would feel a little weird about having a high-profile project that is a SIPB project but is also not really owned by us? By no means we should not help to maintain things, but I'm not sure how we feel for us to call something a SIPB project that we aren't actually responsible for. We have all kinds of resources to throw at a project as necessary, but we also don't use all of those resources for a project that's not entirely in SIPB. kjchen: I vaguely recall that there were some SIPB projects that were done by people outside of SIPB that had some SIPB members in it. cela: Do you remember what the names of the projects were? kjchen: Not sure. I think it was something that happened over the span of last year? javsolis: Is it Explain Everything? kjchen: It was on the site, yeah. mitimmy: It didn't seem quite as a SIPB project to me huydai: Explain@MIT was and is run by Elton, who is a SIPB member. However, I would say that Explain perhaps didn't see as much involvement within SIPB as compared to other projects cela: I think it's about the question of would we be okay with putting our name on a project that we don't have meaningful control over. cjq: This was roughly my feelings about this when I was talking to Edwards. *off-minutes discussion about "crufty"* cela: Here's my idea: Offer him the opportunity to take back control of the website if SIPB is not doing a good job with it. cjq: I'll bring it up. I think the next step is beginning the transfer of some form of ownership and then I'll talk to him about gaining more control. cela: It's probably better if you talk to him about this from the start, because he might feel that you're wrestling control away if you mention this idea later on. kjchen: It's somewhat easier if a project is already maintained by current students and that the current students are committed to recruit new students. I think you should touch base with him to see if he would be willing for us to take on a project in a way that would make it easier to make sure that there will be future students to keep the website running javsolis: Where's the machine room? cjq: *Points next door* huydai: There's a door through the reading room Other: agrebe: The first SIPB cluedump is sooner than you think. It's on November 16th at 7 PM. Would this time not work with anyone? We have a fair bit of flexibility in scheduling it. *no objections* agrebe: In that case I will officially declare it to happen two weeks from tomorrow. I will also send out an e-mail to the SIPB office Other Other: huydai: About two weeks ago in China there was a big hacking competition where teams try to find zero-day vulnerabilities in popular softwares. From an article I read on the event, the teams there were able to execute zero-day exploits on nearly every popular OS (including Windows 10, Ubuntu, iOS). They are also exploited Exchange server, Google Chrome, and perform the first jailbreak on iOS 15. However, this is a good thing as all of the vendors were notified of their vulnerability found as a result of the competition. markchil: Also on the topic of vulnerabilities, did anyone hear of the new Trojan Source exploit? Apparently the technique uses Bidirectional text control characters in Unicode to make your source code do something different than what it's intended to do. This vulnerability has been disclosed to compiler libraries and GitLab about 99 days ago so they're aware of the issue bds: This isn't the first time this kind of bidirectional hackery has been done before. In Windows viruses have been known to use bidirectional characters to make the Windows file system think a file has a different extension than what it actually us cjq: Unicode is a terrible idea cela: Facebook decided they are Meta now? I don't respect that. I didn't respect them before, and respect them even less now. mitimmy: Respect for them went from negative to imaginary. The meeting was adjourned at 19:50. Minutes taken and submitted by huydai.