log☇︎
90100+ entries in 0.776s
asciilifeform: 'The way the MatrixSSL team "fixed" the miscalculation issue is not really satisfying: They now restrict the input to the pstm_exptmod() function to a set of bit sizes (512, 1024, 1536, 2048, 3072, 4096). My test input had a different bit size, therefore I cannot reproduce the miscalculation any more, but the underlying bug is most likely still there. ... Despite the fact that the bug may be still there the CRT attack will probably
asciilifeform: ' I just discovered a somewhat similar issue in Nettle. They switched their RSA implementation from GMP's mpz_powm() function to mpz_powm_sec(), which is supposed to be sidechannel resistant. However mpz_powm_sec() is no drop-in replacement. Unlike mpz_pown() it doesn't accept even moduli and crashes with a floating point error. Therefore when trying to use a specifically crafted RSA key with an even modulus this will crash. '
asciilifeform: i wrote to them
mircea_popescu: dude that fucking thing... i loled all over again
mircea_popescu: i can't comprehend why anyone'd summon the interest to care. the only correct solution is to insist strict latin set exists throughout, and otherwise they can all get fucked.
mircea_popescu: to this day "Exchange" in serbian is menjati, for this reason. two "i".
mircea_popescu: then the barbarians decided to hear distinction between i and j.
mircea_popescu: PeterL no, and leaving the greeks aside : one day some people decided to make an I that looked more like a J. sexier font, stylish, whatnot.
mircea_popescu: and hence numerous examples i'm too much of a business insider to bother fucking listing. who the fuck let these idiots write in the first place, they're an insult to the cattle that had to die for the vellum.
mircea_popescu: hence i/j
mircea_popescu: i dun think so. to wit : every kid has a toy buldozer, which he does improvements to.
mircea_popescu: if i start screaming at the idiots they WILL execute their job, and well. but absent my scream, they have no fucking idea they're doing a bad job, even. nobody ever told them so.
mircea_popescu: the point being that i have wisened to understand the problem. it is a lack of negative reinforcement.
mircea_popescu: yeah, maybe they hunt them, though i've never personally seen it.
mircea_popescu: i also didn't mind them - but it did drive one girl positively crazy. couldn't sleep, eventually had a mild psychotic episode. so i got rid of them.
mircea_popescu: similarly i guess, once had a colony of crickets
mircea_popescu: they patrolled all the outside walls constantly. being no damage they could do to rebared concrete... i really didn't see the harm.
mircea_popescu: well depends. i once had a colony of ants. which i personally liked.
asciilifeform: i wrote 'don't blame the mice' in it.
asciilifeform: i have.
mircea_popescu: if you participate in "communities" that make this difficult, you are, personally, a bad person. it's not "oh, i'm just trying to on facebook".
mircea_popescu: i get that it's a diffuse, socialist, retarded sort of forcing where nobody actually does anything that could possibly be upon them. but that dun matter so much, if you end up pushed out of bed by a colony of maggots, THE MAGGOTS DID IT.
mircea_popescu: speaking of which, i once knew anal sculptor girl. she'd insert condom full of prepared gypsum, shit it back out.
asciilifeform: http://btcbase.org/log/2016-08-03#1513748 << i must now point out that ~everyone ~involved in os design~ is... dead ☝︎
mircea_popescu: i prefer to discern between the two by their reaction to events. the fact that they're not all here means they're all there.
mircea_popescu: it just doesn't actually speak to the foregoing. i suppose the correct rsa implementation comes with a kernel patch.
mircea_popescu: but i do dispute that for this reason it then follows there also can't be put any.
mircea_popescu: anywya, i don't dispute that "accidentally"-deliberately nobody put any effort into rng quality assurance ; key quality assurance ; etc.
shinohai: Well after getting his fudge packed for so long, I guess it finally made it's way to his brain.
a111: Logged on 2015-05-20 15:03 mircea_popescu: http://log.bitcoin-assets.com/?date=20-05-2015#1139680 << speaking of this, am I the only one nonplussed by all this "we use <<best practices>> fixed exponent" bs ? it's an unavoidalbe magic number , okay, but it's tyhe sort that should eminently be a knob for the user. a proper gpg would have e user-settable at the key generation phase (with 65536+1 as a default, sure)
mod6: <+asciilifeform> could've sworn this was in the logz << i recall a few discussions, ya.
a111: Logged on 2015-05-24 14:45 Apocalyptic: "there's no guarantee p and q have the same bitsize is there ?" // I think there is, a couple of lines above it generates them both with nbits/2 bits, so I would say yes, unless there is a bug in "generate_secret_prime", because this function specifically sets the two high bits to 1
mircea_popescu: asciilifeform btw re the fermat discussion, i wonder if anyone ever did a proper review of rsa code for lattice and fermat-closeness weakness in p,q generation.
fabio__: ok I think I understand your position a bit better now thanks
asciilifeform: fabio__: understand, also, that someone who offers you a more complicated (i.e. more moving parts) cryptosystem without ~justification~, is attempting to compromise your security, no less than if he were stalking in your garden under the cover of night bristling with cameras and antennae
fabio__: yes I know, integer factorisation problem
fabio__: you did, but I'm fighting through the snark to ask for more details ;)
mircea_popescu: fabio__ rsa has the advantage that it's the simpler solution. i thought i said this before.
asciilifeform: i use a buncha stuff
fabio__: i totally agree, but what I was getting at was what methods of analysis do you trust
asciilifeform: well, for starters, i'd like a compelling reason to even ~entertain~ ecc in the first place.
asciilifeform: i would like to buy ticket, to watch him stuffed into the paddy
asciilifeform: (i wrote to a few)
asciilifeform: i dun get it, what does either of these 'have to lose'
asciilifeform: i, for one, do not care how many degrees, and from what rotten institutions, such a swindler has.
fabio__: right, I'm with you.
mircea_popescu: as far as i know the fellow's quite respectable.
fabio__: people are rolling it out, openssh has supported it since 2014 i think. one of the openssl devs was asking for code to merge
fabio__: ok, I didn't realise there was not a consensus.
mircea_popescu: the republic doesn't, nor does any lord that i know of, recommend using ecc in any serious capacity. that's the community. otherwise, if you wish to say "i trust djb and whatever he says i'll take" this is fine, but it's a matter of personal investment not "community" nonsense.
fabio__: There has been quite a bit of noise about ECC NIST curves (nistp256, nistp384, nistp521) being tampered with by the NSA. I thought using ECC was all good if you don't use the NIST curves and instead use community approved curves like Curve25519 and Curve1174 by like DJB and friends, or other approved ones at https://safecurves.cr.yp.to/. ☟︎
fabio__: hi guys, I came across http://phuctor.nosuchlabs.com/faq this morning.
mircea_popescu: then they induced the bishop of munster, a sort of medieval thug, to invade the republic, under promise of "large subsidies". those subsidies never materialized, being promised by the broke-ass anglos as they were ; brandenburg moved in from the east and the naive turk uh i mean bishop of munster was forced to a rather disfavourable peace for his trouble / idiotic naivity.
asciilifeform: BingoBoingo: i was speaking of the 'fromphuctor's.
mircea_popescu: asciilifeform two points here being that a) the "global dragnet" is much more difficult to use than you imagine ; and much less productive, being more of a prestige item than a tool of any sort ; b) they're discussing a specific item. if i ask you how many stovetops you have in your house you wouldn't count the roof, notwithstanding the sun heating it is, energetically, more significant.
asciilifeform: i have pretty much nfi what happened after 2008 or so.
mircea_popescu: i thought back when it was voat.co reddit mostly did kiddie porn.
mircea_popescu: what can i tell you, until and unless kid is actually visible in the world nobody can interact with him,
mircea_popescu: i'm sure that'll work!
asciilifeform: ^ pity i missed this party
mircea_popescu: i can't place it.
asciilifeform: jaundice, cirrhosis, i say.
shinohai: https://img1.steemit.com/0x0/http://i.imgur.com/visQpcj.jpg <<< heh
phf: 40 seconds in, i switched from watching that video to watching an old soviet cartoon..
asciilifeform: e.g., it was, last i knew, ~wholly absent from ru sphere
mircea_popescu: the woman i sat down to watch it with was ALL NUDE! who the fuck cares omfg the tamest stht ever
asciilifeform: i watched a few min, it was a snore, turned off
mircea_popescu: so i finally got around to watching that thai prince orgy video thing.
phf: i'm writing subs for girl, because official english translation is awful
asciilifeform: phf: i rewatched it just a few yrs ago!
mircea_popescu: i guess what i'm saying is that i admire your patience.
asciilifeform: every so often i wrestle with the pig, old habit.
mircea_popescu: asciilifeform honestly i don't comprehend why you entertain the tards above and beyond "honey, close your eyes and think of the empire", but each his own i guess.
mod6: Peace in our ctime(); << i lul'd
shinohai: Also, I think I'd use doorknob and string before visiting a dentist in that building.
shinohai: I read that sign as "Spammed Travel" mircea_popescu
shinohai: trinque: this is why I said "supposed" http://archive.is/03EF0
phf: i dunno, i think you can blame mayakovsky for gulags
asciilifeform: and let's say i propose 'the aristotle' as a unit of tautological circularity.
mircea_popescu: oh, i forgot in that enumeration : the tsyan, intelligence measure. named for the... militsyan
asciilifeform: maybe phf. i'm not a fan.
mircea_popescu: and if i did, who'd speak for him ?
mircea_popescu: and i'd expect he does it by the tolkien.
asciilifeform: i do wonder how a boeck is paid - per word? for 'result' ?
mircea_popescu: right. i thought it happened again, woulda been almost trollage.
mircea_popescu: i'm confused. did they just do this, ie, now ?
mircea_popescu: i dun get it ?
mircea_popescu: http://btcbase.org/log/2016-08-02#1513170 << from what i hear that's more of a curse in the us of a. ☝︎
ben_vulpes: and that was the day i won the great Battle of Cyanoacrylate
trinque checks to see if I stopped the thing when working with mod6
ben_vulpes: asciilifeform: semi-relatedly, kiddo sliced his hands open on the radiator fins of an airconditioner i had lying foolishly within reach
asciilifeform: ben_vulpes: i spent 5min prying loose the battery (they glued it) and another 5 wiping off the blood.
ben_vulpes: this is why i left #fabcareer
privkeytones: I can only reach it intermittently for some reason, seems the DNS address cannot be found..
mircea_popescu: i kid you not.
boolcrap: i dug up a 1lb potato that was my biggest
boolcrap: i hope to actually dig up something amazing from the garden
asciilifeform: i recommend also using pc iron bought from shop, and not dug up from garden
boolcrap: hopefully this one doesnt croak when i turn VTx on
boolcrap: im actually going to recover it today when i install my new motherboard