#arpnetworks 2010-05-19,Wed

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)

WhoWhatWhen
***schmir has joined #arpnetworks [01:44]
schmir has quit IRC (Remote host closed the connection) [01:56]
...... (idle for 29mn)
schmir has joined #arpnetworks [02:25]
........ (idle for 38mn)
baklava has quit IRC (Disconnected by services)
baklava- has joined #arpnetworks
[03:03]
.................. (idle for 1h27mn)
ziyourenxiang has joined #arpnetworks [04:30]
dxtrI can see that my dad mowed the lawn because there's mud and grass on my window [04:34]
ziyourenxiangit's a hint to you [04:45]
..... (idle for 24mn)
AndrewBCnonsense. clearly a sod monster is after you [05:09]
cedwardsclearly. [05:16]
bob^^there's no other sensible explanation [05:18]
AndrewBCindeed [05:19]
***heavysixer has joined #arpnetworks
ChanServ sets mode: +o heavysixer
[05:20]
.... (idle for 19mn)
baklava- is now known as baklava [05:39]
........... (idle for 51mn)
vtoms has joined #arpnetworks [06:30]
RandalSchwartznice - the three-line change I made to the code a few weeks ago went live last night... reducing the load on 34 boxes by *half*
I wonder if I get to keep the 17 boxes they won't need now :)
each of those is an 8-processor with 16GB of ram
[06:34]
schmirnice one. I'd say it depends on if you wrote the code in the first place [06:37]
RandalSchwartzI didn't [06:44]
awyeahyay got a new laptop from work. [06:54]
bob^^:D [06:54]
awyeahThe laptop I'm giving back is a Centrino... it's kinda old now
2.25GHz centrino. single core. 80gb, 5400rpm hard drive.
new one is a core2 duo t9400. whatever the hell that is. Shit, I don't know anything about computers anymore.
Oh, that's just the model number. ;)
awyeah moron.
[06:57]
dxtrdxtr whiestles [07:02]
RandalSchwartzso what does a nice 8-proc 16GB box sell for these days? [07:02]
dxtrGenerating a 8192 bit rsa key
o/
[07:02]
RandalSchwartzyou must be afraid of even the NSA :) [07:03]
awyeahRandalSchwartz: My guess is... somewhere between $1 and $1,000,000,000
it's within that range somewhere.
[07:04]
RandalSchwartzI bet it is! [07:05]
dxtrRandalSchwartz: It's mostly for the lols actually :)
But my server's got a 4096 bit key
I think that's quite enough.. for now
[07:05]
***schmir has quit IRC (Ping timeout: 264 seconds) [07:12]
dxtrI spoke with someone who strongly believed the NSA could break a 256 bit RSA key in seconds :D
Beat that, RandalSchwartz!
[07:16]
bob^^i don't doubt that :/ [07:20]
RandalSchwartzwith my newly-spare 17 boxes? :) [07:20]
dxtrbob^^: Really? In seconds? C'mon
In months? Sure. But seconds? nah.
"Factoring RSA 512-bit keys is now squarely within the reach of anyone who is determined enough. As testimony to this, several 512-bit RSA keys used to sign the operating systems of Texas Instruments calculators were recently factored, reportedly within "several months""
http://www.javamex.com/tutorials/cryptography/rsa_key_length.shtml
So.. Say weeks
[07:24]
***vtoms has quit IRC (Quit: Leaving.) [07:27]
dxtrBut I fear the day quantum computers becomes more available [07:27]
bob^^512 is not 2x as secure as 256 remember
it's many many factors less secure
if i remember the maths right :/
[07:28]
dxtrThat's why I said weeks :P [07:28]
bob^^and don't do it in software
design an ASIC
or do it in your graphics card
now factor in an essentially limitless budget
and... :)
suddenly not so unbelievable
[07:28]
dxtri'm still getting the feeling that this computer will be kind of... power hungry
Hmm.. or was it a 512 bit key the guy said? Don't remember
[07:29]
bob^^ASICs don't need to be that power hungry - they're designed to one task and to do it as quickly as possible
calculating prime factors isn't that complex remember :)
i guess it depends if you drink the coolaid and believe that the NSA have a backdoor into public key encryption anyway ;)
[07:30]
dxtrI'm kind of realistic and believe that NSA aren't some kind god
"OMG! THEY CAN DO SHIT THAT ISN'T EVEN INVENTED!"
[07:31]
bob^^hehe [07:32]
dxtrIt's like here when people hear that I'm heavily encrypting my stuff [07:32]
bob^^the limitless budget tends to have the ability to invent things you don't think are possible :P
oh i heavily encrypt my stuff too - nothing to hide, but that's not the point
[07:32]
dxtr"The police would still be able to decrypt it!" - How the hell are they going to decrypt my hard drive? 64 byte key, AES encrypted. SSH? 4096 bit rsa key
It's not like they do it over breakfast
[07:35]
RandalSchwartzin some jurisdictions, you can be compelled to reveal your key [07:36]
bob^^depends on your local laws
you cuold be forced to reveal the key
indeed ^^
it's now a requirement in the UK i believe (amazingly - i do *not* agree with this)
[07:36]
RandalSchwartzI believe truecrypt actually has a stealth mode to combat this [07:37]
bob^^which i guess is why truecrypt offers hidden volumes with a different key :)
yeah
:D
[07:37]
RandalSchwartzheh
are you sitting next to me? :)
"get outta my head!"
[07:37]
bob^^:D
bob^^ waves over
[07:38]
***vtoms has joined #arpnetworks [07:43]
dxtrActually I don't know my key
I've got a yubikey .D
So they can ask and beat me how much they want
I've got nothing to tell them
[07:44]
..... (idle for 21mn)
Damn. ftp.openbsd.org doesn't have 4.7 yet :/
ftp.eu.openbsd.org did
!
[08:05]
cedwardsdxtr: they want you to pay for it! [08:20]
....... (idle for 31mn)
dxtrSo... I'll upgrade my router some day
Probabl this weekend
probably*
[08:51]
cedwardsI'm curious what OpenBSD offers that FreeBSD does not.. besides the free tin-foil hat with each download. [09:05]
RandalSchwartzan ancient version of apache!
a non-standard version of NTP that breaks specs!
however, a version of PF that is still ahead of FreeBSD's version
(but not for long)
[09:07]
dxtrOkay guys... I've gotta two book reports until tomorrow. Do you know of any good books? :D
gotta do two*
(Hint: It must be novels)
[09:16]
bob^^what sort of books do you like? [09:19]
cedwardsdxtr: any specific genre or just "two books" [09:26]
dxtrcedwards: Well, no specific genre as long as they're novels
bob^^: I don't like books at allk
[09:26]
bob^^ahh hehe [09:27]
dxtrThat's kind of the reason I haven't done it [09:27]
cedwardsohh, so this doesn't count: http://store.xkcd.com/xkcd/#xkcdvolume0 ;) [09:27]
bob^^i guess there's plenty of classics to choose from [09:27]
cedwardsI highly recommend Stephen King, but his novels are generally long. [09:27]
dxtrcedwards: If it did I'd read that and "Simons cat" (Yes, my girlfriend got that book) [09:27]
bob^^animal farm? 1984?
i've got simons cat too :)
[09:27]
dxtr:D [09:27]
RandalSchwartzhow novel does it have to be? [09:28]
bob^^something by john steinbeck? of mice and men is quite good and nie and short iirc [09:29]
dxtrRandalSchwartz: The thing is that I won't have time to read anything. I'm thinking I'll google up some reports on books wich I've seen the movie and then go from there
Like.. Twilight and Harry Potter
[09:29]
RandalSchwartzthat can be dangerous [09:29]
bob^^yaeh, i wouldn't do that
you can read of mice and men in a few hours
[09:29]
RandalSchwartzthe book is usually a bit (or a lot) different [09:29]
bob^^http://en.wikipedia.org/wiki/Of_Mice_and_Men [09:29]
RandalSchwartzjust steal something from wikipedia :) [09:29]
bob^^only 107 pages [09:29]
RandalSchwartznobody will figure *that* out [09:29]
bob^^and it's actually quite an interesting book [09:29]
RandalSchwartzis it the Disney story?
about the beginnings of Mickey Mouse?
[09:30]
dxtrWell, I'm averaging VG (The second highest grade on a three-grade-scale)
So hopefully I can't fail with this :D
[09:30]
bob^^this is great too: http://en.wikipedia.org/wiki/The_Thirty-Nine_Steps [09:30]
RandalSchwartz"if you fail to plan... you will plan to fail" [09:30]
bob^^i'd read those two
39 steps is a good action story too, might keep you interested
[09:30]
RandalSchwartz"it's the memory guy!"
oops. Spoiler :)
[09:31]
dxtroh, actually it's four grades. IG > G > VG > MVG. And beacause I'm averaging VG in this course (English B) I'm hoping that no matter how this goes I'll get a G [09:31]
bob^^dxtr: you could read the 39 steps *and* of mice and men within 6 hours
and understand them both quite well
[09:34]
dxtrcool
So if I start now I'll be finished after midnight? :D
[09:35]
cedwardsbetter get started! [09:35]
bob^^go go go [09:35]
RandalSchwartzahh - it's the memory guy only in the Hitchcock version [09:36]
bob^^hehehe [09:36]
dxtrThen I'll have to write the report + civics course
Awesome
[09:36]
cedwardscedwards puts on his drill instructor hat and lets fly the obscenities to "motivate" dxtr [09:36]
bob^^i've not seen the hitchcock one :( [09:36]
dxtrI'm hungry
I'll start studying whenever my dad comes home with food
:D
http://en.wikipedia.org/wiki/Gyros <- Om nom nom nom
[09:42]
cedwardsprocrastinator [09:46]
dxtr:D
FFFFUUUUUU-. I might be a true procrastinator
"Procrastination can be a persistent and debilitating disorder in some people, causing significant psychological disability and dysfunction. These individuals may actually be suffering from an underlying mental health problem such as depression or ADHD."
My girlfriend suspects I've got ADHD
But I don't want ADHD so I'm not going to a doctor
[09:46]
bob^^heh, some swedish people i know in another channel are always going on abuot gyros :)
it looks a lot like donner kebab ;)
[09:49]
dxtr"Traditionally, procrastination has been associated with perfectionism" <- again, my girlfriend is always bashing me because I'm a perfectionist like that
"Fuck everything else until this is perfect" kind of
bob^^: Gyros > Kebab :)
I hate kebab
cedwards: I hate you for bringing tht up :P
that up*
[09:50]
bob^^:) [09:52]
cedwardslol
go read your books
[09:54]
dxtrhehe
No, but seriously. I'm too hungry to do anything productive right now
[09:55]
bob^^once you start reading you'll forget about being hungry [09:56]
......... (idle for 41mn)
***ziyourenxiang has quit IRC (Quit: ziyourenxiang) [10:37]
.......... (idle for 47mn)
schmir has joined #arpnetworks
schmir has quit IRC (Remote host closed the connection)
[11:24]
...... (idle for 26mn)
AndrewBC has quit IRC (Ping timeout: 252 seconds)
schmir has joined #arpnetworks
[11:50]
AndrewBC has joined #arpnetworks [11:56]
jdoehrm, 4.7
wonder how pleasant upgrading is...
[11:59]
***schmir has quit IRC (Remote host closed the connection)
schmir has joined #arpnetworks
[12:06]
.............. (idle for 1h5mn)
schmir has quit IRC (Ping timeout: 240 seconds) [13:13]
...... (idle for 27mn)
schmir has joined #arpnetworks [13:40]
.................. (idle for 1h28mn)
schmir has quit IRC (Remote host closed the connection)
vtoms has quit IRC (Quit: Leaving.)
[15:08]
.......... (idle for 46mn)
up_the_ironscedwards: for me, OpenBSD offers basically: a community that is big enough that useful work gets done, yet small enough that things pretty much move in the same direction. there's not 26 ways to do the same thing in OpenBSD. There's generally one, and only one, way. I find this make it a lot simpler for me to understand.
cedwards: but specifically, I'm liking the idea of using OpenBSD's spamd with my new Postfix configuration, to reduce spam (of course)
now, time to fight with apparmor and libvirt
[15:54]
............... (idle for 1h10mn)
dxtrOkay...
up_the_irons: You won't believe what I've just done
I've written a 13 page report about my school project
[17:09]
up_the_ironsin LaTeX? [17:09]
dxtrNow I've got to improvise 100 hours worth of logs :P
Actually, no. I took the easy road and wrote it in OOo and exporting it to a pdf
[17:09]
up_the_ironsOOo?
i c
[17:10]
***ballen has joined #arpnetworks
ballen has quit IRC (Changing host)
ballen has joined #arpnetworks
ChanServ sets mode: +o ballen
[17:10]
dxtrI'm in a hurry here. Don't have the time to learn latex right now :)
As I said, I've got to improvise a logbook for the 100 hours I was supposed to put into this project (In reality it took more like 2-3 hours)
[17:10]
up_the_ironshaha [17:12]
dxtrOkay, I've written down 36 hours so... 64 to go :P
Seriously, the rules for this project was insane
It couldn't take less than 100 hours and one of my teacher asked me if I couldn't make them a webserver that the first year students can use (Upload php scripts and use a shell in the linux class)
"Sure" I said
[17:12]
***nbari|away has quit IRC (*.net *.split)
cedwards has quit IRC (*.net *.split)
[17:13]
dxtrInstalled Apache and PHP (with SuExec and SuPHP) plus MySQL on a Debian machine
"Done!"
Fixed quotas and stuff too
I did it as slow as possible to drag it out. And I made a side project trying to learn my friend to write a script in either bash or perl that adds users in bulk (One class at a time)
But he didn't gave so I gave that up
he didn't care*
[17:13]
***nbari|away has joined #arpnetworks
cedwards has joined #arpnetworks
[17:15]
dxtrBut the fun part was that my mentor said that it must not take less than 100 hours but the teacher that "ordered" the webserver wanted it as fast as possible
So here I am
Retardedly behind schedule (With the report and log book).. And tired... and hungry
And Tomorrow I've got two more courses to finish (English and civics), on Friday I got two more
But then I'm done with high school
After this summer I'll study some high school math, religion and swedish so I can attend university though
[17:16]
up_the_ironsup_the_irons just discovered "netcap"
Nice util (Linux only, however)
Shows which capabilities your listening processes have
[17:28]
***AndrewBC has quit IRC (Ping timeout: 240 seconds) [17:29]
dxtrcool
"This course will provide in-depth knowledge of various software and hardware. This course will also provide knowledge of other equipment and documentation in the field. This course will provide skills in installation, commissioning, maintenance and documentation of IT facilities. This course will also provide knowledge of the duties incumbent upon an IT coordinator and ...
... knowledge of reliability and data security. This course will also provide knowledge about the collection of information, advice and guidance in the field"
up_the_irons: That's one of the courses I've got to do
:D
[17:31]
***AndrewBC has joined #arpnetworks [17:33]
up_the_ironsdxtr: doesn't sound too bad [17:34]
dxtrIT coordination [17:34] <dxtr> o [17:34]
..... (idle for 21mn)
***fink has joined #arpnetworks [17:55]
awyeahAbout to try installing BackupPC on my bsd box here at home.
We'll see how well that goes ;)
[18:01]
...... (idle for 26mn)
dxtrhttp://tinyurl.com/238qyp7 <- My first three logs in my log book
Written six months ago
[18:27]
***fink has left [18:28]
..... (idle for 21mn)
infraredhi [18:49]
awyeahWell that's not going very well.
It really wants to have everything run under the "backuppc" user.
But Apache runs under the www user of course.
[19:01]
***fink has joined #arpnetworks
nbari|away is now known as nbari
nbari has quit IRC (Changing host)
nbari has joined #arpnetworks
[19:10]
infraredawyeah: rsync > * [19:20]
cedwards+1 [19:23]
infraredo [19:32]
..... (idle for 24mn)
awyeahyeah
I just... i want a little history
like to be able to go back a few days.
[19:56]
ooh. http://www.nongnu.org/rdiff-backup/ [20:01]
RandalSchwartzjust posted to template toolkit mailing list about how I got rid of 17 8-way machines for $client
... http://lists.template-toolkit.org/pipermail/templates/2010-May/011317.html
[20:03]
.... (idle for 16mn)
***heavysixer has quit IRC (Quit: heavysixer) [20:20]
..... (idle for 21mn)
ballenRandalSchwartz: thats fun [20:41]
RandalSchwartzyeah [20:42]
***RonnyBarber has joined #arpnetworks
fink has quit IRC (Quit: fink)
[20:45]
BarberRonny has quit IRC (*.net *.split)
woremacx has quit IRC (*.net *.split)
mtve has quit IRC (*.net *.split)
[20:50]
awyeah has quit IRC (Ping timeout: 260 seconds)
awyeah has joined #arpnetworks
[20:56]
jdoeawyeah: either run it as backuppc or use suexec, I guess [20:58]
ballenor chmod everything to apache
run everything as apache's user
I wouldn't use suexec
mostly because you'll likely have to recompile perl
[20:59]
RandalSchwartzI don't run suexec
mostly bcause I don't run CGI :)
[21:00]
jdoewhy would you have to recompile perl to use suexec? [21:01]
ballentry it ;-) [21:01]
jdoeI already do it [21:01]
***woremacx has joined #arpnetworks [21:01]
jdoethat's why I'm asking why I can't ;) [21:01]
ballenalright, pretty sure you can compile perl to no allow it to be suexeced
and thats the default in a lot of system's packages
[21:01]
RandalSchwartzwhat's your real question? [21:02]
jdoeyou're not thinking of suidperl or anything are you? [21:02]
ballenmight be [21:02]
RandalSchwartzallowing perl in suexec is a problem [21:02]
jdoe... how so? [21:02]
RandalSchwartzbecause perl can do anything [21:03]
jdoeI'm not following. [21:03]
ballena perl suid executable could run anything
as root
which would be bad
[21:04]
jdoeyeah you're not talking about the same thing I am.
http://httpd.apache.org/docs/2.2/suexec.html
[21:04]
***ballen_ has joined #arpnetworks
ballen_ has quit IRC (Changing host)
ballen_ has joined #arpnetworks
ChanServ sets mode: +o ballen_
ballen has quit IRC (Disconnected by services)
ballen_ is now known as ballen
[21:07]
jdoeballen: http://httpd.apache.org/docs/2.2/suexec.html [21:08]
ballenyea [21:08]
jdoeyeah, you're thinking of ... the general insanity of suid scripts. [21:08]
ballena lot easier, and still safer to just use a single user
I have BackupPC setup so the apache user has a ssh key
use that key to deploy to clients
[21:08]
jdoewhatever works.
I don't use it at all, it was awyeah asking
[21:14]
..... (idle for 22mn)
***nbari is now known as nbari|away [21:36]
....... (idle for 33mn)
ballen has quit IRC (Quit: ballen) [22:09]
awyeahah
yeh
I may try that at some point.
for now I'm just going to do rsync or rdiff-backup
I only have one system to back up to my server anyway ;)
alright. sleep needed.
[22:11]
.... (idle for 16mn)
***RandalSchwartz has quit IRC (Ping timeout: 245 seconds) [22:28]
jdoeawyeah: word. I love rdiff-backup. [22:35]
.... (idle for 17mn)
***mtve has joined #arpnetworks [22:52]
nuke` has quit IRC (Ping timeout: 252 seconds)
sentabi has quit IRC (Remote host closed the connection)
sentabi_ has quit IRC (Read error: Connection reset by peer)
[23:00]
sentabi has joined #arpnetworks [23:08]
...... (idle for 25mn)
sentabi has quit IRC (Read error: Connection timed out)
sentabi has joined #arpnetworks
[23:33]
nuke` has joined #arpnetworks [23:44]

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)