log☇︎
109700+ entries in 0.037s
asciilifeform: 'when choosing astrologer, hire the cheapest' ☟︎
asciilifeform: i used it myself when writing rootkits.
asciilifeform: BingoBoingo: nsa uses rc6 for all 'deniable ops', because it is goodenough+short in asm
asciilifeform: there are surely people other than mircea_popescu and asciilifeform who -- have interest in subj + have the theoretical pre-reqs + seriously ready to get their hands dirty + not thralls of usg
asciilifeform: but also i was referring to ~people~ as much as to algos.
asciilifeform: (keccak or another hash can be abused as a stream cipher, but it is precisely 'retarded homebrew', i will leave the reason ~why~ as an exercise)
asciilifeform: keccak is not any kind of cipher.
asciilifeform: cs is not a block cipher.
asciilifeform: serpent is, i must note, 'best horse in the glue factory.'
asciilifeform: at least in as far as public lit.
asciilifeform: and it's more or less a vacuum.
asciilifeform: now i cannot speak for others, but i spent past few yrs exploring the known space between usgola (aes et al) and http://trilema.com/2013/the-danger-of-homebrew-crypto
asciilifeform: 'rocket is trivial, just sit in a pipe and throw hot gas out one end'
asciilifeform: i.e. 'don't exist'
asciilifeform: esp. because ciphers are a blindingly obvious 'political art', where if you aren't schneier et al, you don't get printed in journals, invited to conferences, implemented by open sores monkeys, etc.
asciilifeform: moar folx went to the bottle.
asciilifeform: mircea_popescu: why 'xcode and unity', and not 'the bottle'
asciilifeform: (answer is, the folx with 'acres of crays' will butthurt that their oh-so-precious special-purpose silicon is bricked)
asciilifeform: where you can have 193-bit words if you feel like it, with 311-bit key. and next day - 301-bit words and 503-bit key, etc.
asciilifeform: or, the other obvious mega-question, why there is no STRETCHABLE (a la keccak) block cipher
asciilifeform: ^ d00d worked for kgb crypto directorate in '80s, asked same question of his superiors, got same answer.
asciilifeform: !#s maslennikov
asciilifeform: i asked 'professional cryptographers of international repute' and 0 answer beyond 'here's a banana, monkey boy'
asciilifeform: especially transpositions as we know them. i'm still waiting to hear why s-boxes are fixed, rather than entirely configured by the key, ever.
asciilifeform: mircea_popescu: more dire, even, than this, we aren't dealing with 20 years of disinfo artistry, but ~70 ! hagelin, crypto-ag, etc. and the entire poppycock of transposition ciphers surviving into computer age
asciilifeform: noshit.jpg. ~same ~2dozen people involved.
asciilifeform: http://btcbase.org/log/2015-07-12#1198070 << old thread re aes ☝︎
asciilifeform: lel
asciilifeform: the thing executes in constant-ticks, looks like.
asciilifeform: pipeline doesn't leak timing either, because - if implemented correctly - you never branch on a secret (key or plaintext) bit.
asciilifeform: in particular: no tables. ☟︎
asciilifeform: BUT it is in several ways, apparent to the naked eye, less retarded than aes ☟︎
asciilifeform: now i will remind readers that 'serpent' is not, afaik, on any kind of scientific foundation. it was made using voodoo doll, just like every other block cipher. (what kind of doll, is described in the paper.)
asciilifeform: more or less simply declared 'history, done with'
asciilifeform: davout: it was a loud, public wank, ~impossible to 'unhappen' to any reasonable degree
asciilifeform: the political history is also rather interesting (it was on track to winning the 'aes competition', received fewest thumbs-down votes from the panelists, but mysteriously torpedoed by usg and did not win) ☟︎
asciilifeform: http://wotpaste.cascadianhacker.com/pastes/HQmMH/?raw=true << example in ada. < 700 ln. ☟︎
asciilifeform: (and so, no cache-sensitivity.)
asciilifeform: for instance, there are no tables.
asciilifeform: it is pretty interesting imho.
asciilifeform since release of FUCKGOATS, spent much time studying 'serpent' block cipher. ☟︎
asciilifeform: this is for when mircea_popescu gets his botnet.
asciilifeform: Framedragger: this also. but -- slow.
asciilifeform: whereas this is elementarily reasonable.
asciilifeform: one of the hidden evils of 'of course generating key takes 10 minutes!' traditional entropy starvation -- is that nobody expects to be able to do the test where you generate 10 billion keys and make sure that the resulting keys have gcd of 1
asciilifeform: then -- debianize.
asciilifeform: then enumerate factors.
asciilifeform: the other interesting experiment, yet undone, is to generate ssh, ssl, pgp, etc. keys on some of the other os with known-broken rng -- e.g., freebsd 2010-2014 (or when was it), possibly other
asciilifeform: http://www.loper-os.org/?p=1733 << as seen here, good chunk of the first N ssh keys to pop were tropos boxen.
asciilifeform: the interesting bit re tropos is that it is not a konsoomer box, but infrastructural (isp, public wifi, gsm, utility sensors) and for some reason popular in orc world
asciilifeform: (it displays unremarkable ssh hello, the litmus for it uses the ssl cert that the boxes also display on 443)
asciilifeform: mircea_popescu: tropos , i recall now, was the other big one.
asciilifeform: or.
asciilifeform: or the 462`750 ROSSSH
asciilifeform: huawei, on other hand!
asciilifeform: in this case -- yes
asciilifeform: (and that's just 1 ver; iirc various others identify as plain ssh)
asciilifeform: 15`645 2.3.0_Mikrotik_v2.9 << from mircea_popescu's mega-tally
asciilifeform: they're pestilentially common
asciilifeform: what do you mean 'was ever deployed'
asciilifeform: which it
asciilifeform: (could be -- hundreds of thousand)
asciilifeform: each successful shot is potentially several thousand popped keys.
asciilifeform: (not necessarily the physical box ! the os ought to be enough )
asciilifeform: of a particular type.
asciilifeform: all i need is 1.
asciilifeform: now if someone here knew where to get a hold of even one !
asciilifeform: ditto the huawei boxes, the voip thing, whatever it was called, and the dozen or so other examples i catalogued in recent months
asciilifeform: the thing to observe here is that, e.g., mikrotik, should be susceptible to the debian treatment (enumerate the possible factors, then shoot)
asciilifeform: (not debian. its own idiocy.)
asciilifeform: http://btcbase.org/log/2016-12-28#1591924 << lel, yet another 'mikrotik routeros', lost count by now of how many ☝︎
asciilifeform: and aha, ben_vulpes , recall during conf 4, mircea_popescu playing the baliset, we poured the waterz...
asciilifeform: phf: funnily enough, iirc the item used in the film actually fit this description.
asciilifeform: ben_vulpes: https://www.youtube.com/watch?v=KuBSvNtlAq8 << oblig
asciilifeform: BingoBoingo: d00d has little plastic models of the probez in his office, would go on and on..
asciilifeform: kbd eggog
asciilifeform: aha
asciilifeform: baliset
asciilifeform: for some reason i picture the 'baliste' in 'dune' as working like this.
asciilifeform: something chinese.
asciilifeform: but i fuhget the vendor
asciilifeform: ben_vulpes: no, not the toy, a tunable/playable thing
asciilifeform: switch on, play by imaginarily plucking.
asciilifeform: iirc somebody sells electric guitar now that is just a stick with painted-on 'strings', and a comp
asciilifeform: asciilifeform's pet critter has a guitar, but it has not been touched in decade+, might crumble into dust if unpacked.
asciilifeform: neato, i had nfi.
asciilifeform: ben_vulpes is guitarist ?
asciilifeform: now if it had a www...
asciilifeform: i've nfi
asciilifeform: do i win the prize.
asciilifeform: ubuntu/whateveritwas autoupdater.
asciilifeform: clim is 'hooker ready' ?!
asciilifeform: if you don't, you are stuck using some variant of crapple.
asciilifeform: ben_vulpes: it isn't optional
asciilifeform: i have nothing in particular against the d00d, but it is quite genuinely unclear to me where the 'value added' is.
asciilifeform: from the l0gz, it looks like a shitlinux with sbcl preinstalled (big fat breakthrough?)
asciilifeform: i'd still like to know wtf it was that he even sells. having a www would help...
asciilifeform: and no ransomed old pgp key..?
asciilifeform: also gabriel_laddel_p's boxen flying off the shelf, but still no permanent postbox..?
asciilifeform: yet it has www, because wtf, how else anyone knows what it is that is for sale.