log☇︎
192600+ entries in 1.556s
mircea_popescu: where i live goes nudely swell.
mircea_popescu: i never heard of him
mircea_popescu: pretty cool vid i say!
ThickAsThieves: it's ok, now i'm sharpening my trading skillz
ThickAsThieves: but now i'm all set
ThickAsThieves: but i emailed him to check
ThickAsThieves: kako, I owned coinflow in the end
ben_vulpes: and there are enough on the table that i should be making odds on how many close
ben_vulpes: if these deals come through, i'm going to have such sweet projects lined up
mircea_popescu: <fluffypony> I can't take these bugs seriously without a logo and an info site << these bugs got no ux!
mike_c: i pwned his box for kicks too
kakobrekla: i just noticed - looking at logs - he is spamming my boxen
gribble: parseval was last seen in #bitcoin-assets 41 weeks, 5 days, 19 hours, 24 minutes, and 53 seconds ago: <parseval> though, really, I think banning banks from handling bitcoin transactions is a good thing
berndj-blackout: thanks, but i'm likely to be idle for a while. should work on my rating i guess
fluffypony: I can't take these bugs seriously without a logo and an info site
fluffypony: I hope someone made a logo
fluffypony: oh I see we're calling the Bash bug "ShellShock" now
ThickAsThieves: Darkstone1 this is how I trade at times
Darkstone1: no i'll look it up.
Darkstone1: except the one where a whale sells hundreds of bitcoins on all the exchanges where i'm active. But that probably a slim chance.
Darkstone1: asciilifeform It is no longer possible to do so. I belive i closed all gaps.
ThickAsThieves: shit i dont even trust stop orders
Darkstone1: I'm fairly sure i've met bots specially crafted to screw my bots at one exchange once...
asciilifeform: and yes, i must admit i worked on this. but let it go, from lack of hammer.
Darkstone1: And i am not an neobee bagholder. I sold everything after the crash and gained +50%.
kakobrekla: i see this everyday - what ascii is describing
Darkstone1: asciilifeform: i can partialy agree on that. But if i do not have an game-theory fitness ass raping bot. I tried but failed.
Darkstone1: at least i was.
Darkstone1: i consider myself a neobee invector :P
asciilifeform: (in fact, i suspect that any bot whose strategy is not a game-theoretical-finesse-rape of other bots - is quite useless) ☟︎
mircea_popescu: Darkstone1 i paid 10 dollars a month numerous times to trade pennies in online games
fluffypony: http://i.imgur.com/BPGsKbc.jpg
berndj-blackout: ah, i see, i'm too random i suppose
Darkstone1: i dont think anyone would pay 10 dollars a month to trade pennies.
Darkstone1: oh. I'm not so sure.
punkman: Darkstone1: no I just meant they'll never get to handle any serious amount of BTC
Darkstone1: punkpan: i use doubles. It's bad, i know. But it does not really matter as most exchanges send you the amounts in json floats anyway..
punkman: Darkstone1: yeah I doubt any of the hosted tradebots handle integer BTC amounts
mircea_popescu: this entire shitfest won't survive me i tellya!
mike_c: hm, i suppose the average teenager is.. 16?
Darkstone1: perhaps opinions of the masses differ.. but there is no way i'm going to insert my API keys in an online platform.
Darkstone1: I think there are too many -bad- platforms where people can put in their own stratety already.
BingoBoingo: <Darkstone1> can i ask you guys a question? I have an relatively succesfull trading bot (multi-digit bitcoin gain since the beginning of this year) but i an starting to lose intrest in further development. << Sounds like keeping it in your pocket until it interests you again may be the best option
Darkstone1: that i you shouldn't buy anything that you can't inspect the source for i can certainly agree with.
diametric: and i'd never run a trade bot i couldn't inspect the source for.
Darkstone1: One of the questions i've been unable to answer is weither should sell the source code or only the product.
Darkstone1: it certainly works, but as i said, i'm starting to lose intrest in further development. And i have a full-time job to attend to.
Darkstone1: I'm strugging in what the best way to 'commercialize' this thing is.
Darkstone1: can i ask you guys a question? I have an relatively succesfull trading bot (multi-digit bitcoin gain since the beginning of this year) but i an starting to lose intrest in further development.
Darkstone1: I don't do voice, sorry.
thestringpuller: dunno why I said "our"
thestringpuller: https://i.imgur.com/8U5cOHM.jpg << via our evoorhees
mike_c: oh. (smacks face) I was talking about author of exploit before, not bug. sorry for misinformation.
asciilifeform: i vaguely recall that mr. hearbleed was a pedigreed вредитель though.
mircea_popescu: Transcript for 24-09-2014, 1337 lines <<< we've done it, everyone. i hereby call the end of the #b-a party. thanks for all the lines, it's been a hoot etc!
mircea_popescu: so i just got totally outcarded. i find this nice chocolatier, buy three pounds of mixed chocolates in three boxes, ask for their card, and leave.
mike_c: of course. so you have vulnerable bash. doesn't mean someone can hit it through your web server. i guess i gotta construct applicable http request.
mircea_popescu: i also quoted a test for 6271 yest.
mircea_popescu: mike_c i just quoted it above
kuzetsa: mircea_popescu: I was just thinking the same thing
gribble: CVE-2014-7169: Bash Fix Incomplete, Still Exploitable | Hacker News: <https://news.ycombinator.com/item?id=8365158>; What is the CVE-2014-6271 bash vulnerability, and how do I fix it?: <http://askubuntu.com/questions/528101/what-is-the-cve-2014-6271-bash-vulnerability-and-how-do-i-fix-it>; (CVE-2014-6271) bug introduced, and what is the patch that fully: (1 more message)
kuzetsa: yeah, I have 7169 patched
mircea_popescu: ThickAsThieves: i often think about that, how the hell can someone who cannot/willnot read code, ever be the steward of a software project safely? <<< you know i don't actually read all that much code at all. i guess i could, more or less, but i wouldn't trust myself to understand it. by which i don't mean "what it does", but i do mean "what we can absolutely say about this program"
kuzetsa: Naphex: yeah, I decided to compile a new kernel anyway so I rebooted after making sure bash was patched :)
kuzetsa: mike_c: I'm certain that the public-internet-facing daemons on the system in question don't pass stuff around using environment variables
mike_c: shit, i gotta read more.
mike_c: yes, but i thought shocky thingy required cgi/bash to chane env
kuzetsa: Naphex: I don't have any mail daemon on that particular system either
asciilifeform: also it is possible that i used a bad example. man has indeed invented hydrogen bomb. but securing 50 years of turdolade by 'fixing mistakes' is more akin to jumping 1km. no athlete has jumped 1km, and beatings will not create one.
kuzetsa: Naphex: I don't use apache
kuzetsa: mircea_popescu: but... I don't have any cgi on the httpd, nor are any of the other daemons the sort which use environment variables to pass stuff around (using bash or otherwise)
mike_c: if i wrote a new btc wallet (or managed development thereof), it would be secure for fear of above methods
mircea_popescu: if he says this sitting right next to a lathe i'm going to smack his head on the lathe.
asciilifeform: context of 'i need a box of bullets'
mircea_popescu: as long as you let me beat them selectively i'll have my bomb, and some adoring princesses to follow me around to boot.
mircea_popescu: i will, yes.
mircea_popescu: i don't think you properly understand grinding.
kuzetsa: Naphex, asciilifeform: yeah... I've had to stop neglecting a production server and finally run updates today because of shellshock :(
wywialm: I recall something close stated in Investigations, in the flavour of "the meaning is use"
wywialm: mircea_popescu, that sounds very much like Wittgenstein - correct me if i'm wrong
mircea_popescu: which is why you can have good programmers that speak english, russian or whatever else natively, as well as c or lisp or whatever else ; but you can't make someone a good programmer by teaching him to say i++;
mircea_popescu: bounce: now it would help if we can properly articulate what ails us. but we can't, because the terminology has been deliberately confused and watered down and broadened and stretched (by the industry) so as to spread FUD more effectively << you are very naive to imagine the terminology has anything to do with it. point in case : if in a room with a woman that wants to fuck me, i don't need to speak her language. point
gribble: Dekker3D was last seen in #bitcoin-assets 11 weeks, 4 days, 0 hours, 40 minutes, and 47 seconds ago: <Dekker3D> I remember someone who used this.
asciilifeform: i finally realized - they cribbed the 'dust bin' from -- apple.
asciilifeform: jurov: am i the only one who instantly thought 'dust bin' ?
jurov: http://bitstash.com/ such gems i keep finding today. hardened bluetooth!!1
mircea_popescu: in unrelated news : i've added an email filter rule to drop anything with "bounce" in the headers. best rule ever.
Naphex: i'm always here :P
nubbins`: "those tippies are unusually smooth", i said to myself
kakobrekla: https://i.chzbgr.com/maxW500/8328379648/h92418905/
rithm: but now i sound like atlas
rithm: the bitcoin society is most likely fraternal too if I had to bet
rithm: i've been thinking bitpay's bowl gam sponsorship was a play to get bitcoin in ncaaa stadiums
ThickAsThieves: yeah i think this year's lows may never be seen again
mats_cd03: my principle concern is getting to 1000btc. i don't know if it can be done, at the current rate of career progression... i need a better job.
asciilifeform: ThickAsThieves: at present, the door opens when i open it. just end up having to go back inside to eat.
mats_cd03: i can't afford to flee. i have yet to bump four digit vidya game coins.
mircea_popescu: i only pay on reception, and if acceptable. never had anything but the loveliest most serviceable contractors.
ThickAsThieves: i was thinkin, why didnt they just scan forge it, cmon now
mircea_popescu: ThickAsThieves: like i couldnt recognize my own sig... << the hand signature thing in the us is nuts by now.