log☇︎
100800+ entries in 0.058s
ben_vulpes: take heart douchebag, determining how far to go above the bare minimum is a lifelong project :P sometimes 'not one iota' is a fine response.
ben_vulpes curious to see if the guy leaves off at 'osint' copypasta
douchebag: Determining how the various vulnerable libraries pose an impact, and wether or not they could be leveraged by an attacker
ben_vulpes: native bluetooth stack i'm going to guess does not affect trb build
ben_vulpes: douchebag: now how would one go about determining if any of these mines were steppable-upon or stepped-upon in the context of trb?
ben_vulpes: douchebag: aaah now that's more like it
ben_vulpes: "hey dudes did you know that $whatever?"
ben_vulpes: i think that'd be a fine thing with which to 'shit the logs up'
ben_vulpes: douchebag: there is always p.bvulpes.com
ben_vulpes: douchebag: the image approach is impossibly frustrating; will not reflow across my screen
douchebag: I didn't want to shit up the logs posting CVE's and their descriptions
asciilifeform: douchebag: is there a reason this is a pic ?
BingoBoingo: Is that carnaval?
BingoBoingo: asciilifeform: That's just lithium salt
BingoBoingo: http://archive.is/KgtD9 << It is also far cheaper here to get protein from beef tenderloin than powdered dairy biproducts
BingoBoingo: ben_vulpes: The "Vitango" with rhodiala
ben_vulpes: which one is the maoi, BingoBoingo ?
lobbes: I'll bbl tonight. I gotta do some maintenance on archive process tonight so I can send em through then
a111: Logged on 2018-05-09 19:21 asciilifeform: hey mircea_popescu ( or anybody else ) do you happen to have a script handy for mass submission of links to archive.is ?
lobbes: If you give me the list of URLs I'll feed 'em through the meatgrinder >> http://btcbase.org/log/2018-05-09#1811668 ☝︎
BingoBoingo: As as humid as it is here, I don't want mushrooms growing inside me. It's a river valley so everyone is assumed to be carrying histoplasmosis
BingoBoingo: Yogurt is a big thing here
BingoBoingo: been taking yogurt and blue cheese before my evening ice creams ☟︎
trinque: make sure you get your gut critters in order after dropping nukes on them
BingoBoingo: And the professional opinion came in today. Keep taking the same antibiotic, same dose for 10 more days and if it isn't substantially better in a week chest X-ray. Also was recommended a different anti-mucus syrup. ☟︎
a111: Logged on 2018-05-09 21:11 asciilifeform: 109.41.3.220 - - [09/May/2018:17:11:33 -0400] "GET /phuctored HTTP/1.1" 200 9578812 "http://phuctor.nosuchlabs.com/stats" "Mozilla/4.0 (MSIE 6.0';DROP TABLE browsers;--\x22<u>{!=&})" "-"
BingoBoingo: http://btcbase.org/log/2018-05-09#1811726 << Should I get a sleeping bag and sleep in the datacenter hall tonight? ☝︎
asciilifeform: but yes i'ma let this alone for nao
asciilifeform: ben_vulpes: in the abstract, it'd be pretty great to have mechanisms that work with and without fleanode ☟︎
ben_vulpes: plus, gotta do the customerdatabase first in anycase.
ben_vulpes: will save time if i bring a polished design instead of this adhoc bikeshedding.
ben_vulpes: asciilifeform: let us table it for a bit, i do not have a proposal baked and understand all of the things you've pointed out so far.
ben_vulpes: "dun fuckin lose this!"
ben_vulpes: can also generate unique account identifiers from fg, use that instead
ben_vulpes: user decrypts, leaks, their problem. set a session key, broadcast data unencrypted, leak is pizarro's fault
asciilifeform: pizarro/$fp leaks just the same, neh?
ben_vulpes: but this sucks for obvious reasons
ben_vulpes: another approach is to challenge-response and hand over a session token
asciilifeform: ( i lifted the idea from mircea_popescu )
ben_vulpes: yes well steal from the best
asciilifeform: hey this is more or less exactly how asciilifeform implemented the snsa wwwshop
ben_vulpes: but, and many details not designed at this rate since you press me, something along the lines of pizarro/$fp/ renders an encrypted account status including support tickets
ben_vulpes: i'm half of a mind to take offense at the implication i'd impose email on anybody in the republic
asciilifeform: if you have a pill to make email 1992-style usable again... i'll be quite impressed
ben_vulpes: asciilifeform: quit jumping to conclusions
asciilifeform: ben_vulpes: i sure as fuck won't sift through GB of spam to read strangermail
ben_vulpes: asciilifeform: from experience, chat is a miserable way to manage support tickets. ☟︎
ben_vulpes: i've been thinking about a pizarro wot identity, yes
ben_vulpes: there is also the concern of every customer now gotta be rated, likely by me, which puts me in the nanotube position ☟︎
asciilifeform: ben_vulpes: if $luser won't irc, how is he to access pizarro for support/maintenance/payment q's ?
ben_vulpes: i'm not necessarily loathe to give up the "dump pubkey and sshkey in hole, pay invoice, receive server deets at this url encrypted to your key" model, but i worry the irc demands are an unnecessary salting of friction
asciilifeform: it does not make any sense to attempt to do business with folx who won't pgp
asciilifeform: how , for instance, would you propose to match up who paid with their box ? send creds ? ( what, via plaintext shitmail ?? )
asciilifeform: ben_vulpes: you think this is optional ?
asciilifeform: ben_vulpes: prospective pizarro user gets into wot. so there's the key.
ben_vulpes: there'll be ~no way around asking each user for a gpg key i don't think
ben_vulpes: i imagine some kind of remotehands queue of "make rockchip with sshkey of XXX, upload which IP addr or other unique identifier got the key in question"
asciilifeform: 109.41.3.220 - - [09/May/2018:17:11:33 -0400] "GET /phuctored HTTP/1.1" 200 9578812 "http://phuctor.nosuchlabs.com/stats" "Mozilla/4.0 (MSIE 6.0';DROP TABLE browsers;--\x22<u>{!=&})" "-" ☟︎☟︎
asciilifeform: meanwhile, in the peanut gallery:
asciilifeform: ( you would have to, more or less, bake a rockchip board from 0 )
asciilifeform: ben_vulpes: nao the problem ~could~ be finessed with custom hardware. but not with something that can be built quickly.
lobbesbot: ben_vulpes: Sent just now: <asciilifeform> i oughta elaborate re http://btcbase.org/log/2018-05-09#1811686 : neither rockchip ( nor any device in its price range, afaik ) has any mechanism for netbooting, that does not at the same time reside in something the previous user could have overwritten ( flash rom ). on top of this, rockchip has ~no~ onboard flash , nor can it boot from usb without a valid bootloader ~on sd~ . so a new tenant requires a refr
ben_vulpes: i figured that something like this was the case and appreciate the followup
lobbesbot: asciilifeform: The operation succeeded.
a111: Logged on 2018-05-09 19:52 ben_vulpes: asciilifeform: in re production rockchip plant, is it feasible to, with some netboot magic, bring a rockchip up with a specific ssh key emplaced?
asciilifeform: !Q later tell ben_vulpes i oughta elaborate re http://btcbase.org/log/2018-05-09#1811686 : neither rockchip ( nor any device in its price range, afaik ) has any mechanism for netbooting, that does not at the same time reside in something the previous user could have overwritten ( flash rom ). on top of this, rockchip has ~no~ onboard flash , nor can it boot from usb without a valid bootloader ~on sd~ . so a new tenant requires a refr ☝︎
lobbesbot: asciilifeform: The operation succeeded.
asciilifeform: !Q later tell jurov plz tell me how you obtained the KEYID in the 'phathub' collection; and more generally how the scan was made...
asciilifeform: enjoy the beach, mircea_popescu
asciilifeform: ( will detail the ram sadness later )
mircea_popescu: alright then.
asciilifeform: and no moar ramdisk, so it's 5x+ slower than typical
mircea_popescu: anyway, im taking the bitches for a beach trip ; mind holding off till i'm back ?
asciilifeform: mircea_popescu: i think i grasp the idea, they'll be denying even as the 'shower' door slams and the zyklon hisses
mircea_popescu: authority is the concern, not some sort of really tall tower of chairs of meaning.
mircea_popescu: electoral college is good for the empire / bad for the empire. same people, two weeks apart. what do you want ?
mircea_popescu: but even if you got the entire pantsuit party, from everyone-involved-with-github to everyone-opining-on-the-internet to sign an agreement aforehand, they'll STILL deny after the fact.
asciilifeform: hey douchebag ! we're about to post buncha ssh privkeys. some, connected to -- nominally live -- shithubs.
asciilifeform: well there's more- and less- deniable dents. i dun recall louis xvi walking around and pretending his head were still attached..
mircea_popescu: or do you hope to somehow make a "more undeniable" hole than "this is specifically what we agreed you won't do" ?
mircea_popescu: need i remind you of, say, http://trilema.com/2013/the-endless-story-of-korea/#selection-77.0-77.246 ie "Plaintiff seeks to make his case solely upon the theory that, by reason of the change in the weight of the dollar he is entitled to $1.69 in the present currency for every dollar promised by the bond, regardless of any actual loss he has suffered" ?
a111: Logged on 2017-08-28 23:10 mircea_popescu: kanzure " Obviously there is no possiblity of meaning outside of a structure of authority, and the authority can not be predicated on the meaning."
mircea_popescu: it'll be denied. and the denial will "stick" in the sense luke skywalker really has a "laser sword", for as long as you stay in battlestar galactica universe or w/e the scientology fanfic was. because, for better or worse, http://btcbase.org/log/2017-08-28#1704268 ☝︎
asciilifeform: mircea_popescu: i'd like to make some sort of non-debiable/unhealable hole in the boeck bubble, and it almost seems possible in this case
asciilifeform: ben_vulpes: on top of this it'd be quite simple to emplace given, on cmdline, sshkey -- simple mount-and-copy
asciilifeform: ben_vulpes: currently re-customering a rockchip requires pulling the usbstick and sd and reimaging
deedbot: http://trilema.com/2018/my-verbiage-on-trilema/ << Trilema - My verbiage on #trilema
mircea_popescu: eh, who the fuck cares what boecks boeck.
asciilifeform: mircea_popescu: i'm taking ideas re pills against 'these were never keyz, you pulled them out of arse'
ben_vulpes: asciilifeform: in re production rockchip plant, is it feasible to, with some netboot magic, bring a rockchip up with a specific ssh key emplaced? ☟︎
ben_vulpes: asciilifeform: mk, will callout at top the changes in a bit.
asciilifeform: ben_vulpes: for now it'd suffice imho to say, approx what was updated
asciilifeform: neato, ty ben_vulpes
ben_vulpes: asciilifeform: the next item after setting Mocky up with python cgi on UY1 (dear lord, it never ends) will be to databize our customer list, ip assignations, rack assignations, subscriptions etc. i will then reproduce your calculator with actual numbers.
asciilifeform: the other thing, ben_vulpes : ~where~ updated ? it is terrible form to make people do 'eyeball diff' with old copy ( supposing they have one handy )
asciilifeform: ben_vulpes: could i persuade you to keep an updated ver of http://btcbase.org/log/2018-05-05#1809743 ? or too hightech/ugly ? ☝︎
asciilifeform: ( will be interesting to find out if luser whose shithub modulus is divisible by 3, can still log in... )
mircea_popescu: sadly, i dun have such a thing on hand
asciilifeform: ( interestingly, for some of the lusers, their account is still live BUT above loads a null. )
asciilifeform: i'd like to snapshot the https://github.com/loser.keys links