log☇︎
269300+ entries in 0.176s
mircea_popescu: asciilifeform FF FF still there.
asciilifeform: just that when you dance off its edge, required horsepower grows exponentially
asciilifeform: and this is not a hard bound, either
asciilifeform: between two public mods.
mircea_popescu: asciilifeform if you look at the 4kb thing i published : there's no actual contiguity. just fields of double FFs
asciilifeform: this may be enough to blow away a good fraction of extant gpg pubkeys.
asciilifeform: (anywhere in the mod pair)
mircea_popescu: let them figure out how to release software first.
mircea_popescu: anyway, i'm giving up on this bs. gnupg 2.0 doesn't even exist, contrary to nonsense noise on social media.
asciilifeform: boolcrap1: i promise, you'll like this one.
boolcrap1: I'm not sure im that dedicated to trilema yet
asciilifeform: boolcrap1: consider reading the channel log
mircea_popescu: arguably it's a lot more useful, too.
mircea_popescu: eulora builds ~500 times easier than this dumb shit.
asciilifeform: funnily enough, testing on a box that, long ago, used to have gpg2 working...
asciilifeform: i built it, refuses to run without 'gpg-agent'
mircea_popescu: dude the sheer insanity...
mod6: yah, this is just a test box.
mircea_popescu: what the fuck is this.
mod6: mircea_popescu: so, instead of doing all the things with --prefix, i just started straight out building all the deps and installing them.
mod6: ./.libs/libgcrypt.so: undefined reference to `log_hexdump'
mircea_popescu: you don't understand how the x works.
mircea_popescu: it just passes the test but dies on make nm
mircea_popescu: mod6 edit configure, the test above with your path.
mod6: i can'gnupg-2.0.30 to build either
mircea_popescu: ftr thee test is : if test "x$GPG_ERROR_LIBS" = "x"; then
asciilifeform: now for the magic moment.
asciilifeform: presently testing on a box that had the deps crapolade
asciilifeform: oh and on top of this,
mircea_popescu: so now, if i put the path in autogen.rc, nothing happens.
mircea_popescu: ARE THEY MAD???
asciilifeform: hey there was a reason i did not start with gpg2.
asciilifeform: that's the prefix the gpg2 abortion wants.
mircea_popescu: from autogen : "--with-gpg-error-prefix=@SYSROOT@" << what format does that take if not fucking path
asciilifeform: well if you want to do this the gentoo way, actually gotta build libgpgerror
asciilifeform: which is why 'let heathen box pull the binary deps'
mircea_popescu: you don't properly appreciate the chain of braindamage.
asciilifeform: build gcrypt normally other than the added hexdump line.
mircea_popescu: how do i build libgcrypt then ?
asciilifeform: you want this only when building gpg.
mircea_popescu: fucking nightmare. so the lib-error shit compiled, but obviously ./configure --with-libgpg-error-prefix="/home/mircea/gpg-2.0.30/libgpg-error-1.24/" does nothing, with or without quotes
asciilifeform: it will pull the deps you didn't tell ./configure about from the various pestholes they normally end up in.
asciilifeform: then build the new gpg2 as described here.
asciilifeform: fastest way to get all the deps is to simply grab a sacrificial (e.g., 'african') box and let it install gpg2
mircea_popescu: is it going to walk me one by one through the entire list of loserdom, lib"assuan" and whatnot ?
mircea_popescu: what the fuck is wrong with these people!
mircea_popescu: yet the makefile is right there ?!
mircea_popescu: make: *** No targets specified and no makefile found. Stop.
asciilifeform: you gotta build libgcrypt and then tell gpg's ./configure where to find it
BingoBoingo: asciilifeform: Good. You accepted Step 1. You are powerless over social media and all it does it eat your time.
asciilifeform: BingoBoingo: i'm not even bothering with that crapolade nao.
mircea_popescu: im going to try 1.7.3
asciilifeform: the copy i happen to have pulled from my arse at this moment is 1.5.1.
asciilifeform: put the hex dump RIGHT AFTER the 'mpi_set_bit(prime,0)' idiocy
asciilifeform: in libgcrypt, the thing is in cipher/primegen.c
mircea_popescu: ah that's what it was huh. standardization of diddling.
mircea_popescu: "put the key into an S-expression"
asciilifeform: so the lunacy isn't even CONTAINED in it
mircea_popescu: i'm still untangling wtf it does to get primes.
asciilifeform: mircea_popescu: if you built it, post the dump plox.
mircea_popescu: and you should see keygen.c THERE
mircea_popescu: asciilifeform incidentally their dumbass "manual" https://gnupg.org/documentation/manuals/gcrypt/Prime_002dNumber_002dGenerator-Subsystem-Architecture.html references /cipher/ which is gone in 2.0 trunk
asciilifeform pictures boeck, poor idiot, waking up at 4 in the morning, called to do his dooooty
BingoBoingo: So is S.NSA going to have a line item expense for alf.dope this month?
asciilifeform: at AT MOST 0.27 of the total, the rape is polynomial.
asciilifeform: the more known bits in modulus, the easier to reconstruct whole thing.
asciilifeform: no this is optimistic mircea_popescu .
BingoBoingo: ;;later tell pete_dushenski everything a person needs to know about dating can be found on Trilema
mircea_popescu: so basically... the best key produced by stock gpg is... wait for it... about 700 or so bits strong.
asciilifeform: if somebody wants to replicate on gpg 2.x, plox.
mircea_popescu: asciilifeform http://trilema.com/2016/werner-koch-confirmed-usg-stooge/ << admire the FF FF pairs, among other things.
mircea_popescu: jesus mother of holy shit, two different problems.
mircea_popescu: asciilifeform plox to qntra.
mircea_popescu: hm where the fuck does it spit the binary after all ?
asciilifeform: and this isn't even the koch scenario.
asciilifeform: do i need to keep going, draw a picture ?
asciilifeform: it is quicker to throw in the extra 'hexdump' line by hand, than to get the patch ducks in a row, imho.
asciilifeform: after this, you will need http://wotpaste.cascadianhacker.com/pastes/e63a6d1f-5f34-4be4-9e9f-0226dc8b8de2/?raw=true
mircea_popescu: the things you're an expert on ...
asciilifeform: but slow is better, less tearing.
asciilifeform: folks yer gonna have to take this road cone in, a few mm at a time.
asciilifeform: aaah did i ever mention that gcc 5.x won't build gpg 1.4.x ??
mircea_popescu: at it means to be a blogger[7] . These essays and this writing style are tempting to people outside the subculture at hand because of their engaging personal tone and idiosyncratic, insider's view. But after a while, you begin to notice that all the essays are an elaborate set of mirrors set up to reflect different facets of the author, in a big distributed act of participatory narcissism. "
mircea_popescu: I blame Eric Raymond and to a lesser extent Dave Winer for bringing this kind of schlock writing onto the Internet. Raymond is the original perpetrator of the "what is a hacker?" essay, in which you quickly begin to understand that a hacker is someone who resembles Eric Raymond. Dave Winer has recently and mercifully moved his essays off to audio, but you can still hear him snorfling cashew nuts and talking at length about wh ☟︎
mircea_popescu: pe I am not the only to find this highly suspicious.
mircea_popescu: " In Paul Graham's world, as soon as oil paint was invented, painting techniques made a discontinuous jump from the fifteenth to the twentienth century, fortuitously allowing Renaissance painters to paint a lot like Paul Graham. And the difficult problems the new medium supposedly helped painters solve just happened to resemble the painting problems that confront an enthusiastic but not particularly talented art student. I ho
mircea_popescu: this gotta be in the logs :
mircea_popescu: asciilifeform there is more to this yes/
mircea_popescu: oil painting replaced tempera in 1400 ? hoily shit what.
asciilifeform: mircea_popescu: upon reflection, there may exist also a mathematical relationship which allows BOTH mods to be broken.
mircea_popescu: also, i had never read that dabblers and blowhards essay before, but good god is graham unfucking bearable AND ALSO remarkably undistinguishable from every other foss idiot, from o reilly to who have you, if distilled like that.
mod6: indeed. and thank goodness for that.
mircea_popescu: anyway, seems proper tmsr-rsa will have to come sooner rather than later.
asciilifeform: (to the subkeys.)
asciilifeform: the correlant is the FIRST key generated (i.e. primary key)
asciilifeform: mircea_popescu: remember, the ~initial~ contents of the pool are entropic (at least in as far as the os provides)
mircea_popescu: asciilifeform also importantly, is it the first 20 or the last 20 ? he's claiming the last 20.
mircea_popescu: seems prepasterous in that such narrow space'd have been evident by now
mircea_popescu: situation : you go to make key with stock gpg, set it to 4096, ie 512 bytes. it makes you the sign key with 512 entropy bytes, then makes you the encrypt key wirth the remainder 68, and that's it.
asciilifeform: from my current reading, first 20 of every 600 is fixed, for the duration of entire run of process.