log☇︎
695000+ entries in 0.443s
asciilifeform: unfortunately, intimately specific to make/model of disk.
asciilifeform: (i did some work in this area myself a few years ago. nothing usefully publishable.)
asciilifeform: remember the fellow who booted linux on a dead hdd's controller pcb?
mircea_popescu: decent way to generate terrabytes of prng data on the fly too
mircea_popescu: have a slot on the thing where end user plugs his own chip
mircea_popescu: i suppose one of the best ways to go, actually, would be to embed the encryption in the drive.
asciilifeform: re: 'addonics cipherchain' - mystery meat. and see where they want to generate keys for you.
mircea_popescu: spo let tens and tens of indians and somali kids twitter undesirable words, it's not a bad net result.
mircea_popescu: asciilifeform, i imagine there's some interest against mass bannings. moreover, you aleways want to allign the creed leeching of scammers with your agenda.
asciilifeform: mircea_popescu: too easy. soon you'll trigger a wave of scamzors getting themselves banned to earn 'l33t street cred.
midnightmagic: pankkake: How is GELI to use anyway?
mircea_popescu: asciilifeform, i shall interestedly propose the heuristic "were they banned on twitter"
asciilifeform: anyone who thinks 30m bezollars are permitted to fall into a pocket disfavoured by the crown - i've a bridge to sell to.
assbot: Encryption company Silent Circle, creator of Blackphone, raises $30 million - The Washington Post
midnightmagic goes to look
asciilifeform: i'd say misconception here - software doesn't fall apart from overuse. but there are forces at work to ensure that derpatronics become popular, vs. actually solid products.
midnightmagic: the nice thing is you can wreck the whole volume just by killing the corresponding luks slot.
gribble: Schneier on Security: Full-Disk Encryption Works: <https://www.schneier.com/blog/archives/2011/12/full-disk_encry.html>; Schneier on Security: Auditing TrueCrypt: <https://www.schneier.com/blog/archives/2014/04/auditing_truecr.html>; Schneier on Security: Protecting Your Privacy at International Borders: <https://www.schneier.com/blog/archives/2012/01/protecting_your_1.html>
mircea_popescu: suopposedly faster than ecrypot too
mircea_popescu: i think its lack of popularity has a lot to do with its usefulness.
jurov: i also use ecryptfs where wholedisk is not possible... but it is too linuxonly
mircea_popescu: luks is prolly one of the better choices acutally
midnightmagic: plus you can use stacked volume layering to stuff it into a raid config
midnightmagic: one of the simplest is just a plain luks crypted vol
Dimsler: whats the best to use for a container
Dimsler: i think
assbot: Block cipher mode of operation - Wikipedia, the free encyclopedia
mircea_popescu: isnt twofish aes ?
Dimsler: i've been using the 2 encryptions
asciilifeform: jurov: misconception. this was 'codebook mode' aes
pankkake: and truecrypt is one of the less audited. just no reason to even risk it
jurov: Dimsler: they were able to recover outlines from encrypted JPEG files
Dimsler: but from what i gather the full drive encryption from truecypt is unhackable?
asciilifeform: 'don't blame the mice' (obligatory)
pankkake: it's great, it's secure, but again, not for a 10 TB backup of millions of files with frequent updated and history
mircea_popescu: like if a woman was washed by the FOSS, her nipples and vulva would be very clean
mircea_popescu: even if it were proper open sourcde (which truecrypt never really was) the entire "oh million of eyes" is a total myth.
assbot: Pass: The Standard Unix Password Manager
Dimsler: thats true
mircea_popescu: one DEFINITELY doesn't want a populr packaging that's too likely to be attacked anyway
mircea_popescu: im just saying you know ? the tools are there, one doesn't actually need a particular packaging thereof
mircea_popescu: asciilifeform, doesn't have to. you can give it a ramdisk
pankkake: there's no reason to use trucrypt over cryptsetup
asciilifeform: make a tarball that you gpg encrypt << tehsuck. decrypts to plaintext buffer (!) on disk for add/modify
Dimsler: i only use TC for full level encryptioin
Dimsler: i'm actually hesitant about using TC containers
pankkake: my other backups are dar|xz|gpg. but not the big one
mircea_popescu: prolly byte for byte mor efficient than truecrypt or anything else.
mircea_popescu: and i doubt it works any less than your system works anyway.
pankkake: backup and update the backup
pankkake: doesn't work to back up 10 TB of files. I need the right layering
mircea_popescu: there's fucking reasons tar ended up the way it did, and they have to do with 30+ years of actual use in the field.
mircea_popescu: anyway, if one must have container encryption, use the fucking tools. make a tarball that you gpg encrypt
diametric: i have a moderate reddit presence but not the attention span
mircea_popescu: pankkake, yea that. or bitcoin-privilege
mircea_popescu: seems to me a helicopter submarine.
mircea_popescu: pankkake: I guess you could do file level encryption with gpg, but… there are probably better solutions << i still don't get why anyone thinks container encryption is a thing or makes sense
mircea_popescu: also ban all the reddit mods just for good measure.
mircea_popescu: anyone with a reddit presence want to start a subreddit ?
mircea_popescu: do the mooks just sorta beep on their side ?
mircea_popescu: so what happens if trhe terrorists turn on a huge fan on the side ?
BingoBoingo: pankkake: Somethings are better handed off to hardware.
diametric: mircea_popescu: yeah i agree, it was the best of the suck.
mircea_popescu: pankkake, actually, you can use the cardano to generate a multi-mb otp, keep it encrypted
pankkake: I don't really see the point. I'll do the encryption software, and encrypt the key with the cardano
mircea_popescu: pankkake, like thaqt except those women don't look like they could a) operate the hardware ; b) drag it around in the sun for 16 hours.
BingoBoingo: pankkake: Think how awesome a cardano keyed alternative would be.
mircea_popescu: thestringpuller: we should all threaten Theymos << mass solutions, kinda meh
mircea_popescu: last i said this a year ago consensus ended upo being "yeah but not much alternative"
mircea_popescu: diametric, truecrypt was kinda the suck.
mircea_popescu: in more ways than one
mircea_popescu: a regiment of topless-bikini camo clad chicks'd prolly kill
mircea_popescu: assbot: Israeli (IDF) female soldiers girls dancing with guns and underwear << i dun get what the big scandxal is. if they had any sense they'd allow victoria's secret make an optional uniform for women in the service.
diametric: now i have to waste time figuring out alternatives
diametric: everything I use is encrypted with truecrypt
BingoBoingo: asciilifeform: Cardano is indeed the propotype of such a thing. I'm thinking somthing like those hard to find widgets that occupy a 5.25" bay in a computer case.
asciilifeform: (with sd rather than external mechanical disk)
pankkake: yeah… it has some disadvantages compared to full disk encryption
asciilifeform: BingoBoingo: cardano is, in a sense, this
asciilifeform: (e.g. file sizes, access times, etc)
assbot: EncFS - Wikipedia, the free encyclopedia
asciilifeform: good chances the author of truecrypt has been nailgunned.
pankkake: I guess you could do file level encryption with gpg, but… there are probably better solutions
punkman: is there something that can do file containers with gpg?
Mats_cd03: it'd probably stay open for 2 years and then get locked to read-only, 'cept for people in WoT
fluffypony: I never thought of it in the canary context
fluffypony: asciilifeform: see convo earlier re: truecrypt...something is weird
BingoBoingo: I guess a lot of people are going to have to return to keeping their hard drives suspended by string over a bucket of Aqua Regia
asciilifeform: that'd be an interesting way to 'kill canary'
asciilifeform: 'Another possibility - the author was required by a court order to provide a backdoor for unfettered access to truecrypt disk, and to not disclose the existence of the order.'
asciilifeform: 'There's a new binary that recommends moving to BitLocker during install, and the signature matches.'
assbot: TrueCrypt suggesting migration to BitLocker? | Hacker News
BingoBoingo: Looks like Truecrypt is over.
assbot: Secret service to end rural anonymity for Modi's wife| Reuters
asciilifeform: RIP truecrypt ?
assbot: China pushing banks to drop IBM servers in hacking dispute - report| Reuters
Duffer1: how is assets this afternoon?
gribble: Currently authenticated from hostmask Duffer1!~Duffer1@c-98-232-231-188.hsd1.or.comcast.net. Trust relationship from user Duffer1 to user Duffer1: Level 1: 0, Level 2: 1 via 1 connections. Graph: http://b-otc.com/stg?source=Duffer1&dest=Duffer1 | WoT data: http://b-otc.com/vrd?nick=Duffer1 | Rated since: Fri Dec 13 04:23:08 2013
gribble: WARNING: Currently not authenticated. Trust relationship from user assbot to user Duffer1: Level 1: 0, Level 2: 2 via 2 connections. Graph: http://b-otc.com/stg?source=assbot&dest=Duffer1 | WoT data: http://b-otc.com/vrd?nick=Duffer1 | Rated since: Fri Dec 13 04:23:08 2013
pankkake: there are two: ask someone is assbot trust, or get yourself in the wot and get rated you can up yourself