Hi everyone, I filed this report a while ago for w...
# neuvector_suse-security
n
Hi everyone, I filed this report a while ago for what we feel is a pretty serious security flaw. In short, it seems like group rule are sometimes not applied to quick/ephemeral processes. I filed an issue here Process generates security event even though custom group should allow · Issue #2161 · neuvector/neuvector Someone else filed another here Quick processes can bypass rules · Issue #1800 · neuvector/neuvector And another one here Is there a warm up time until the enforcement starts working? · Issue #2068 · neuvector/neuvector Has this been addressed internally, is there any news you could share on this? Thanks!
l
cc: @quaint-candle-18606
q
Product Engineering reports "i put the team analysing this so we are investigating and we will have more answers monday or tuesday"
a
yes the team is evaluating how we can tackle this ill let you know since the team comes back to me it can take some time because of timezone differences
n
Thanks everyone, please let me know either here or under the issue I opened as progress happens on this. Much appreciated 😄
Hi @adamant-needle-95152, any news on this?
Hi everyone it's been almost a month without news...
a
Hello Louis sorry for the late reply
the team already knows the problem and identified the possible workarounds and solutions but ultimately you need to liase with @tall-army-18868
but from what ive gathered this is a design limitation from NV
its not something easy to undertake at this point in time
n
Thanks for the feedback, much appreciated. I'll try to get in touch with Davide.
a
in order for us to get over that limitation it seems a lot of effort needs to be overcome , and right now i dont know if we can tackle this right away
👍 1
n
That's understandable! Still, since this has been noted in our ITSec reviews we're kind of in a bind where we need to at least try to mitigate this. We can't just let pods run unenforced for long(ish) periods of time. And if you see my post below in the chat, we're also getting constant security events from rules we have already allowed, this all makes NeuVector difficult for us to operate. In any case, I appreciate y'alls work on this and we hope we can find a solution at some point. Thanks!
a
there might be a good solution in the works in version 6 but thats something that @tall-army-18868 can provide more information