log☇︎
177500+ entries in 0.063s
asciilifeform: even got a sun photodiode mouse (but misplaced the reflector!)
asciilifeform: l0l i still have one of those somewhere.
asciilifeform: phf: lulzy gadget: draws so much current that the battery has to be changed daily. it pulls out, like pistol clip, and changes places with identical, included stick, that charges in the radio receiver
asciilifeform: phf: the weights ought to be trotyl
asciilifeform: various nice touches. e.g. the wheel well goes all the way through, does not collect shit like normal mouse
asciilifeform: (this is not clear from the photo, but the 'wings' are on long screws and... can move)
asciilifeform: http://www.xoticpc.com/images/accessories/mice/rat9_02.jpg ☟︎
asciilifeform: it already looks quite like one...
asciilifeform: it is very neat. but, what to do with the extra buttonz !
asciilifeform: 'rat 9' ☟︎
asciilifeform got a spiffy gift from a phriend, a mouse where various pieces of the chassis can move around to fit the hand, various iron knobs. endlessly tunable thing. had no idea this existed.
asciilifeform honoured
asciilifeform: mmm
asciilifeform: fully 90% of what was in the camera, even.
asciilifeform still needs to post his recoleta pics
asciilifeform goes off to eat dinner before it dies a 2nd time
asciilifeform: l0l
asciilifeform now will have to prove, pissed
asciilifeform: whaddayamean, i gotta prove
asciilifeform: mno.
asciilifeform: yes, expensive.
asciilifeform: mircea_popescu: can do a one-to-many permutation.
asciilifeform: (and especially not close in the phase space of cryptographic malleability, for the kind of crypto in use)
asciilifeform: mircea_popescu: 'padding' is a misnomer for a variety of possible processes, all of which have the objective of making sure that a message is never close in phase-space to another plausible message
asciilifeform: iirc it was midnightmagic
asciilifeform: phf: nah it'll be quick and humane, more of a michael hastings sort of affair.
asciilifeform: yes
asciilifeform: the 'padding' thing is an entirely separate animal
asciilifeform thinks 'sic transit gloria mundi'
asciilifeform: in ~that~ sense alone, a hash is a cheque drawn on a total unknown.
asciilifeform: today - gigabux, tomorrow - penny (pointedly ~not~ because of any advance in cpu, but on account of mathematical efforts)
asciilifeform: and in most cases it is not in any way knowable.
asciilifeform: the only question concerns the difficulty of finding said collisions
asciilifeform: thing re: hashes is that every hash, being a many-to-one function, is by definition guaranteed to collide.
asciilifeform: 'and passing moduli around bloats messages'
asciilifeform: normally everybody proposes it and then writes it off as 'we haven't the cpu or the entropy'
asciilifeform: mircea_popescu did propose putting it to battlefield use
asciilifeform: and symmetric crypto is also not made use of.
asciilifeform: where nothing needs to be hashed.
asciilifeform: and to that we have analogy: the pure-rsa variant
asciilifeform: (he had a whole host of motionless pneumatic building blocks based on vortices)
asciilifeform: tesla begs to differ
asciilifeform: hash is the proverbial 'hole through which the night walks in'
asciilifeform: the weaker the hash, the more 'promise' and less 'protocol'.
asciilifeform: systems which rely on a hash, ultimately contain trace elements of 'promise'
asciilifeform: the fundamental issue that bothers me is that a broken hash is where 'protocol' begins to decay into 'promise'
asciilifeform: but i suggested it some months ago, and so it is conceivable that it will.
asciilifeform: not afaik
asciilifeform: let's picture, say, an isis beheading is held on top of a banner containing an fp
asciilifeform: 'quod licet' usg 'non licet bovi' (tm)
asciilifeform: sitting between them
asciilifeform: phf: this only leads to laughs unless you can somehow be there for the rest of the two would-be pen pals' lives
asciilifeform: the other thing is, to the extent that the integrity of the wot as we now have it is predicated on sha1 not costing a penny to break, some of the sweat that went in to forming the wot may end up having to be re-sweated
asciilifeform: no mega-shocking result - pgp is not a magical fountain of phree-energy-style 'trust from the aether', but rather an amplifier of trust established - to some extent - in the meat.
asciilifeform: this of course demonstrates the point mircea_popescu made earlier, whereby no one who he was not properly introduced to, could ever hope to escape this.
asciilifeform: deedbot, then
asciilifeform: and the matching hitler key, for the key normally appearing in http://trilema.com/contact-pgp
asciilifeform: other thing is, the problem goes a little deeper. one might craft, for instance, a filter which eats mircea_popescu's www and substitutes hitlerine signatures for all of the signatures contained therein.
asciilifeform: my original observation, though, stands - the time to stop thinking of pgp 64bit fp as 'the man' is not when arbitrarily colliding sha1 costs a penny! it is now. ☟︎
asciilifeform has intended to produce one for a long while, but it is not a priority presently
asciilifeform: they are candidates for the treatment described earlier.
asciilifeform: with a modest expenditure of cpu.
asciilifeform: because they can be derived from signed material
asciilifeform: the one thing remaining to add is that, theoretically, it is not necessary to distribute pubkeys at all!
asciilifeform: the basic result here is that pgptronium is conserved, if you will.
asciilifeform: aha
asciilifeform: 'here is me, and this is my pgp' also works, is what i meant.
asciilifeform: also works.
asciilifeform: (if you can meet in the flesh, you could exchange one time pads just as well)
asciilifeform: that is, the idea was that it is not necessary to meet in the flesh to form a working relation
asciilifeform: the part that bugs me is that the fundamental premise of public key crypto is a kind of downer
asciilifeform: et al.
asciilifeform: or al schwartz
asciilifeform: but if knuth wants to write in - then tough cookies.
asciilifeform: aha.
asciilifeform: instead it'd be a funkspiel between hitler and mr schmuck, the latter having believed that he is speaking to mircea_popescu
asciilifeform: mircea_popescu: except the ideal scenario for firing this weapon is precisely a case where the resulting message never reaches mircea_popescu
asciilifeform: not on account of rsa per se.
asciilifeform: solely because rfc2440/4880 is retarded
asciilifeform: (it is conceivable that one might produce a key which will verify mircea_popescu's signed body of works, but which, if encrypted to, resulting ciphertext could be read both by mircea_popescu AND by hitler.)
asciilifeform: and this still is predicated on an assumption, to date unproven, that rsa sig operation is not malleable.
asciilifeform: really, it is 'key plus body of signed material' is a man.
asciilifeform: the point i wanted to make is that the original attitude of 'keys are people' was predicated on ideally 'stiff' keys
asciilifeform: and anyone else who'd make a satisfying splat.
asciilifeform: for this bullet.
asciilifeform: they then are the targets.
asciilifeform: large volume of material, afaik none of it signed.
asciilifeform: there are also people who are not really mute by any reasonable definition but this one. e.g., knuth
asciilifeform: sure. those bedeviled with... ideas
asciilifeform: if anything, the net needs more, rather than fewer, of them
asciilifeform: but i disagree that folks who largely listen, and seldom talk, are necessarily 'idiot'
asciilifeform: !b 1 ✂︎
asciilifeform: pattern: folks who 1) are somehow interesting (german number theorists, etc) 2) have a very threadbare, if at all present, volume of published signed material 3) communicate their key to other people largely in the form of a fingerprint
asciilifeform: aha, hence 'archive.org'
asciilifeform: as to where the bullet might be aimed, the phuctor dataset suggests a certain pattern
asciilifeform: how about assbot?
asciilifeform: where does btcalpha get its pubkeys ?
asciilifeform: https://web.archive.org/web/20100430025638/http://imc.org/ietf-openpgp/mail-archive/msg30980.html << mainly interesting for having been deleted from the ml
asciilifeform: (how found - not specified)
asciilifeform: mircea_popescu: https://github.com/coruus/cooperpair/tree/master/pgpv4 << contains, iirc, example of collision