log☇︎
150400+ entries in 0.034s
asciilifeform: 'GnuPG 1.2.3... If you have used ElGamal keys for signing your private key can be compromised, and a malicious keyserver could remotely execute arbitrary code with the permissions of the user running gpgkeys_hkp.'
asciilifeform: https://security.gentoo.org/glsa/200312-05 << vintage megal0l
asciilifeform: from the dept. of definitely-not-news,
asciilifeform: B3ST PR4CT1C3Z!1111111
asciilifeform: ty, to defend you must hire good people who do information security professionally...'
asciilifeform: 'Should have not fallen for pseudosecurity technobuble talk. Should have gotten second opinions. Should have used established information security frameworks and be extremely suspicious on why they are not being used... ...It is a common misconception that to defend against hacking you must hire a hacker. Perhaps you've been watching that old movie "hacker" and lots of other Hollywood produce too much and believed that crap. In reali
asciilifeform: first commenter is also 'usg gold'
asciilifeform: i dun care if it's pronounced 'hoover vacuum co.'
asciilifeform: vorhees was always a scumbag, and it is no surprise to me that his verminous nest is full of scumbags likewise.
asciilifeform: ve a salary and confidence from that team, and then screw them all for barely enough money to buy a Tesla. Oh yeah, and then abandon a dog to starve alone, likely soon to be put down by animal services.'
asciilifeform: 'Bob betrayed us. He betrayed his privileged position, profiting directly from the destruction of those who trusted him. He stole, lied, ran away, and then after being afforded a period of time long enough to reflect upon his actions, decided to betray us again for a few more scraps in his pathetic bowl. Hackers gonna hack, but it takes a certain variety of bastard to ascend to a trusted position, work face to face with a team, recei
asciilifeform: and, best lulz,
asciilifeform: 'Our server admin, in the midst of an investigation into a $130,000 theft, deletes his two keys, and only these two keys, without telling anyone, and then admits on our call that he did it because “they weren’t important.”'
asciilifeform: hire moar 'injuns' ahahaha.
asciilifeform: thing special, but we were content to have a professional taking care of devops at least well enough to enable our engineers to build upon the architecture.' << l0l!!
asciilifeform: 'We hired such a person, and patted ourselves on the back for our proactive decision. On paper, he looked great; the reference we called confirmed his prior role and responsibility. He’d even been into Bitcoin since 2011/2012 and had built miners in his room. Awesome. We’ll call this new employee Bob… indeed his real name starts with a B. Over the next months, Bob built and managed ShapeShift’s infrastructure. He did okay, no
asciilifeform: standardized templates for frequent chores, e.g., queues, stacks
asciilifeform: in useful ways
asciilifeform: phf: aside from the useful 2012isms discussed previously (see logz - spark, predicated types, etc) the standard lib grew
asciilifeform: and finally understood why the '95 b00kz were so cheap.
asciilifeform broke down & bought 'standard' and 'rationale' circa 2012
asciilifeform: but that might be just me.
asciilifeform: i celebrate 0 holidays and would prefer that they ~all~ be movable
asciilifeform: useless.
asciilifeform: what the hell is that good for
asciilifeform: as in, everyone ?
asciilifeform: company-wide ?
asciilifeform: mod6: neato
asciilifeform: mod6: you have the kind that can be stored for >1y dontcha.
asciilifeform: (i theoretically have some, but must hoard them, for job interviews...)
asciilifeform: must be great having dayz off tho
asciilifeform: ;;later tell mircea_popescu http://trilema.com/2016/asscience/#comment-117057
asciilifeform: aha, then it turned into how asciilifeform is as dumb and unreflective as vorhees, or sumthing
asciilifeform: i dun see any surprised people
asciilifeform: l0l seemed like an obvious test.
asciilifeform: and then how.
asciilifeform: or is this pref legit where others are not
asciilifeform: so, e.g., mircea_popescu's lack of eagerness to be buggered, say, by six metre long black cock, is also 'from loathing and ignorance' ?
asciilifeform: and i don't argue it as a universal good, but as something i specifically want out of life.
asciilifeform: *sound f
asciilifeform: my 'gyro-boat' has a found foundation in my utter loathing of the company of the typical meatsack
asciilifeform: mircea_popescu: which pseudopod specifically did they argue 'matters' ? usd ?
asciilifeform: and, presumably, not realizing that themselves also do not matter
asciilifeform: the kind stuck in
asciilifeform never even heard of it before qntra
asciilifeform: waiwut i thought this was a fiatola exchange
asciilifeform: you can only, on a good day even, pay folks to tick the boxes in the 3-ring.
asciilifeform: this goes right back to mircea_popescu's old observation re 'jobsworths', i.e. that you can't actually ~pay~ folks to give a fuck
asciilifeform: sacrifice M04R!111
asciilifeform: 'haxx0r3d because did not use the standard amulet and did not sacrifice to Great Inca!11'
asciilifeform: and, likewise, 'Although Deterministic Keys is another CCSS Level 2 requirement and not Level 1, LLI recommends ShapeShift’s architecture be re-architected to make use of deterministic seeds.'
asciilifeform: << ahahahaha! finally the usgtronic payload
asciilifeform: 'Although this is required for CCSS Level 2 and not Level 1, LLI recommends that ShapeShift’s architecture be re-architected to require multiple signatures.... ...End-users should be presented with a P2SH address (or equivalent for its coin type) that is built from a script that requires 3 signatures – 2 signatures from online signing agents that exist external to ShapeShift’s infrastructure'
asciilifeform: as mircea_popescu might say, 'jobsworths bore something fierce'
asciilifeform: l0ltr0nic, or,
asciilifeform: 'Ledger Labs drafted an Employee Security Policy and an Infrastructure Security Policy that identify security procedures and protocols for the use of ShapeShift assets. Employees are required to read and sign the policies and submit identification to ShapeShift’s Human Resources department. This control helps ShapeShift achieve compliance with CCSS Level 2.'
asciilifeform: which i thought even in zimbabwe was baseline civilization
asciilifeform: apparently this 'standard' does not include basics such as server-logs-on-paper-tape
asciilifeform: 'LLI performed an assessment of the ShapeShift infrastructure against the CryptoCurrency Security Standard (CCSS). The assessment identified...' << holy FUCK what?!!
asciilifeform: ^ l0l!!11
asciilifeform: Simpson which had its log deleted. The last few lines of the log were overwritten with NULL (0x00) bytes, preventing digital-forensic recovery.'
asciilifeform: 'Analysis of Lenny’s Ubuntu operating system’s configuration revealed that – similar to Simpson – there was no logging or auditing configured beyond the default configuration that ships with Ubuntu. Analysis of the /var/log/auth.log file showed tampering via overwriting unlike
asciilifeform: trinque: but with faux btc ?
asciilifeform: how do folks not barf.
asciilifeform: http://btcbase.org/log/2016-04-18#1453376 << i still have trouble grasping the notion of 'tipping' outside the servility context (e.g., restaurants etc) ☝︎
asciilifeform: cosmic rayz!1111
asciilifeform: http://btcbase.org/log/2016-04-18#1453490 << just like me nodez!11 ☝︎
asciilifeform: everything's mystical to the fella who dun have to live it himself.
asciilifeform: or is good for nothing at all.
asciilifeform: but man without legs has to get pretty good with arms.
asciilifeform: nobody cancelled it, no
asciilifeform: l0l
asciilifeform: i am satisfied that our mircea_popescu has not been stolen!
asciilifeform: snore, ye olde 'mens sana in corpore sano' (tm) (r) aha
asciilifeform: dun make it so.
asciilifeform: http://btcbase.org/log/2016-04-18#1453427 << it is mircea_popescu'd ideological sauce that these are equivalent or even comparable, i get it. ☝︎
asciilifeform: old men are not reflashable, (though i hear, they ~are~ recyclable..)
asciilifeform: chix are reflashable.
asciilifeform: and mircea_popescu knows this,.
asciilifeform: there is not a cure for missed childhood development
asciilifeform: if mircea_popescu had said anything else i'dve worried that he were stolen and replaced by a cheap double.
asciilifeform: there is exactly one end.
asciilifeform: understand, i would rather seal hard disks against sea foam, than deal with humans.
asciilifeform: actually i would.
asciilifeform: phf: you don't
asciilifeform: l0l
asciilifeform: one type of item i deal with, like breathing. other - entirely useless in.
asciilifeform: understand the difference ?
asciilifeform: mircea_popescu: my heuristic is that i consider problems involving simple physical systems, thousands of years in test, as SOLVABLE. and those involving people/social skill, etc. NOT.
asciilifeform: or what
asciilifeform: or is actually a nuke sub funded by moscow ?
asciilifeform: mircea_popescu: so mr o's tub never leaks ?
asciilifeform: and yes, somehow life on ships is 'adolescentine male fantasy' to mircea_popescu but shooting tax collectors (who, where i live, come in tanks and with heavy machine guns, by the dozen) isn't...
asciilifeform: quite incidental.
asciilifeform: BingoBoingo: i just happened to go in one, on the way from place 'a' to place 'b'
asciilifeform: phf: understand, i find it appealing strictly from the escape-from-rent angle.
asciilifeform: and when they start to leak, they use the lift (comes with the slip rent) and drag the tub to the communal repair lot, and work.
asciilifeform: BingoBoingo: my understanding is that many of the folks doing the boat thing (and we have them even here in dc) don't go far from the parking dock.
asciilifeform: realize, the 2k/mo i wouldn't be paying in rent buys quite a few fixed leaks.
asciilifeform: spring a leak - fix it alone.