log☇︎
102700+ entries in 0.842s
mircea_popescu: asciilifeform he's not JUST into lesswrong, wikipedia, bla bla. he's also convinced "darknet" is relevant in general, that a bunch of inept shitheads were "a cryptoanarchist revolution" and, wonder of wonders, that the pill poppers had some sort of impact in bitcoin whatsoever.
asciilifeform: 'I'm no longer as interested in the DNMs as I used to be. I was originally lured in by the fascination of watching a small cryptopunk revolution, and I was hopeful that it would go beyond the SR1 model into multisig and beyond. But we have seen little multisig usage, and that augurs ill for the distributed marketplaces. (What if someone built a trustless distributed blackmarket and no one wanted to use it?) Instead, the SR1 business
mircea_popescu: i almost prefer the vapid floozies. to hear these schmucks " I feel like this post deserves a montage or a slideshow with music. So much reminiscing and joyful sadness. ", makes my skin fucking crawl.
mircea_popescu: i guess a bunch of weirdos have the usg to thank for their wholly delusional belief that child porn is "big business", somehiw.
mircea_popescu: "Pedofunding A crowdfunding site for child pornography, “Pedofunding”, was launched in November 2014. It seemed like possibly the birth of a new black-market business model so I set up a logged-out scrape to archive its beginnings (sans any images), collecting 20 scrapes from 2014-11-13 to 2014-12-02, after which it shut down, apparently having found no traction."
asciilifeform: 'In Bloc by Bloc: The Insurrection Game, players join a movement that is struggling to liberate a randomly generated city that changes every game. Each player controls a faction of revolutionaries fighting back against the authorities. The factions must cooperate to defeat their common enemy while carefully balancing individual secret agendas. Build barricades, clash with riot cops, loot shopping centers, defend liberated zones, and
mircea_popescu: right. so the new standard for a rsa key is (e, N, userstring), and everyone's expected to produce THAT. ☟︎
asciilifeform: otherwise the output becomes a pain to read.
mircea_popescu: so is the logical thing here to just proclaim "rsa key, as per the republic, is a e, N, string tripled" and then, jurov can dump to THAT format and you'll import from that format later ?
asciilifeform: unless want to generate a pgp 'box' for them.
mircea_popescu: asciilifeform more's the point : is phuctor happy with a e, n, userstring csv ?
asciilifeform: there was a shit-combinator sponsored one at least a year ago
ben_vulpes: there's a deedbot ripoff doing the rounds as well
deedbot: [» Contravex: A blog by Pete Dushenski] Razerbacks, oh razerbacks! - http://www.contravex.com/2016/05/04/razerbacks-oh-razerbacks/
mircea_popescu: i suppose this really ends up in a discussion of "we need a new format for rsa keys", doesn't it.
asciilifeform: his primez will fatten the 8ball for a run and we see.
mircea_popescu: that schmuck ? gimme a break.
mircea_popescu: that a liar claims something doth not mean it is also worth investigating.
asciilifeform: and got a bunch of mods we dun have afaik. from ????.
a111: Logged on 2016-05-04 22:49 mircea_popescu: asciilifeform imo this is absolute proof he copied the phuctor results without understanding them. otherwise it is plain impossible he has a list of "vulnerable moduli" that is more extensive than phuctor's all the while having a list of factors that includes ~none of the factors phuctor found
mircea_popescu: it just cycles that, takes a while.
mircea_popescu: cat keybase.io | while read derp; do curl "https://keybase.io/$derp" | grep ' class="username "' | sed 's/" class/\n/' | grep "a href" | sed 's% <a href="/%%' | sort -u > keybase2.io ; done
mircea_popescu: anyway, i've implemented a truly braindamaged algo,
mircea_popescu: asciilifeform imo this is absolute proof he copied the phuctor results without understanding them. otherwise it is plain impossible he has a list of "vulnerable moduli" that is more extensive than phuctor's all the while having a list of factors that includes ~none of the factors phuctor found ☟︎
asciilifeform: seems like he even bagged a few folks we didn't, e.g,. http://phuctor.nosuchlabs.com/gpgkey/E11CDF14DD89647BC7B12CEAA217D3FFFBD37D6640295728BEC80235ED76367F
mircea_popescu: i guess. i come from a world where women under 30 aren't allowed at uni anwyay.
phf: 48g and a 206m "padding file"
asciilifeform: but you need a number of sigs.
mircea_popescu: for all this is work, he ran /u/random for a while.
mircea_popescu: is that even a rsa modulus ?
asciilifeform: looks like a standard mirrormod
mircea_popescu: i find stuff like that 271 byte one a little off.
mircea_popescu: if you're bored run a comparison.
asciilifeform: or rather, a pruned (how, i didn't bother to see, but smaller) subset.
mircea_popescu: no he didn't. he didn't get as far as removing the dsa/ecc keys out of the sks dump to get a proper count of rsa moduli
mircea_popescu: sure, it works. and hanno boeck's ( http://trilema.com/2016/psa-hanno-bock-still-a-deceitful-shitbag/ )'s hands also work. in principle like that.
mircea_popescu: asciilifeform there was a form that did nothing. how is this "Available"
asciilifeform: or iirc there was a form!
shinohai: http://www.egyptindependent.com//news/tom-jerry-blame-violence-arab-world-official <<< so I watched a lot of T&J as a child, I suppose I am a terrorist.
punkman: 2tb will do in a pinch, does it have to run in polite mode on shared server?
mircea_popescu: phf anyway, at the very least that thing needs long term seeders ; which is a mitzvah.
mircea_popescu: send men to where they have leverage - such as by exposing a whole swathe of usg "law enforcement" derps.
asciilifeform: another thing that really needs 'a doer' is the hunt for ancient pgptrons
mircea_popescu: so it is ; currently looking for a doer.
phf: that's a whole Project
mircea_popescu: a) it should be downloaded anyway ; b) contains pgp keys.
mircea_popescu: http://btcbase.org/log/2016-05-04#1462750 << there's a 50gb dump of snapshots of dark markets. ☝︎
phf: i has a working keybase crawler..
asciilifeform: because what, he is a pashtun, never seen computer ?
mircea_popescu: asciilifeform understand, the most important quality of doing things openly is that every derp everywhere is now able to try and stuff it into his peculiar headbox. there's a lot of "number worshipping" undercurrent i detect in there, sort-of the educated version of "lottery playing systems", which is more repugnant to the civilised man than the political slant. even so.
asciilifeform: plain to anyone without a mouthful of obamacok
mircea_popescu: " Could it be that all of the broken e keys were generated by OpenSSL from year 2000 or earlier? " << it could not be. a) none of the keys come from openssl ; b) most keys are post 2000.
mircea_popescu: all he's saying is that using THE FOUND FACTORS as some sort of lithmus for the key production process is a dead end. which it is.
mircea_popescu: in point of fact composites are broken into not-necessarily-prime chunks, which is more of a function of the random state of the breaker than anything, and the actual bitfield offers no information re the process that made the key
asciilifeform: but yes the large numbers are composites, this is obvious in 5 seconds to a kindergartener
mircea_popescu: asciilifeform he has a point tho.
asciilifeform: probably a red herring: an artifact of the process used by these
mircea_popescu: "something made by ten year olds on a rainy day"
mircea_popescu: incidentally-2 : you absolutely should introduce a (faux) directory structure of the type /ABCD/ABCD/ABCD/ABCD/ABCD/ABCD/ABCD/ABCD where each superior "directory" lists the subs it contains, and the last level lists actual keys. google will utterly lap this up. and it's useful in the general, passive sks.
asciilifeform: mircea_popescu: 'gwerns' are a dime a dozen.
a111: Logged on 2016-05-04 18:01 mircea_popescu: asciilifeform meanwhile : keybase keys confirmed new via http://phuctor.nosuchlabs.com/gpgkey/1D7AB955D7C3D6DA6952F80879F3F89B16E367E31BA8067853DEFF66389A1FE7 ; will be sending you a dump later today.
mircea_popescu: it;s almost like a metal detector of its very owwwn!
mircea_popescu: asciilifeform meanwhile : keybase keys confirmed new via http://phuctor.nosuchlabs.com/gpgkey/1D7AB955D7C3D6DA6952F80879F3F89B16E367E31BA8067853DEFF66389A1FE7 ; will be sending you a dump later today. ☟︎
mircea_popescu: am i the only one to have ever asked for "jiztory" in a terminal ?
asciilifeform: 'server and client side remote code execution through a buffer overflow in all git versions before 2.7.1'
asciilifeform: ''Under certain conditions it allows unprivileged users running under qemu VMs to affect the host Linux kernel in a problematic manner...' ☟︎
trinque: what a coincidence!
mircea_popescu: punkman turns out i don't have such a wonder ;/ you can have 2tb right now, though. should be ok, nevertheless, i think, seeing how it's not a single file/item, but a collection.
phf: oh remember how we were going to have a golang gossip
mircea_popescu: totally puts a stake through the heart of the "fair price" nonsense also. what is this "fair price", to hire the man that knows the future ? the causes of the past ?
mircea_popescu: in a sea of "who could have predicted", the man who does predict is but amused.
asciilifeform: (perhaps through not giving a fuck re shitlangs)
asciilifeform: it always distinguished between 'not a key' and 'key, but no rsa'
punkman: hmm maybe, got a server with space for it?
asciilifeform: i'ma saw apart a recent sks dump this weekend.
punkman: there are a couple companies that do comprehensive crawls of pastebins, could be worth looking into
asciilifeform: at the end of a werker run, all keys that were part of the run, are marked nonwaiting.
mircea_popescu: (will be particularly useful to check/disprove shit coming from hanno bock, http://trilema.com/2016/psa-hanno-bock-still-a-deceitful-shitbag/ ) et all.
mircea_popescu: and finally, you do have a knob to fill in factors into 8 ball manually ? if not add it in
mircea_popescu: asciilifeform anyway, just get the 8ball expander to work constantly, fill a core or something.
asciilifeform: ''ImageMagick allows to process files with external libraries. This feature is called 'delegate'. It is implemented as a system() with command string ('command') from the config file delegates.xml with actual value for different params (input/output filenames etc). Due to insufficient %M param filtering it is possible to conduct shell command injection. One of the default delegate's command is used
asciilifeform: mircea_popescu: as a matter of fact i do
mircea_popescu: asciilifeform the thing's been a blessing for hackers for many years now.
asciilifeform: 'There are multiple vulnerabilities in ImageMagick, a package commonly used by web services to process images. One of the vulnerabilities can lead to remote code execution (RCE) if you process user submitted images. The exploit for this vulnerability is being used in the wild. A number of image processing plugins depend on the ImageMagick library, including, but not limited to, PHP's imagick, Ruby's
asciilifeform: i can throw them in as a specialcase.
mircea_popescu: there already exists a "various ssh formats" conversion ; need to bolt on base16/10 number and pgp format.
mircea_popescu: with the first half, yeah. we also need a general purpose multiconverter.
asciilifeform: i have a ~strong~ suspicion that there are q == nextprime(p) keys in there.
mircea_popescu: IF we ever want his political opinions on things, which is a very remote distant and unlikely if, WELL ASK FOR IT!
mircea_popescu: you can do whatever the fuck you want, including help yourself to a double serving of his wife
mircea_popescu: there is a difference between YOU DOING and HE DEMANDING.
asciilifeform: perhaps a literate man should already know the theory..?
mircea_popescu: i want him giving a shit like i want cold sores.
mircea_popescu: really, he's going to trade his "giving a shit" for me doing more work on top of the work i did that he can't do in the first place ? in what fucking world!
mircea_popescu: (number one issue for the noob slaves, too, "it wasn't explained". bitch, i'm going to beat you into a pulp, what explain. figure it the fuck out, it's your ass.)
mircea_popescu: think about it in these terms : 1. i can sail, and actually used to be / could be very good at it (right body type) ; 2. i could afford a yacht, what. 3. i don't either. ???
mircea_popescu: actually fuck that. you ever been on a yacht ? by been i mean > 6 hours.
phf: sometimes i still see these santa barbara americans though, old men with "silver hair" driving a Mercedes, or mostly on the metro here. they always look so lost and small, like they walked from the screen, "the last American hero" style. except instead of like punching the car window and discovering that it hurts, their credit card is denied or something, and they are like "what is that???"
mircea_popescu: phf i'm like the emperor-god xenomorph from the future, i go "what was that bullshit tv series from the early 90s with all the boats" and wihin minutes a woman pops the name. unfuckingbelivable.
asciilifeform: then i'm at a loss re explaining the fixation.