log☇︎
214400+ entries in 0.147s
deedbot: http://trilema.com/2017/the-storied-cupcake-and-other-stories/ << Trilema - The Storied Cupcake and other stories
deedbot: http://phuctor.nosuchlabs.com/gpgkey/992134A45E95AE9AED64792AE64FE334354617FE33B4DE355FBDE4E3D82798BD << Recent Phuctorings. - Phuctored: 1562...6647 divides RSA Moduli belonging to '38.96.32.1 (ssh-rsa key from 38.96.32.1 (13-14 June 2016 extraction) for Phuctor import. Ask asciilifeform or framedragger on Freenode, or email fd at mkj dot lt) <ssh...lt>; ' (Unknown US CA)
deedbot: http://phuctor.nosuchlabs.com/gpgkey/992134A45E95AE9AED64792AE64FE334354617FE33B4DE355FBDE4E3D82798BD << Recent Phuctorings. - Phuctored: 1575...1223 divides RSA Moduli belonging to '38.96.32.1 (ssh-rsa key from 38.96.32.1 (13-14 June 2016 extraction) for Phuctor import. Ask asciilifeform or framedragger on Freenode, or email fd at mkj dot lt) <ssh...lt>; ' (Unknown US CA)
deedbot: http://phuctor.nosuchlabs.com/gpgkey/97C29455A45F36568DD279D71FAFBE63624E7C2630F5B764C56D8418E0EDCACB << Recent Phuctorings. - Phuctored: 1387...5559 divides RSA Moduli belonging to '211.234.125.52 (ssh-rsa key from 211.234.125.52 (13-14 June 2016 extraction) for Phuctor import. Ask asciilifeform or framedragger on Freenode, or email fd at mkj dot lt) <ssh...lt>; ' (Unknown KR)
deedbot: http://phuctor.nosuchlabs.com/gpgkey/97C29455A45F36568DD279D71FAFBE63624E7C2630F5B764C56D8418E0EDCACB << Recent Phuctorings. - Phuctored: 1404...8569 divides RSA Moduli belonging to '211.234.125.52 (ssh-rsa key from 211.234.125.52 (13-14 June 2016 extraction) for Phuctor import. Ask asciilifeform or framedragger on Freenode, or email fd at mkj dot lt) <ssh...lt>; ' (Unknown KR)
trinque: the fuck are you people talking about, blank
a111: Logged on 2017-02-23 23:53 asciilifeform: and holy mother of fuck, jurov , why does your thing mangle '@' into 'at'
mircea_popescu: which burial should hopefully occur this year, it's getting ridiculous already.
ben_vulpes: http://btcbase.org/log/2017-02-24#1617558 << this was a huge boon to me at one point as well ☝︎
phf: i kind of want a way to link useful assets to a patch on btcbase. right now if you have a readme.txt inside a patches folder you get that included as a prelude for a patchset (http://btcbase.org/patches?patchset=fg). i think it would be handy to include wires over ssh link somewhere on the wires patch page..
shinohai: Baloney exchange is on there too .... but majority of exchanges use crapflare so likely affected.
phf: asciilifeform: that's some neat hackery
lobbes: http://btcbase.org/log/2016-03-03#1421109 << btw, thank you for this, alf. I will be embarking on my own gentoo quest soon to finally stand up a trb node ☝︎
deedbot: http://phuctor.nosuchlabs.com/gpgkey/C300E7F53E93306CE671E9C2BEE2440C21AE8142202BD8E090FFA40BFF361FDA << Recent Phuctorings. - Phuctored: 1718...3643 divides RSA Moduli belonging to '50.16.76.136 (ssh-rsa key from 50.16.76.136 (13-14 June 2016 extraction) for Phuctor import. Ask asciilifeform or framedragger on Freenode, or email fd at mkj dot lt) <ssh...lt>; ' (ec2-50-16-76-136.compute-1.amazonaws.com. US VA)
deedbot: http://phuctor.nosuchlabs.com/gpgkey/C300E7F53E93306CE671E9C2BEE2440C21AE8142202BD8E090FFA40BFF361FDA << Recent Phuctorings. - Phuctored: 1372...0663 divides RSA Moduli belonging to '50.16.76.136 (ssh-rsa key from 50.16.76.136 (13-14 June 2016 extraction) for Phuctor import. Ask asciilifeform or framedragger on Freenode, or email fd at mkj dot lt) <ssh...lt>; ' (ec2-50-16-76-136.compute-1.amazonaws.com. US VA)
deedbot: http://phuctor.nosuchlabs.com/gpgkey/B6F7716FB330D2289C4738E5469CA944BBE9C65BD00099E4F03A5EAB8049E80F << Recent Phuctorings. - Phuctored: 1591...6403 divides RSA Moduli belonging to '87.237.120.158 (ssh-rsa key from 87.237.120.158 (13-14 June 2016 extraction) for Phuctor import. Ask asciilifeform or framedragger on Freenode, or email fd at mkj dot lt) <ssh...lt>; ' (nb2508.virtualhosts.netbuild.net. DE)
deedbot: http://phuctor.nosuchlabs.com/gpgkey/B6F7716FB330D2289C4738E5469CA944BBE9C65BD00099E4F03A5EAB8049E80F << Recent Phuctorings. - Phuctored: 1453...7459 divides RSA Moduli belonging to '87.237.120.158 (ssh-rsa key from 87.237.120.158 (13-14 June 2016 extraction) for Phuctor import. Ask asciilifeform or framedragger on Freenode, or email fd at mkj dot lt) <ssh...lt>; ' (nb2508.virtualhosts.netbuild.net. DE)
asciilifeform: i could even picture that the original plan included offering d00d antidote, if he comes along..
mircea_popescu: asciilifeform the administration route is terrible, how the fuck do you dose the ingestion through splashing.
asciilifeform: complicated. pediwikia lies, paralysis of breath is not the only problem.
mircea_popescu: also, the russians would have probably ventilated their guy into ~survival.
mircea_popescu: i dunno that guy who got splashed vx would go around complaining that hey, i got splashed ten minutes ago.
asciilifeform: (pupils the size of pinholes, etc)
asciilifeform: btw i find it strange that the local orc docs did not notice classical picture of organophosphate poison
mod6: <+asciilifeform> [BTC-dev] (EXPERIMENTAL) A Recipe for the use of Wires via SSHITunnels. << cool! thanks alf.
asciilifeform: it is a liquid, similar to motor oil, at room temp
asciilifeform: ( or butyrylcholinesterase, or one of the other lulzies asciilifeform worked on when slaving for usg )
asciilifeform: https://archive.is/HBLyJ << vx, claimed. was my suspicion also. chick prolly fed , e.g., pralidoxime, ahead of doing the deed.
asciilifeform: (stock trb will happily drop ~anyone~ on the floor, for dozen different reasons, incl. 'we used him for too long')
asciilifeform: the essential thing is nondisconnectable nodes.
asciilifeform: it was made for 'g', the ssh thing is temporary.
asciilifeform: wire is agnostic of tunnelator.
asciilifeform: iirc mpb also had something equiv. to 'wire'.
asciilifeform: can't help but wonder how much, or little, theirs resembles mine. just as brits wondered how much nazi 'freya' radar, resembled brit radar
mircea_popescu: why's that lulzy
asciilifeform: lulzily enough, back in.. 2013..? mircea_popescu described how Serious Folx, incl. miners, already do this.
asciilifeform: unbitflippable direct pipe to large trb node.
asciilifeform: ultimately i'ma tear down the tunneltron and replace with 'g'. but same idea, topologically.
asciilifeform: (any takers..?)
asciilifeform: also mircea_popescu the 'node as paid service' thing now can actually exist.
asciilifeform: and happily chat on it, like cat talks to mirror
asciilifeform: my wired nodes still find each other via addr.dat and open ~second~, plaintext tcp pipe...
asciilifeform: phun phakt: the 'anti-selfconnect nonce' in bitcoin, never worked
mircea_popescu: !negrate asciilifeform typos.
asciilifeform: also http://therealbitcoin.org/ml/btc-dev/2017-February/000252.html has typo! and nobody noticed!!1 chown oughta be, of course, chmod.
asciilifeform: the emperor is the earliest, known to me, inventor of 'specificity of diddling' lemma. see logs, very informative.
mircea_popescu: what i'm more interested in is this apparent limit on "what can be thought about" based on some sort of i'm not even sure what. is it the case that i can't think about women now ?
asciilifeform: veen: let's try a historical angle. according to legend, emperor qin shi huangdi (same d00d as known for taking the 'immortality pill' and promptly croaking) had a palace with 1,500 rooms. and would not tell anyone in advance which one he plans to sleep in on a given night. and which ones he would put cutthroats in, ready to kill anyone who opens door. think 'minesweeper.' ☟︎☟︎☟︎☟︎
veen: forget it, it's a low value point i've already attempted to make
mircea_popescu: i confess i have nfi what you're talking about.
a111: Logged on 2017-02-24 02:15 asciilifeform: without seeing the rack, you don't know which ones -- if any -- are fg; and which one is my air conditioner; etc
veen: i suspect we'll never reconcile the "must build snow-flake" paranoia with drive to make architecture which can be reasoned about
a111: Logged on 2017-02-23 23:52 asciilifeform: [BTC-dev] (EXPERIMENTAL) A Recipe for the use of Wires via SSH Tunnels.
asciilifeform: i have this duo, scrolling on opposite lcds
mircea_popescu: it's worth keeping a farm of vartious nodes just to watcdh them struggle with the chain. pretty interersting data.
asciilifeform: veen: it isn't that it is a catastrophically bad idea, compared to what is currently on your box -- rather, it is an example of something you do not want to cement in long-term use
mircea_popescu: a ok. that.
mircea_popescu: yeah, see teh log.
veen: is this new as of the SHA1 nooze yesterday?
mircea_popescu: the only thing is that gpg is already obsoleted becauyse of its inane fingerprinting scheme
veen: sounds like solution for gpg is rip out `char shitprng();` implementation and replace it with one that calls a trusted noise source
mircea_popescu: listen to the words of he who suffers this weekly with eulora.
asciilifeform: during the great wild goose chase.
mircea_popescu: lol he escaped the slashes, isn't he adorable :D
veen: by that token s/\/dev\/random/\/dev\/fg/g again gpg src doesn't help us either
mircea_popescu: asciilifeform stronger argument than it seems. leaving aside the static issue, it's not even a given gpg compiles at all.
veen: userland shitprng is a wrinkle indeed, one i wasn't aware of until this thread
mircea_popescu: so it may make sense as a convenience thing to symlink it to your fuckgoats tty. but don't expect you've now thereby fixed the system
mircea_popescu: well the only argument pro i'm aware of is "it's there already"
veen: what is at issue at this point is use of /dev/random at all, regardless of how it is implemented
mircea_popescu: yes. but if you then turn around and feed that into userland shitprng, you've not impoved anything.
veen: surely we all agree that linux-csprng < FUCKGOATS
mircea_popescu: that sameness allows the enemy some levers it needn't have, first of all in its own safety's sake.
veen: proposal is replace output of linux csprng-crazy that underlies /dev/random with the output of FUCKGOATS
mircea_popescu: actually, the sentiment here is that ~all usg code is just reused scraps of the same stale old crap. this sentiment is fed by you know, us having cut up the usg toys numerous times and having run into the same bits.
veen: but it sounds like the sentitment here is using a well-known noise fountain is a vulnerable one
veen: to explain my reasoning by way of donning my engineering hat, i saw an existing contract of the form "noise comes out here" and a deficit default implementation, and proposed a better impl
mircea_popescu: because cryptography deals with absrtacts only, the kerckhoffs standard makes sense. but whenever items with an associated mass are involved, things change.
mircea_popescu: cryptographical security is one thing ; operations security is another.
mircea_popescu: would you propose the usg "invisible fighter" program is "security through obscurity" ? because... it is.
asciilifeform: veen: security through not conveniently labeling 'here i keep the crown jewels' in advance. it multiplies.
veen: security through obscurity eh?
asciilifeform: without seeing the rack, you don't know which ones -- if any -- are fg; and which one is my air conditioner; etc ☟︎
veen: so you've got /dev/fg0 thru /dev/fg9
asciilifeform: as opposed to 'just break /dev/random'
asciilifeform: and the work is 100% unique to the setup, which is not known in advance to anyone
asciilifeform: takes actual work to determine
mircea_popescu: review the thread re centralization recently. it's centralized at the sane place.
asciilifeform: veen: i, for instance, am sitting in front of a box with 11 hardware ttys
veen: seems gpg tried to sovereignty-wash a source of entropy and here it is bearing your criticism anyway
mircea_popescu: so, you may not ~care~ to compile them all ; but whether you are interested in war or not -- war is interested in you.
mircea_popescu: and gpg is not very far off this ; neither are ALL usg produced programs you are running.
veen: not sure that recompiling gpg to read from /dev/fg really frustrates enemy all that much
a111: Logged on 2017-02-24 01:40 veen: oh it runs output of /dev/random through it's own ('cs')prng?
mircea_popescu: http://btcbase.org/log/2017-02-24#1617373 << the importance of this can't be understated. if f(x) = 4 it matters VERY little what 'rng" you feed f. ☝︎
asciilifeform: which is why /dev/random was a terrifyingly bad idea from day 1./ ☟︎
asciilifeform: veen: specificity-of-diddling. by using one centralized entropy pool that the os knows about, you make enemy's work slightly easier.
veen: my reasoning is that if the semantics of /dev/random is that, taken over infinity, it emits flat spectrum of octects, and lots of binaries in the wild have that assumption baked it, why not coax kernel into allowing FUCKGOATS to fulfill the contract of /dev/random directly?
asciilifeform: there is (not yet released) 'p', mentioned in earlier thread today, which will eat from 1 or more FGs
asciilifeform: there are also others ( e.g., generating onetimepads; or in general input for any proggy that sanely eats input )