log☇︎
7400+ entries in 0.126s
Framedragger: heh. yeah, k.
Framedragger: your phuctor uses a different hashing scheme. but i suppose wide deployment would be hard and also ultimately futile, given that i assume folks here haven't planned a bright future for gpg
Framedragger: but sure.
Framedragger: but folks here still use gpg fingerprints, which is funny
Framedragger: http://btcbase.org/log/2016-06-04#1476783 << don't forget that a "full" gpg fingerprint is a shitty 160 bit sha1sum, heh ☝︎
Framedragger: vc: hey better slower than fast and shitty :)
Framedragger: yeah, hard to argue with that
Framedragger: (re. pkcs#11, because e.g. that substring-attack is only meant to be against symmetric keys stored in that shitformat, but since e.g. ECDSA keypair's secret logarithm "is just stored as 32-byte scalar value [it's not meant to be stored that way there, but is, because reasons], [...] extract-key-from-key can be used to successively reveal chunks of that scalar value.") ☟︎
Framedragger: cool vc, and i hope your rolling-out of hosting boxes is going most cocksuredly well!
Framedragger: wow, ok, so pkcs#11 is horrible over 9000.
Framedragger: ohey vc how's romania treating you then
Framedragger: sensitive = some bit set
Framedragger: so we're all good guyz
Framedragger: but look it's secure because when it's deriving new secret keys from another secret key it has this majestic security constraint: "If the original key used in this process is sensitive, then the derived key must also be sensitive for the derivation to succeed."
Framedragger: indeed..
Framedragger: maybe you can run cellular automata on that thing, with those useless APIs
Framedragger: yeah wtf right?!! (i didn't know, wtf)
Framedragger: yeah i've recently started - enjoyable indeed
Framedragger: https://randomoracle.wordpress.com/2015/08/13/safenet-hsm-key-extraction-vulnerability-part-i/ tl;dr "PKCS#11 security = lol"
Framedragger: http://btcbase.org/log/2016-06-02#1475260 << (i'm busy with afk stuff and most probably won't be able to resume the ipv4 ssh keyscan thing until some time next week. but i'll ping you once this is done) ☝︎
Framedragger: kthx
Framedragger: ah hence the 'political' term. (naggum).
Framedragger: *shudders*. reminded me of this: https://qntm.org/unit
Framedragger: and quite possibly run by a chinese mining cartel to boot
Framedragger: wibbly-wobbly
Framedragger: oh, yes, i did.
Framedragger: http://btcbase.org/log/2016-06-01#1474997 << notrly! ☝︎
Framedragger: mircea_popescu: http://trilema.com/2014/the-hour-of-reckoning/ was a nice read, thanks. chance, right.
Framedragger: lots of logs. kk. sorry
Framedragger: nice. ok
Framedragger: oh lol, oops.
Framedragger: asciilifeform: i would seriiosli consider http://www.2x4.ru/index.php?pid=71
Framedragger: "They were bored to death even with their own thoughts and dreams, bored with the attack they expected momentarily. They were bored of being bored, and too sick and tired of being bored to even consider not being boring. It's just not possible to do, it exceeds human capacity. Turns out that when confronted with the meaningless pointlessness of endlessness, the inadequacy of the muchly lauded human faculty of creativity becomes readily a
Framedragger: http://btcbase.org/log/2016-06-01#1474528 << goddamnit: read article; fail to parse word ('edulcorously'); realise only two google results are (1) ben_vulpes uttering the word, and (2) this trilema artcile (the following day); end up checking roots of "edulcorate" (make something more acceptable or palatable) http://imgur.com/85Iy0el ☝︎☟︎
Framedragger: a screenshot: http://trilema.com/wp-content/uploads/2014/08/lol-death.png
Framedragger: sounds like it was fun, at least for a while!
Framedragger: s/\n/?\n/
Framedragger: what was war of life? (http://trilema.com/2014/the-twinheaded-announcer-announces/ ) ? a kind of game of life with bitcoin betting
Framedragger: $s "war of life"
Framedragger: jesus wtf am i doing
Framedragger: s/you claim that/you claim that he claims that/
Framedragger: (thanks for bearing with me, and i'm off home). i leave you with http://smbc-comics.com/index.php?id=4092
Framedragger: mircea_popescu: this is super unimportant but under your analysis, he says that 2 is safer than 1. you claim that 1 is safer than 2. should be inverted, methinks. (the "(less safe)" refers to 1, not to 2.)
Framedragger: "was a terrible answer tho)" (fuckin irc)
Framedragger: hm. *this* (i.e.: that "no polynomial-time algorithm exists for factoring the product of two random n-bit primes with some good probability") *is* less safe as compared to the safer assumption that "no polynomial-time algorithm exists for always factoring all products of two random n-bit primes". this is a much safer assumption cf. to the one you interpreted it to mean, no? (no baiting this time - just honestly confused). but eh, may
Framedragger: i don't think 'c)' obtains? no mix-up there. otherwise, sure, blergh re. a) and b)
Framedragger: (i sounded more literary in my mind)
Framedragger: so wikipedia sux and sometimes you need to glance at it, the way a hasty businessman glances at a dubitable street food stand in a foreign city. sometimes the temporary "before pgp xamarin something" solution is to glance at that damn wikipedia. what of it
Framedragger: *pointing out
Framedragger: mircea_popescu: merely point out that the "root layer of the universe structure" may be a blocker on this bug. but the root layer has needed a paddlin' anyway..
Framedragger: yeah, i've been prone to this, too, but luckily by applying some "heuristic human computronium" a.k.a. common sense no truly stupid tragedies happened.
Framedragger: why in the fuck did she move to SF given the rent prices. this is truly perplexing.
Framedragger: s/or that/if that/
Framedragger actually liked when reading some marx, at least volume 1 of das kapital. lenin can be discarded, save for learning from history or whatever (or that).
Framedragger: guess you can't, hence yes, problem
Framedragger: heristicable = heuristically solvable?
Framedragger: s/assumption/instances/
Framedragger: well systems which assume "worst case" assumption vs. "random instances" of problem are perhaps better. see end of that answer
Framedragger: not to rain on the parade (not that i could), but isn't it possible such a thing won't ever be found? http://stackoverflow.com/a/3654889 ☟︎☟︎
Framedragger: but of course, true.
Framedragger: *chill
Framedragger: child the fuck down
Framedragger: asciilifeform: hmh i guess https://en.wikipedia.org/wiki/Merkle%E2%80%93Hellman_knapsack_cryptosystem is np-complete, pity it's broken
Framedragger: yeah i know the latter, i thought there were additional reasons for preferring c-s here. ok.
Framedragger: that's fair. ok. i assume you don't think much of OAEP (i see it mentioned in the logz but only just)
Framedragger: please no appeals to teh coming empire
Framedragger: any particular preferences on your part asciilifeform ?
Framedragger: asciilifeform: yeah i've got to that section, interesting, gonna slowly parse it
Framedragger: (their "hybrid implementation" assumes a good symmetric-key cipher..)
Framedragger: (heh they even suggest sha-1 for the hash function, though this is from an olden paper, so.)
Framedragger: (their "proof of security" assumes the hash function is truly one-way)
Framedragger: though a "hash-free variant" appears to be possible, so maybe there's that; need to check.
Framedragger: http://btcbase.org/log/2016-05-31#1474264 << that's nice, but doesn't the beloved cramer-shoup also use hashes? their scheme, to quote, "requires a universal one-way hash function" ☝︎☟︎
Framedragger: i'll take a look, thanks..
Framedragger: *runs*
Framedragger: 2+2==4 only holds under boring algebras
Framedragger: so much opinion
Framedragger: oh man
Framedragger: aha, then i guess you don't really enjoy the fact that gpg uses aes for session key actually? :) ☟︎
Framedragger: asciilifeform: couldn't you use an argument of a similar form to say that e.g. AES depends on luck? (2^256 keyspace of luck, for example..)
Framedragger: right.
Framedragger: designed to introduce an external implicit trust node
Framedragger: s/achievement/just getting things done/
Framedragger: true anonymity kinda sux in terms of achievement.
Framedragger: right you are; i was mixing the terms to further my point
Framedragger: hm, yeah.
Framedragger: but it's possible to maintain stable pseudo identities in groups of people wherein those identities are recognized for what they do; etc etc.
Framedragger: yeah. i mean one day i'll grow balls and get out of my comfort zone of sorta-pseudo-anonymity. your points are valid here, even though i think it's possible to do useful/productive work under pseudo/anonymity. this doesn't work if you require the *world* to recognize your awesomeness, of course :)
Framedragger: fair enough. but i also tell you that there are hosting providers which say fuck you to LE of specific states; but ultimately it boils down to the same security question: "how important are you?" - if you're important enough then sentimentalities of sysadmins will be ignored.
Framedragger: Live Support | Thomas: Yes, sure, we allow. Give us money and we host you and we will **** the german police
Framedragger: stephen: excusme ? you must be joking
Framedragger: Live Support | Thomas: we allow botnets.
Framedragger: stephen: BOTNET ARE ILLEGAL AND YOUR COMPANY MUST NOT HOST SUCH CLIENTS
Framedragger: anecdotal case in point (hey it's amusing): http://www.webhostingtalk.com/showthread.php?t=859747&p=6761371#post6761371
Framedragger: BingoBoingo: u what m8
Framedragger: sorry 4 spam
Framedragger: e.g. 2x4.ru have a reputation of being more hardcore; i know this sounds naive and it probably is, but i've heard this from trustable sysadmins running, er, shadier stuff. this is of course anecdotal and it's naive to trust someone with your hardware anyway.
Framedragger: "i am not aware of any services that can be considered bulletproof much like i'm not aware of any electoral process that can be considered representative, any computer code that can be considered correct or any fiat financial item that can be considered not a scam." << i see your point and i agree, however it's probably not "all of the same"; e.g. 2x4.ru have a reputation of being more hardcore; i know this sounds naive and it probably i
Framedragger: "i am not aware of any services that can be considered bulletproof much like i'm not aware of any electoral process that can be considered representative, any computer code that can be considered correct or any fiat financial item that can be considered not a scam." << i see your point and i agree, however it's probably not "all of the same";
Framedragger: mircea_popescu: yeah of course - i just meant that any LT servers cannot be considered to be "bullet-proof"; but maybe you were not aiming for the latter in terms of phuctor hosting anyway