log☇︎
29 entries in 0.192s
asciilifeform: btw i confirmed that phf's v98 ( when patched to remove the subkey handler thing ) successfully presses ch1-11, with bitwise-correct results ( compared with classic vtron )
asciilifeform: loox like i'ma have to strip out the subkey garbage, and regenesis, 'v98-that-actually-worx'. unless phf has better idea.
asciilifeform: !#s from:asciilifeform subkey
asciilifeform: iirc whether this worx depends on whether only your subkey expired, or whole thing
asciilifeform: subkey, to be specific.
asciilifeform: the funniest bit is that anybody who spends a few $10k to find sha1 collision, can take it one step further and make a valid subkey for asciilifeform's, or mircea_popescu's, etc. key ☟︎
asciilifeform: though then you want to see the unpopped subkey siblings of the popped moduli, and start clicking, and you'll get zip.
asciilifeform: (my subkey expires every year.)
asciilifeform: soooo the subkey idiocy is apparently the 2nd half of a bipartite poison.
asciilifeform: e.g. primkey and subkey.
asciilifeform: Old: Public Subkey Packet(tag 14)(109 bytes)
asciilifeform: hence 'subkey must die!'
asciilifeform: btw does mircea_popescu know what would happen if a pgp key with his main key but new magical subkey were generated and posted to sks ? ☟︎
asciilifeform: (or more general variant where enemy can take something you signed and turn THAT into a subkey that is in turn accepted somewhere!!)
asciilifeform: Framedragger: concept of 'subkey' is waiting to be shot in the head incidentally.
asciilifeform: but now it seems like hdbuck somehow ended up with my expired subkey ?
asciilifeform: but looks like the actual rsa op was carried out WITH THE SUBKEY
asciilifeform: anyone recall how mircea_popescu spewed chunks when i pointed out that he's been signing with a subkey and not with the magical modulus ? ☟︎
asciilifeform: my main objection to subkey as implemented in gpg is that IT DOES NOT TELL YOU OR EVEN LET YOU CHOOSE with which modulus (i.e. which sub) it actually signs with ! ☟︎☟︎
asciilifeform: subkey is one of those things that could be a useful idea IF IT WORKED and WERE NOT IMPLEMENTED BY IDIOT ☟︎
asciilifeform: updated date on subkey
asciilifeform: http://log.bitcoin-assets.com/?date=12-10-2015#1297376 << this does absolutely nothing about the subkey signatures OR the fingerprints ☝︎
asciilifeform: Subkey fingerprint: 7B0D 6C5D D3C6 46DE EB0D F73D B4A0 4553 7370 8B0E
asciilifeform: some of these folks have only one subkey; others - two; etc
asciilifeform: BingoBoingo: depends which subkey, of who
asciilifeform: mircea_popescu: this one's another 'invalid subkey...'
asciilifeform: the subkey is skipped
asciilifeform: because there is no physically possible way to determine what subkey ought to be asked from sks et al, for that particular pubkeyblock hash
asciilifeform: i'd suggest term 'of', and use mathematical notation subkey(ofkey)