log☇︎
254100+ entries in 0.114s
asciilifeform: there are dumb isps where i live, that want you to use their router. most of them are easily dealt with (MAC spoof)
asciilifeform: bounce: you're using a router supplied by other people ?!
asciilifeform: (lives on its own bus, too. because basic literacy.)
asciilifeform: and never a key
asciilifeform: so the card only sees crypted blocks.
asciilifeform: cardano uses a micro-sd card for storage, and assumes that said card was built by the devil
asciilifeform: e.g. icon parser overflows, etc.
asciilifeform: anyone who does, and uses an external drive that faithfully stores bits (no micro diddling) is vulnerable to a world of fun
asciilifeform: re: usb: it is important to remember that using winblows is a strictly voluntary surrender.
asciilifeform: this subject has been beaten to death in engineering literature
asciilifeform: in the sense that a recent 'ssd' would barely last a few thousand write cycles without leveling.
asciilifeform: generally, the newer the 'flash', the more threadbare the actual eeprom cells
asciilifeform: bounce: they do.
asciilifeform: most of the available ones are designed to be reflashed via usb
asciilifeform: incidentally, this is one of the reasons it took me so long to find an appropriate micro for cardano
asciilifeform: but it is worth pointing out that many, if not most, usb gadgets - are.
asciilifeform: not from usb.
asciilifeform: mike_c: cardano emulates a usb drive, when connected to pc.
asciilifeform: http://www.irongeek.com/i.php?page=security/plug-and-prey-malicious-usb-devices
asciilifeform: and then there's the winblows-specific crap, which i regard as uninteresting:
asciilifeform: i've tried this personally - it works. (you need a drive for which either docs or some reverse-engineerable flash diddler from the factory are available.) ☟︎
asciilifeform: usb keys have been penetrated before << this refers to various experiments where you re-flash the microcontroller inside a usb drive, to do various useful things.
asciilifeform: whether this has anything to do with practical security is a puzzle for students of u.s. bureaucracy.
asciilifeform: now, these gadgets are blessed by a priest, sprinkled with holy water before deployment, etc.
asciilifeform: (trivial example: anything that enciphers/deciphers)
asciilifeform: but this is not mandatory - there are plenty of gadgets with 'red' and 'black' connectors on one panel
asciilifeform: everyone's seen the photos of the general sitting next to two keyboards, two monitors, etc.
asciilifeform: incl. power supplies
asciilifeform: it is mainly about separating wiring for 'red' (plaintext that must not leave) and 'black' ciphertext that can go outside the walls
asciilifeform: handbook that describes design of airgapped systems (the red/black system design philosophy) << read the crap. red/black has nothing to do with airgaps, for the most part.
asciilifeform: https://www.google.com/search?q=вундервафля&source=lnms&tbm=isch
asciilifeform: 'вундервафля'
asciilifeform: it's a derisive poke
asciilifeform: naturally.
asciilifeform: ('wunderwaffe' original)
asciilifeform: i'll take the liberty of translating the russian expression for these - 'wonderwaffles'
asciilifeform: anyone who had the misfortune of attending u.s. schools is in for a little mindfuck - the evidence that sk (at the behest of its puppeteer across the ocean) started the korean war is, imho, convincing.
asciilifeform: personally i've no evidence in favour or against the 'they've got the pill and are sitting on it' hypothesis
asciilifeform: what, if anything, they have to show for it, is another matter
asciilifeform: these people claim (not entirely implausible) to be the largest employer of math phd types in the usa
asciilifeform: cads: likewise no leaks from the math farms.
asciilifeform: not that i know of
asciilifeform: mircea_popescu: rezun (pseudonym suvorov) and his histories of gru, which he ran away from
asciilifeform: nsa writes crapware for winblows, 'meta-nsa' then would do something interesting.
asciilifeform: it's mostly a product of my diseased imagination, but has some grounding in soviet history
asciilifeform: cads: the two-nsa hypothesis is that the americans have a stable of folks with brains squirreled away somewhere
asciilifeform: which topic? cunt cum angler-fish?
asciilifeform: lol
asciilifeform: because you can only really use it once.
asciilifeform: it's a pill that would be kept in reserve for some unspecified 'dire times' that never come - as nukes are
asciilifeform: see winston churchill and the demolition of coventry.
asciilifeform: the interesting thing is that nsa-as-we-know-it, but with a pill against modern crypto hidden in an 'indiana jones'-style vault, would scarcely be distinguishable from what we can now see
asciilifeform: phone should be regarded as something like plaintext email.
asciilifeform: cads: are you familiar with the 'two NSAs' hypothesis?
asciilifeform: rather than plain stripe bits.
asciilifeform: yeah - but the new turd craps out a blob rsa'd to square's public key.
asciilifeform: (original 'square' reader was usable by any machine that had a 3.5mm headphone jack)
asciilifeform: the more realistic explanation is that they didn't care to see people write magstripe stuff using their reader
asciilifeform: most cards have multiple tracks.
asciilifeform: alignment is critical
asciilifeform: (these, and stacks of blank cards, sell on ebay every day)
asciilifeform: as if these had any trouble buying chinese readers
asciilifeform: excuse was, if i recall, that scammers will use the reader to lift cc #s.
asciilifeform: amazing what people are willing to spend on inserting antifeatures.
asciilifeform: (old)
asciilifeform: http://hackadaycom.files.wordpress.com/2012/04/square.jpg?w=470&h=136
asciilifeform: (new)
asciilifeform: http://venturebeat.files.wordpress.com/2012/03/square1.jpg?w=716
asciilifeform: just so people couldn't use it as a generic magstripe reader.
asciilifeform: i set the 'bozo bit' on 'square' when they caved in to the FUD and replaced their purely-analogue card reader with an elaborate crypto turd
asciilifeform: lol
asciilifeform: nubbins`: i wonder if anyone would buy a casascius coin that i've touched, after what i said about them
asciilifeform: i do believe that my kitchen floor will collapse 'when', not 'if'
asciilifeform: not far off is the day when the black mold outweighs me, gram for gram.
asciilifeform: hell, to mars.
asciilifeform: BingoBoingo: i'd move to antarctica if there were work there.
asciilifeform will soon have finished 7th year in a 30 m^2 flat.
asciilifeform: if only we had that 'rental starter' crap here.
asciilifeform: it is always one thing to read a philosophical bit, and another to taste it on one's sorry skin
asciilifeform: apparently one of the things you can't get for these is: rental house in the wash. dc metro area.
asciilifeform: for those who remember mp's essay about bezzle-dollars:
asciilifeform: MisterE: reminiscent of the 'is my bank card stolen' service.
asciilifeform: or, almost all.
asciilifeform: but, for some reason, they are all very far away.
asciilifeform: plenty of people know how to program.
asciilifeform: aside from 'have useful idea, mp might invite you as co-author'
asciilifeform: how difficult is it to get listed on mpex... kakobrekla asciilifeform etc could comment on it << i still have no idea what to say to hypothetical random people who want to be listed.
asciilifeform: damn i leave for one day to do meatspace crap and miss all the fun.
asciilifeform: mircea_popescu: http://trilema.com/2014/snsa-march-2014-statement << looks correct.
asciilifeform: ;;gpg everify freenode:#bitcoin-otc:6d513a0718c57a04a7b7789d1718a0451eb1f4173191a8c2476bf21b
asciilifeform: ;;gpg eauth asciilifeform
asciilifeform: mircea_popescu: i marvel that she lasted this long - my dosimeter turns full black from just reading that phorum for a few min.
asciilifeform: i thought she just moved to new forum?
asciilifeform: lol
asciilifeform: '“It couldn’t be stupider, and that’s why it’s brilliant,” he concluded.' << me brain dumped core.
asciilifeform: ('dejanews')
asciilifeform: not my fault these bozos bought the world's only reasonably-complete usenet archive.
asciilifeform: https://groups.google.com/d/msg/soc.singles/5bYxszUQKDY/05P-h5JY6YEJ
asciilifeform: example of quality mocsny:
asciilifeform: https://groups.google.com/d/msg/soc.singles/5bYxszUQKDY/o8fkGj7yEzEJ