69600+ entries in 0.04s

mircea_popescu: anyway, point being -- lamp's enough, don't have
to
turn off
the chap's computor.
mircea_popescu: you know, boat crashes on amazon island. some of
the sailors -- excited
to be rescued. some others -- burned down rescuer ships.
mircea_popescu: i suppose
the dog&man permutation duality
translates escape-or-enslave dilemma.
mircea_popescu: "my phd in ancient history is --
the reason X civilisation died.
turns out, physics subtly cvhanged, rendering environment uninhabitable for
them"
mircea_popescu: asciilifeform
this is an amusing symmetry, republican machine
that halts if it can't
touch entropy like imperial machine
that halts if it can't phone nsa hq.
mircea_popescu: not what we were
talking about! still error condition.
mircea_popescu: unless
there's further constraints, such as "all random numbers are 4"
phf: asciilifeform:
to be fair musl's version is naive, it generates/stats in a loop until
there's no collision, but
theoretically you can still get a race condition. glibc i believe does all kinds of smart
tricks
to ensure
that doesn't happen, but it's all magic
mircea_popescu: though i've never seen
this
thing where parallel execution gets same clock value. i half suspect it's hardware fucked
to not.
phf: well, you still have
to stat
the filesystem
to make sure you're not clobbering
mircea_popescu: phf why do you even use it at all ? i mean... hash
the
time with a salt,
that's your filename. no good ?
phf: posix mandates 6 x's, glibc 3 or more, etc.
thanks bvt for catching it,
though it seems like a solution is
to roll own
mircea_popescu: let me guess,
this is like,
the golden age of f&o&linus source ?
mircea_popescu: is a security risk.
The race is avoided by mkstemp(3)."
mircea_popescu: ing whether
the name exists and opening
the file, every use of mktemp()
mircea_popescu: are easy
to guess, and on
the other hand
there is a race between
test‐
mircea_popescu: 26 different names can be returned. Since on
the one hand
the names
mircea_popescu: XXXXXX by
the current process ID and a single letter, so
that at most
mircea_popescu: (this is not even so
trivial a point -- generally insanity is perceived as so very personal by
the insane.
mircea_popescu: well,
they say
the path
to sanity comes with finding out
there's a word for insanity
bvt: I was man-aloning for quite some
time
bvt: I was
too naive when I entered academia. Hoped for honest investigation of
technology, but everyone
there seems
to be ok with building on broken stuff.
bvt: "security", so in
the end in boils down
to handwaving problems away with
TLS (aka pseudosecurity)
bvt: well, I was reading logs for a really long
time
bvt: GNAT 2017,
though, deletes such files on Close call.
bvt: GNAT 2016 runtime deletes all files with
temp bits at
the Finalization stage, so everything should work fine. (Not an ada specialist, so when finalization is actually run is a mistery
to me)
bvt: but also sets a
Temp bit in File record
bvt: Sorry, don't have a WWW, but
the fix should be a one-liner
bvt: Hello, I am BT from
the recent diana_coman's comments section
☟︎ a111: Logged on 2017-03-02 18:10 asciilifeform: a 'secure prng' is fundamentally
THE SAME animal as
the 'secure hash' and
the 'secure blockcipher'.
a111: Logged on 2017-12-29 15:55 asciilifeform: but
to return upstack , if one could design a satisfactory ( somehow! ) hash , it would
thereby also necessarily be a satisfactory symm cipher.
mircea_popescu: certainly i'd rather use keccak
than ~anything else for
the "make crypto out of
trapdoor" style alf
thing for example
mircea_popescu: problem with sha is
that it has no niche besides "fuck you, i'm lazy", and even
there... md5.
mircea_popescu: Mocky it's a riff on how
they use
tiny mouthfuls at
time. car just goes.
mircea_popescu: in
the immortal words of kramer, "i
tried
to make gravel and... it... it just didn't work"
mircea_popescu: for
the job here discussed, keccak stands with "other hash" like car stands with kitchen robot.
Mocky: mircea_popescu,
the significance of keccak here is
to have a better hash of same?
Mocky: oh, i didn't realize it was
that much better with aggression. my prior, discouraged attempt was without aggression and looking
to be substantially slower
than 3 weeks