erratic: fbsd is looking pretty good these days
I like that option for zfs+root
I'm still on the fence about zfs's encryption
https://blogs.oracle.com/darren/entry/choosing_a_value_for_the
(gcm vs ccm)
http://en.wikipedia.org/wiki/Galois/Counter_Mode#Security
BryceBot: Galois/Counter Mode :: Galois/Counter Mode (GCM) is a mode of operation for symmetric key cryptographic block ciphers that has been widely adopted because of its efficiency and performance. GCM throughput rates for state of the art, high speed communication channels can be achieved with reasonable hardware resources. It is an authenticated encryption algorithm designed to provide both data authenticity (integrity) and confidentiality. GCM is...
erratic: I'd like to see the opinion of a cryptography experts analysis of zfs's implementation of both gcm and ccm
From what I understand about it is that its implementation specific and there are weaknesses in how some implementations re-use IV's
somebody told me to stick to LUKS
but of course you can't really do LUKS with ZFS, you could but it would be dumb
also with btrfs still not clear whether or not I can use luks with it and still keep support for things like discard I don't really understand how it works but it would make sense that you probably would lose support for it since luks is a filesystem in and of itself... maybe its more transparent than that
you'd at least still have zlib/lzo compression
***: LT has joined #arpnetworks
erratic: yeah, aes-256-ccm... I guess it defaults to 128. gcm is supposedly a bit faster, and it sounds like you lose the ability to do de-duplication and its also prone to IV weakness
I think I might give zfs+root a try on my laptop
pyvpx: besides setting up a jail for each IP, anyone know of a quick and dirty way to setup SOCKs proxies bound to more than one IP?
openssh just takes whatever getaddrinfo gives (only the first IP on an interface)
dne: pyvpx: man page says: "-D [bind_address:]port"
eh, forget that, wrong side of the connection ;)
pyvpx: ya ;)
dne: hmmm, the listening port's interface or the outgoing one?
pyvpx: outgoing one
I was thinking netcat, or surely socat could do something for me
but I'm too dense/sober to figure it out in time it would seem
heh
dne: ssh -o"BindAddress=a.b.c.d" ?
new attempt: ssh -o "BindAddress <IP>" -D <port> ....
pyvpx: hm
ill give that a try in a sec
thanks
***: LT has quit IRC (Quit: Leaving)
mohaslan_ca has joined #arpnetworks
pjs_ has joined #arpnetworks
pjs has quit IRC (Ping timeout: 272 seconds)
pjs_ is now known as pjs
up_the_irons has quit IRC (Ping timeout: 272 seconds)
up_the_irons has joined #arpnetworks
ChanServ sets mode: +o up_the_irons
erratic has quit IRC (Ping timeout: 272 seconds)
m0unds: fun: http://www.cert.org/blogs/certcc/post.cfm?EntryID=206
***: erratic has joined #arpnetworks
erratic: http://imgur.com/BUj0pAG,YzzoPIy
net neutrality being pissed away
fuck the us, I dont care if I have to enlist in the military here I'm getting my citizenship by way of lineage and I'm never going back.
phlux: where are you?
brycec: I fail to see how the images equate to net neutrality being pissed away
Based on the clock, somewhere in Europe
erratic: well for one they're not loading because I'm not connecting from an address that is legit enough
I have to be connecting from a comcast address
or some such thing
I dont even care
brycec: the Hulu screenshot? Sure, makes sense.
erratic: they're detecting that literally by looking at where the address is allocated though
m0unds: haha, content licensing ftw
brycec: ^
pyvpx: yeah
the network is neutral. the licensing for content on it however....
brycec: licensing != net neutrality :p And sure, you connected from an IP [block] that is usually used by foreigners to access content they're not "legally" entitled to.
m0unds: i'd suggest contacting viacom and telling them you don't appreciate the method their partner (hulu) uses to detect your location
erratic: brycec: just forget it
I seriously dont care
m0unds: ok, ocol
s/ocol/cool
erratic: facebook is stupid anyway
BryceBot: <m0unds> ok, cool
m0unds: it sure is
erratic: I only need it for communicating with my aunt so I can get family info for getting my citizenship figured out
if their cdns wont let me connect fine
I dont care I dont want to see all of the stupid pictures of cats anyway
brycec: it really seems like I have problems with cdns all the time though
and I cant help but think that it must be the same sort of thing
its a little bit upsetting
staticsafe: sounds like a problem with your ISP
erratic: staticsafe: nooooo
I have a vpn setup in arp
and I'm using an address from a /28 that is allocated by arp
so arp essentially is my isp
staticsafe: no, not quite
erratic: ..
staticsafe: your transit to the ARP network is also relevant
erratic: how so
staticsafe: you are tunneling your traffic *through* the ARP VM
erratic: ok whats your point
brycec: I see staticsafe's point... but it's not exactly relevant
staticsafe: your connection to the VPN is also as important as ARP connection to the rest of the internet
brycec: Since the traffic is encapsulated, the transit doesn't know "hey, this is CDN traffic, I'm gonna fuck with it.". If it were transit issues, he'd see problems across the board.
acf_: is it only with images and things?
erratic: its been cdns in general
brycec: "it really seems like I have problems with cdns all the time though"
erratic: and I want to believe its related to the allocation
acf_: do large files over HTTP work from non-cdn sources usually?
erratic: its a "commercial" IP address because there just HAD to be a distinction
acf_: I don't think so. I never have had problems with CDNs through arp
staticsafe: i don't believe that is relevant
erratic: acf_: how often are you using it
I use mine exclusively
BryceBot: That's what she said!!
acf_: over IPv6, every day
over IPv4, somewhat often
mostly with wget
erratic: what about 4
acf_: do you have a specific example?
erratic: yeah
sec
http://imgur.com/BUj0pAG,YzzoPIy
and lemme see if the other one is still having issues
acf_: all the images not loading?
try
ifconfig eth0 mtu 1400
erratic: one will, reprod in seperate browsers
thats a good point
I'll have to try that tomorrow
pyvpx: shitty mtu. shitty tunnelling protocol. shitty implementation. shitty conection
all four
any combo of all four
acf_: you should only need to change the mtu on the client machine
brycec: (Good thinking)
erratic: I would think the mtu would make next to no difference
alright
lemme try
brycec: on the contrary, if the transit MTU is lower than your local/tunnel MTU, shit gets dropped
erratic: What VPN protocol?
erratic: yeah it makes absolutely no difference
acf_: I was having this issue with Google over an ARP IPv6 tunnel
I had path mtu detection set up properly
and random images and things would never load
erratic: that makes sense
acf_: but if I set the mtu on the client, everything was fine
BryceBot: That's what she said!!
staticsafe: yeah MTU issues can be easily seen with a tool like Wireshark
acf_: how is that?
brycec: BryceBot: no
BryceBot: Oh, okay... I'm sorry. 'but if I set the mtu on the client, everything was fine'
staticsafe: acf_: you will see retransmissions
acf_: ok, yeah
m0unds: i'm guessing the hulu thing is based on origin ip ASN or whatever, since they actively prohibit VPS and VPN endpoints
acf_: for the longest time, Google thought my ARP IPv4 IP was in Australia
you'd think that Google would have the path mtu stuff worked out...
I guess there must be something wrong with my configuration, but I can't figure out what
packet too big messages appear to be sent properly
brycec: you have an IPv6 tunnel to arp, yeah?
have you seen any problems recently with Google?
for example, I can't access http://www.google.com/intl/en/options/
erratic: looks a lot like a path mtu issue to me
maybe try using tcpdump or wireshark like staticsafe said, and see if there are TCP retransmissions all over the palce
brycec: acf_: I have the tunnel setup, but it's not currently used (I never got around to doing the firewall rules and enabling forwarding)
m0unds: i used my arp vps for ipv6 tunneling and did notice lots of quirky v6 behavior on client devices
acf_: good to hear it's not just me
m0unds: google thought i was in NZ, msft thought i was in NZ
acf_: maybe it was NZ... it was a long time ago
mercutio's fault? :P
m0unds: i say blame gizmoguy
brycec: Always blame gizmoguy
>.>
@last gizmoguy
BryceBot: brycec, I last saw gizmoguy 5 days 9 hours 36 min 42 sec ago joining a channel.
gizmoguy: hello
m0unds: lol
gizmoguy: @last gizmoguy
BryceBot: gizmoguy, umm... O..kay...
-: BryceBot points at gizmoguy...
m0unds: hah
-: gizmoguy turns off his script stealing everyone's traffic
gizmoguy: better?
m0unds: yes, thanks
the cat pics are flowing much more freely
staticsafe: s/stealing/routing through NZ
BryceBot: >>> gizmoguy turns off his script routing through NZ everyone's traffic
gizmoguy: NZ is best internet
m0unds: i'm surprised NZ has big enough pipes to handle all these cat pictures
did you guys run up a new bank of modems recently?
gizmoguy: yeah frank just added another cabinet worth
m0unds: good 'ol frank
gizmoguy: and we worked out how to bond them!
so we do 100x 56k now
m0unds: hahahaha
brycec: Bonded PPP really is amazing
gizmoguy: Oh man
I just googled "bonded dialup"
http://forums.whirlpool.net.au/archive/517448
brycec: mlppp
gizmoguy: posted 2006-May-6, 6:47 am
m0unds: that's immediately what i looked for (the date)
gizmoguy: Of course australians were doing this in 2006
brycec: m0unds: ++
I used to do mlppp dialup back in the 90's
m0unds: especially when i saw *.au
hahaha
brycec: My ISP didn't officially support it, but I tried it one time and it worked...
m0unds: nice
brycec: And since I discovered that, I would run both phone lines overnight :D
-: brycec had a second line just for Internet/fax
m0unds: just the fax, jack
brycec: (And nowadays I play with bonding T1's, whee)
m0unds: oh boy
brycec: It's hard to justify when the NIC in the same machine does 200x
But fun to goof around with all the same
-: brycec wishes his company made DS3 hardware, then he could have even more fun
pyvpx: 10x10GE is where the bonding fun is at
;p
brycec: 10GBE hardly fits the criteria of "stupid old-tech tricks" though
No doubt it's fun, but not the same as "hey, let's bond 28 T1's together for some major bandwidth, 1991 style"
erratic: I want to give up computers
theres no easy way to just get rid of them
brycec: except time travel
granted, time travel itself isn't easy.
erratic: yeah
I have this bad habit of trying to solve problems at night when Im about to go to bed and getting really paranoid
about shit that really doesn't even matter anyway
like this stupid images not loading thing
I just got into some huge argument with some recruiter kid which I wouldn't have done otherwise and handed him his ass for no good reason
stuff just doesn't even matter
computers and phones and tablets are for entertainment and nothing else and tech is a joke. It's a race to see who can spend more money on a startup to produce something that really doesn't do anything to make the world a better place....its just neat and people will pay money for it
mnathani: what are some reputable companies I can partner with to become a domain reseller and provide domain registration se
*services under my brand
erratic: mnathani: I would hope you would consider prq.se
but I dont know about partnering
just sell domains and register them with prq
mnathani: starting off with small volume and gradually growing
staticsafe: mnathani: ENOM, Hexonet
erratic: but I seriously like want to end it all because I know there is no escaping this
I cant just not do what I do
and I hate the world too, the world is all messed up
mnathani: staticsafe: thanks
erratic: 99% sure theres nothing I want to live for but I cant just kill myself
I wish I could get past it
and people tell me I shouldn't and that would be bad etc
so I try to enjoy what little I can and that seems to always disappoint me
always back in the same place wanting to end it
people will always in some capacity be stupid, careless, or selfish whether they mean to or not. I'm guilty of it as well and I'm not sure whats worse. I hate it
I can't come to terms with it
and its clouding my judgement and I should probably just go to sleep anyway
-: erratic &
***: RandalSchwartz has joined #arpnetworks
RandalSchwartz has quit IRC (Changing host)
RandalSchwartz has joined #arpnetworks
phlux: do any of you ever get bored and install different desktop environments/window managers just to change it up for a week or two?
or am I alone in this
RandalSchwartz: not really possible with OSX. :)
acf_: I tried that once...
but I felt like nothing compared to Xfce really
have any suggestions?
phlux: well
I always go back to my i3
up_the_irons: phlux: i think toeshred does
phlux: http://img.phluxbox.com/screenshots/song1y.png there's my i3
acf_: how do tiling window managers compare?
phlux: I'm more productive on one
-: phlux shrugs
up_the_irons: phlux: i, for one, never do this, although it sounds nice. i just can't give work without xmonad
phlux: right now I'm playing around with KDE4 for kicks
acf_: I always have tons of windows open
and I tab between them
up_the_irons: phlux: i wanted to see your conky config
phlux: up_the_irons: I still have to get you that phone number. The best people to contact out there are the Auxiliary.
OH YEAH
acf_: can you do that on tiling window managers easliy?
up_the_irons: and i3status or i3bar or w/e it is
phlux: acf_: yes, i3 is perfect for that
in that screenshot, I have 3 windows over on the right that I tab between
The one on the left remains constant
one second, up_the_irons
up_the_irons: phlux: it's OK, been so busy lately, hard to volunteer. it still seems worth it to have a contact "on the inside" to help with the process when i'm ready. unless you think i should just call the general number of USCG Auxiliary and take it from there ;)
phlux: up_the_irons: you could certainly do that, but I've got someone on the inside there
I need to find a decent pastebin
!pastebin
up_the_irons: phlux: my status bar is blank right now, after migrating to my T520. would love to get a status bar like yours ;)
phlux: brycec: pastebin
er
BryceBot: pastebin
-_-
sprunge it is
up_the_irons: phlux: ah yeah, see it seems better to just contact someone on the inside :)
sprunge rocks
phlux: msg'd it to you
i'm too lazy to check it for passwords atm
i trust you :P
brycec: phlux: ?
phlux: brycec: I was meaning to highlight your bot and ask it about pastebins
but NEVER MIND NOW
brycec: phlux: "ask it about" not sure what kind of info you're looking for from BryceBot
phlux: I thought it had infobot capabilities?
brycec: explain
acf_: 17:13 < BryceBot> http://pastebin.com/
phlux: ^
toeshred: phlux: i've tried pretty much all the DE's and WM's (except maybe a few obscure ones like bspwm). i3 is my favorite. i like your i3 status. this is my i3 + weechat: http://i.imgur.com/eVn68jR.jpg
phlux: brycec: 19:14:28 phlux │ pb: brycec is my fran
19:14:29 pb │ phlux: The operation succeeded.
19:14:32 phlux │ pb: brycec?
19:14:33 pb │ brycec is my fran
brycec: phlux: (and now acf_) So what, it just burps out a url?
phlux: goot example there
brycec: ?
Oh I see what you're trying to demonstrate
weird
up_the_irons: toeshred: i like that you're playing 'Maiden in that upper right window
phlux: Nice, toeshred. You're making me want to get on my desktop...with a bigger monitor :|
My laptop feels so small now
m0unds: hahaha
toeshred: up_the_irons: i've been getting a craving for metal lately.
up_the_irons: haha
RandalSchwartz: I'm typing on 1920x1280...
a relic 17-inch macbook pro
brycec: btw phlux Weechat released 1.0 a little bit ago (from your i3 screenshot)
granted I see the date in that screenshot now...
BryceBot: That's what she said!!
brycec: BryceBot: no
BryceBot: Oh, okay... I'm sorry. 'granted I see the date in that screenshot now...'
phlux: lol
RandalSchwartz: that's some kind of date!
hmm. not trigging
or is it only if you?
brycec: that's some kind of date!
twss?
BryceBot: That was 61.33% what she said. 'that's some kind of date!'
RandalSchwartz: threshold have to be higher?
brycec: 96%
Otherwise inane sentences like this would trigger, and there's nothing funny about this.
twss?
BryceBot: That was 58.35% what she said. 'Otherwise inane sentences like this would trigger, and there's nothing funny about this.'
m0unds: s/about this/potatoes
BryceBot: <brycec> Otherwise inane sentences like this would trigger, and there's nothing funny potatoes.
m0unds: nothing funny potatoes, indeed
brycec: twss?
BryceBot: That was 9.03% what she said. 'nothing funny potatoes, indeed'
brycec: So un-funny
m0unds: how about just potatoes?
brycec: probably 50%
potatoes
twss?
BryceBot: That was 6.52% what she said. 'potatoes'
brycec: ouch
m0unds: shiver me dingus
brycec: twss?
BryceBot: That was 50% what she said. 'shiver me dingus'
m0unds: ...how on earth?
hahahah
up_the_irons: oh man
twss?
BryceBot: That was 50% what she said. 'oh man'
RandalSchwartz: half of what she said
the other half might be something odd
up_the_irons: lol
twss?
BryceBot: That was 50% what she said. 'lol'
up_the_irons: <3 BryceBot
<3
twss?
BryceBot: That was 50% what she said. '
up_the_irons: haha
brycec: (That was weird)
m0unds: twss?
BryceBot: That was 75.04% what she said. '(That was weird)'
brycec: I like it hard
twss?
BryceBot: That was 50% what she said. 'I like it hard'
brycec: Oh come on, BryceBot, you know better
RandalSchwartz: she likes it semi-hard :)
m0unds: I like it flaccid
twss?
BryceBot: That was 50% what she said. 'I like it flaccid'
up_the_irons: omg
BryceBot: That's what she said!!
up_the_irons: yup
brycec: omg
BryceBot: That's what she said!!
brycec: twss?
BryceBot: That was 96.51% what she said. 'omg'
up_the_irons: hahahahaha
***: sga0 has joined #arpnetworks
up_the_irons: twss
BryceBot: Okay! twss! 'hahahahaha'
up_the_irons: twss?
BryceBot: That was 88.46% what she said. 'hahahahaha'
up_the_irons: that's what i thought
BryceBot
BryceBot is hung like a horse
twss?
BryceBot: That was 90.97% what she said. 'BryceBot is hung like a horse'
up_the_irons: oh BryceBot ...
brycec: you just can't get enough
twss
BryceBot: Okay! twss! 'you just can't get enough'
***: bellows has joined #arpnetworks
bellows: I need some router advice. The router I have now is doing weird stuff and I was wondering if I should buy a new one or get one though the cable company that will be free but have to pay $5 a month for Wireless Router Maintenance(FREE ROUTER). Which way would be better?