log☇︎
131000+ entries in 0.031s
asciilifeform: https://libraries.mit.edu/archives/exhibits/purse << related.
asciilifeform: i suppose this here is the kind of 'standard' that makes mircea_popescu reach for his pistol when he hears word 'standard'.
asciilifeform: javascript.
asciilifeform: period.
asciilifeform: ben_vulpes: there are no ints in js.
asciilifeform: WHY
asciilifeform: lolwut
asciilifeform: not of country.
asciilifeform: 2/3 of lowell, mass., possibly.
asciilifeform: (womanities phd, managerial apparatchiks, etc.)
asciilifeform: generally, the courtly kabuki nonsense caste
asciilifeform: the 'being nice' delusion is confined to a small set of ustardz
asciilifeform: scooter!!1111
asciilifeform: ( http://motherboard.vice.com/read/i-used-to-write-apocalypse-survival-guides , confessions of pay-per-word spamola pinoy, supposedly )
asciilifeform: le, and they live in your city.'
asciilifeform: from same rag, a gem for BingoBoingo, 'While lurking on a prepper discussion thread on Tea Party Community, a social network marketed as a conservative alternative to Facebook, I once saw a rousing discussion about navigating the tricky business of armed combat while confined to a mobility scooter. In that particular hypothetical scenario, individuals were discussing the best ways to kill NATO peacekeeping forces. These are real peop
asciilifeform: http://motherboard.vice.com/read/the-administrator-of-the-dark-webs-infamous-hacking-market-the-real-deal-has-vanished << moar tabloid lulz
asciilifeform: ^ somehow i missed.
asciilifeform: speaking of 'modern', http://www.cnbc.com/2016/05/26/mt-gox-creditors-seek-trillions-where-there-are-only-millions.html
asciilifeform: screenshots thing ?
asciilifeform: wtf is 'twitch' anyway
asciilifeform: 'The Maiden Rape Assault: Violent Semen Inferno' << lel
asciilifeform: it's a fine thing. and if all you want is to ~receive~ in broad spectrum, it is light enough to fly.
asciilifeform: rtlsdr ?
asciilifeform: dig around.
asciilifeform: and for all i know, already done somewhere
asciilifeform: jurov: it's an undergrad-level project
asciilifeform: and, also incidentally, a 64GB+ sdcard weighs ~1g. so there is no reason whatsoever for the cipher not to be otp.
asciilifeform: incidentally, a Useful Product Idea, plug-in replacement guidance module for popular flying toys, to pick arbitrary quiet frequency spread in a reasonably broad swatch of spectrum, when remote is paired with toy, rather than the current 'legal' jammable idiocy. ☟︎
asciilifeform: next: flying vuvuzelas.
asciilifeform: 'The patch included in SA-16:25 is incomplete, and may still permit heap corruption. The patch included in the document dump is more complete. Why only a partial fix?' <<< ahahahahaha
asciilifeform: BingoBoingo ^
asciilifeform: http://www.cnn.com/2016/08/10/europe/wandsworth-prison-drone-death/index.html << further lelz.
asciilifeform: and the same one which threw out gcc in favour of crappleade, etc.
asciilifeform: this, notice, is the same freebsd as was distributed with DEAD rng, for ~year
asciilifeform: 'Why was there no mention of the fact that running freebsd-update to install the fix for the bspatch advisory [SA-16:25] may actually expose users to the vulnerability?'
asciilifeform: https://lists.freebsd.org/pipermail/freebsd-announce/2016-August/001739.html << further lulz
asciilifeform: mircea_popescu: but current idea is, an instrumented gpg.
asciilifeform: mircea_popescu: not quite yet.
asciilifeform: the only permissible operation on an unsigverified input is - constant-time sig verification.
asciilifeform: (quite arguably, (2) is redundant and subsumed in (1). but it defines what is a 'rando')
asciilifeform: the most galling thing is the VERY NOTION of a tcp that isn't porous. because tcp breaks BOTH of the two, as i found, iron rules of network sanity: 1) NOTHING TO RANDOS FOR FREE 2) NO OPERATIONS ON UNSIGNED INPUT
asciilifeform: why no mention of WHO implemented ?
asciilifeform: 'implemented in Linux kernel version 3.6 (from 2012) and beyond' << emphasis.
asciilifeform remembers thread, but unable to turn it up in the l0gz
asciilifeform: iirc it was the db descriptors thing in trb.
asciilifeform: ments, we show that the attack is fast and reliable. On average, it takes about 40 to 60 seconds to finish and the success rate is 88% to 97%. Finally, we propose changes to both the TCP specification and implementation to eliminate the root cause of the problem.'
asciilifeform: rther, if the connection is present, such an off-path attacker can also infer the TCP sequence numbers in use, from both sides of the connection; this in turn allows the attacker to cause connection termination and perform data injection attacks. We illustrate how the attack can be leveraged to disrupt or degrade the privacy guarantees of an anonymity network such as Tor, and perform web connection hijacking. Through extensive experi
asciilifeform: 'In this paper, we report a subtle yet serious side channel vulnerability (CVE-2016-5696) introduced in a recent TCP specification. The specification is faithfully implemented in Linux kernel version 3.6 (from 2012) and beyond, and affects a wide range of devices and hosts. In a nutshell, the vulnerability allows a blind off-path attacker to infer if any two arbitrary hosts on the Internet are communicating using a TCP connection. Fu
asciilifeform: https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/cao << orig. source apparently.
asciilifeform: this is the n-th time with the sequence number prediction thing, isnnit.
asciilifeform: http://www.isssource.com/fixing-an-internet-security-threat << moar 'black hole lulz'
asciilifeform: and none of the reference material i have on the subj, features it.
asciilifeform: with fruit.
asciilifeform: PeterL: weed
asciilifeform: mircea_popescu: lel
asciilifeform: ;;later tell BingoBoingo can you identify this weed ? >> http://www.loper-os.org/pub/whatisit.jpg
asciilifeform: 'shmoocon'
asciilifeform: nope.
asciilifeform: in other lulz, http://www.theregister.co.uk/2016/08/10/microsoft_secure_boot_ms16_100
asciilifeform: $s 90055334522847202481312882334750017605897224759371784435327473584564809667943
asciilifeform: in other vintage lulz, https://ballandalus.wordpress.com/2014/09/11/a-hispano-muslim-embassy-to-the-vikings-in-845-an-account-of-al-ghazals-journey-to-the-north
asciilifeform: the films, just as the b00kz.
asciilifeform: mircea_popescu: ~all the ru material worth seeing, afaik, is.
asciilifeform: pretty lulzy
asciilifeform: turns out whole 'giro girotondo' is on youtube
asciilifeform: so, 2nd hardphork when ?
asciilifeform: ah lel
asciilifeform: give to starving nigerians ?
asciilifeform: what did they originally propose to do with it?
asciilifeform: (i haven't any dispute re dns being a work of evil, from day 1, but the rms solution is not a solution and i will continue to laugh)
asciilifeform: see what they say.
asciilifeform: try asking them to do next mission without dns.
asciilifeform: ah there we go.
asciilifeform: mircea_popescu's intel group investigates solely using binoculars ?
asciilifeform: y'know, it STILL counts as dns'in if you send gurlz to do it...
asciilifeform: sometimes i wonder if mircea_popescu is seeeekritly an orthodox jew:
asciilifeform: or what.
asciilifeform: but i guess i forgot that... YOU CAN HAVE ONE COMPUTER ONLY
asciilifeform: just as i run, e.g., virii, which like to use dns.
asciilifeform: more or less immediately.
asciilifeform: try what? if i can't search for error messages, i literally go broke.
asciilifeform: but is advice that is of 0 use outside of the dirigible.
asciilifeform: it works, apparently, for mircea_popescu .
asciilifeform: and his 'i ask friends to load www links for me and print and to bring me'
asciilifeform: all quite reminiscent of rms
asciilifeform: and perhaps it is 'not inconvenient' because other folks do this for him ?
asciilifeform: well apparently it did keep mircea_popescu from searchengining for the error msg.
asciilifeform: 'The website may try to fallback to TLS 1.0 in a way that is no longer allowed in current releases or may be using a deprecated cipher suite.'
asciilifeform: them bitz were shuffled 'round, to get them dirty terrorists UPDATING LIKE GOD SAID TO etc
asciilifeform: or rather, where it first pops up in the logz.
asciilifeform: mircea_popescu: https://support.mozilla.org/en-US/questions/1056325 << it's the curl thing aha.
asciilifeform: but didja know, how WORLD WORX, ya CAN'T HAVE computer without dns and updatez!111111111111111
asciilifeform: ^ bonus lul
asciilifeform: '...The attackers used multiple interesting and unusual techniques, including: Data exfiltration and real-time status reporting using DNS requests. Implant deployment using legitimate software update scripts....'
asciilifeform: mircea_popescu: this came out of what, curl ?
asciilifeform: from the dept. of Run Moar Winblowz, https://securelist.com/analysis/publications/75533/faq-the-projectsauron-apt
asciilifeform: tru.
asciilifeform: 5 goat / minute.
asciilifeform: and the whole exercise becomes one of deciphering martian language.