log☇︎
443700+ entries in 0.255s
mircea_popescu: you'd be surprised. those damned things... i've had one for a decade.
decimation: likely, the cr1203 battery wouldn't last that log
mircea_popescu: yeah it's good for a decade, since we have ~2 hours to spare
decimation: my reading of the spec sheet is that combined aging and temperature stability (assuming 0-40C) would be about 8.5 ppm
decimation: unlike alot of the other rtcs, the crystal is on-chip and temp compensated
shinohai: Fer crissakes I forgot to partition fr.
punkman: the "spam" is now up to 0.00034513 fee
asciilifeform: what's on the drive ?
assbot: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges ... ( http://bit.ly/1fr43lp )
mircea_popescu: the dram thing ?
shinohai: I could send to deedbot or something?
shinohai: but not trilema, and nothing in spam folder so i dunno :/
shinohai: I dunno. I get the dev mailing list.
assbot: You rated user danielpbarron on 29-Jul-2014, with a rating of 3, and supplied these additional notes: Logician in charge of logistics..
assbot: Successfully updated the rating for lobbes from 1 to 2 with note: #eulora logs bot
shinohai: I am sorry to report that I have not yet received an email from trilema with a deposit addy
assbot: You rated user lobbes on 06-Feb-2015, with a rating of 1, and supplied these additional notes: Well... he did teach himself how to view a directory....
assbot: Successfully updated the rating for mats from 1 to 2 with note: http://trilema.com/2013/so-whos-running-the-courts-circus/#comment-113478 ; helping people get pogos, stuff.
assbot: So who's running the Courts circus ? on Trilema - A blog by Mircea Popescu. ... ( http://bit.ly/1fr25Bn )
assbot: You rated user mats on 08-Apr-2015, with a rating of 1, and supplied these additional notes: Lotta paralegal work on http://trilema.com/2013/so-whos-running-the-courts-circus/.
shinohai graciously thanks mats again ...
mircea_popescu: yes there ios a known workaround. has been known since 1985. FUCK UNICODE.
mircea_popescu: Workaround There is no known workaround at this time.
asciilifeform: just the raw animal
mircea_popescu: guess that wasn't apparent.
asciilifeform: it is in ~EVERYTHING THAT USES UNICODE~
asciilifeform: it isn't a gentoo-specific thing
mircea_popescu: you may be the only one here seriously following gentoo.
assbot: Logged on 07-07-2015 17:37:15; trinque: https://security.gentoo.org/glsa/201507-04
asciilifeform: incidentally, http://log.bitcoin-assets.com/?date=07-07-2015#1191327 << this thread fell through the cracks, i think ☝︎
mircea_popescu: that way, you won't need "security patches" in the first place.
mircea_popescu: "we will stop deliberately adding holes to these versions aftyer this date, and you are please asked to upgrade because we won't be sending patches a quarter afterwards, either"
mircea_popescu: non sequitur prize of the year.
mircea_popescu: "As per our previous announcements and our Release Strategy (https://www.openssl.org/about/releasestrat.html), support for OpenSSL versions 1.0.0 and 0.9.8 will cease on 31st December 2015. No security updates for these releases will be provided after that date. Users of these releases are advised to upgrade."
mircea_popescu: and yet, "we do not feel compelled to denounce the person who added this hole in our codebase, and call for a boycott from everyone on it against their sorry ass. because, fundamentally... it's us."
asciilifeform: (though it's been a while since i looked at the turdation's tree - perhaps they do ?)
mircea_popescu: "During certificate verification, OpenSSL (starting from version 1.0.1n and 1.0.2b) will attempt to find an alternative certificate chain if the first attempt to build such a chain fails. An error in the implementation of this logic can mean that an attacker could cause certain checks on untrusted certificates to be bypassed, such as the CA flag, enabling them to use a valid leaf certificate to act as a CA and "issue"
asciilifeform: not the cert crud
asciilifeform: why is anyone using that thing again...?
punkman: "However, a Fitbit device Risley was wearing told a different story, the affidavit shows. The device, which monitors a person’s activity and sleep, showed Risley was awake and walking around at the time she claimed she was sleeping."
kakobrekla: or the need for one. can service others in yurop i guess.
asciilifeform: than straight intravenous injection from ntp into a machine with no clock to speak of
asciilifeform: but overall i'm much less allergic to the idea of letting ntp adjust a running clock by a percent now and then
asciilifeform: decimation: not afaik. probably best to assume the worst.
decimation: asciilifeform: are there specs for the rtc modules? specifically thermal stability?
asciilifeform: incidentally, if anybody feels up to falling on this grenade with me, please speak up
decimation: sorry tmux died
asciilifeform: these clocks would still have to be ~set~, but it can be done en masse, once.
asciilifeform: can be attached to the gpio in pogo ☟︎
asciilifeform: i also learned last night that chinese rtc modules, complete with battery, are about fifty cents in quantity
asciilifeform: could probably do several hundred in a weekend, if they were sent to me disassembled
asciilifeform: (it also needs a capacitor or li battery on the power input to the rtc)
asciilifeform: i've also thought about personally retrofitting the pogos with the crystals
asciilifeform: hence sanity-check rather than reliance
jurov: just that in your scenario of hostile isp and everything, they will be yet more easy to block than time.windows.com
asciilifeform: gotta think of a way to sanity-check it
jurov: if we agree to ship with pogos also 100 of authed ntp servers, I'm all for it
asciilifeform: ntp, on other hand, is a pants-down unauthenticated plaintext (for reasons explained previously, this cannot really be helped)
asciilifeform: jurov: the particular example, 'gossip', ~is~ jam tomorrow, yes. but it is possible to run encrypted tunnels of various sorts even today.
asciilifeform: so in that sense it is 'usg institution' in exactly the way my house, and my earthly carcass, are
jurov: jam tomorrow
asciilifeform: once 'gossip' is running, the only thing enemy will be able to do is pull plugs
jurov: and i keep telling you they already do cuz internet *is* usg institution
asciilifeform: since everybody seems to insist on doing mental gymnastics to come to peace with using ntp
asciilifeform: i am only dreaming up specifics because asked to
asciilifeform: i believe that it is wrong for a large network of bitcoin nodes to depend on a usg institution.
asciilifeform: jurov: gotta understand, my allergy to ntp is more of a 'reason from causes, not from purposes'-theorem application
jurov: and these other computers can server as canary, users *do* notice time off by hour
jurov: asciilifeform: and my idea is that pogos will be together with other computers behind the NAT
asciilifeform: (today, that is)
asciilifeform: or for that matter, in the original
asciilifeform: decimation: i can't comment on what's in the other '641a's.
decimation: how you gonna delay packets with that
asciilifeform: jurov: idea is that no one will 'notice weird time', nodes will just silently drift off the network
assbot: Room 641A - Wikipedia, the free encyclopedia ... ( http://bit.ly/1gq7okT )
decimation: asciilifeform: read the description of room 641a https://en.wikipedia.org/wiki/Room_641A
asciilifeform: we launch the pogos, and suddenly 'ntp is obsolete, dontchaknow,' here is a new replacement by poettering, 85% consensus1111!!!1111!!! within weeks, plug pulled on ntp servers ☟︎
jurov: so, instruct chumps "scream if you notice weird time"
assbot: Logged on 20-02-2015 03:34:05; mircea_popescu: In addition, anti-fascism was never to have as cheap as today. Previously, he could cost you your life, today it costs no more than lip service among peers - and heard to this, the exclusive circle of the upright, decent, brave. The fighters against law form the peerage of enlightened society. Or even a shot polemical: Here is an indulgence trade takes place; the moral superiority can be acquired sim
assbot: Log In - The New York Times ... ( http://bit.ly/1gq7gBU )
jurov: how do you know ntp is from the bitcoin node and not from other machine on the same network?
asciilifeform: it won't happen every day, naturally. just when 'national s333k000r1ty' requires a stinkbomb dropped on the network - to keep a certain tx from getting relayed, say
assbot: Logged on 09-07-2015 08:50:06; jurov: or try to precisely pinpoint which packet is from pogo and which is from other machines?
asciilifeform: http://log.bitcoin-assets.com/?date=09-07-2015#1194795 << feed diddled ntp to ~known public bitcoin nodes~. ☝︎
asciilifeform: iirc there were other 'postbox names' in there, amounting to the same idea
assbot: Logged on 09-07-2015 08:41:10; jurov: http://log.bitcoin-assets.com/?date=09-07-2015#1194359 so there should be plenty examples of usg diddling a traffic on the backbone, could you please post one?
asciilifeform: http://log.bitcoin-assets.com/?date=09-07-2015#1194783 << 'quantuminsert' and 'ferretcannon', just off the top of my head (from the snowden papers) ☝︎
punkman: "I wish I had the money to setup enough miners myself to get 95% hashing power and just freaking fork already." ☟︎
thestringpuller: https://www.reddit.com/r/Bitcoin/comments/3cnobx/regarding_raising_the_1mb_block_size_limit_just/ << for those interested in some more "hard fork lulz"
thestringpuller: ;;later tell mircea_popescu On Qntra you said, "This is a resource war and you people are poor." Well some poor redditard was venting this morning and in his rage said, "I wish I had the money to...do xyz". Ironic how denial turns to anger, almost like stages of grief.
assbot: Dot-dash-diss: The gentleman hacker's 1903 lulz - tech - 27 December 2011 - New Scientist ... ( http://bit.ly/1SaI79R )
punkman: "Berlusconi, 78, will not have to serve the sentence as the statute of limitations expires later this year, well before a final ruling will have been reached on appeal." ☟︎
assbot: Silvio Berlusconi sentenced to 3 years for bribing Italian senator | World news | The Guardian ... ( http://bit.ly/1CqY7mJ )
punkman: BingoBoingo: http://www.jameslafond.com/article.php?id=2623&pr=1 << is that part of a series or one-off?
jurov: or make buth m$/google move the servers to different IPs? no way that wouldn't get noticed, actually would be useful signal for us
jurov: or try to precisely pinpoint which packet is from pogo and which is from other machines? ☟︎
jurov: what is usg to do? risk diddling time on throngs of linux/windows machines?
jurov: say, let's put time.windows.com or google's addy among there and make the occassional packet look like systemd or windows emit
shinohai: It is EXACTLY like them
jurov: and it needs so much manpower that someone from "terrorist-packets-on-backbone-diddling-dept." would already spill the beans