Show Idle (> d.) Chans


| Results 257251 ... 257500 found in trilema for 'the' |

asciilifeform: the only necessary change to make working with multiple trees convenient would be 'multi-press' where you specify more than one 'head'
mod6: <+asciilifeform> it would end up as an altogether other tree in the graph << so said patch to add documentation dir would be its own root?
mod6: oh, i see, so like if a patch further down the line (in time) remove a file that a specific sub tree relies upon, that those become removed?
asciilifeform: it would end up as an altogether other tree in the graph
asciilifeform: nah those are yet another matter
asciilifeform: but dead branches of the tree, basically
asciilifeform: perhaps orphan is not the word
asciilifeform: if the toposort is correctly written, mod6's vtron ought to do it
asciilifeform: the other thing a vtron needs to handle is orphans
asciilifeform: (a patch that uses a deleted file can be legit so long as it is not on the tree branch that contained the deletion)
mod6: yeah, otherwise `sha512sum` returns "No such file found".
asciilifeform: oughta post this on therealbitcoin.org
mod6: so the ones that it /does/ skip is when 'b' == 'false' -- where the file was ~removed~ from a given vpatch.
mod6: and if a new file is introduced the 'a' should be 'false' and the 'b' will be some sha512 hash, and will still be verifyable. correct?
mod6: <+asciilifeform> mod6: have you tested it with 'false' entries? (files which were newly created) << this is a good test. it should just do what its supposed to do 'as is' I think? this line will grab the 'b' of the vdiff; my $file_hash = $vp_map{$vp}{$src_file_name}{b};
thestringpuller: The risk for crime is the gasenwagen. Raiders have always been ride or die.
asciilifeform: thestringpuller: there is not a single such 'group' in planet 3 that isn't either a) usg tendril b) full of stoolies and candidate for gasenwagen
thestringpuller: asciilifeform: well traditionally a blackhat would have a group and they would deal max damage themselves.
asciilifeform: but it is also impossible ~with~ a wot, unless you are mircea_popescu and are in commerce with another mircea_popescu .
asciilifeform: they'd get swamped with disinfo
asciilifeform: but even then impossible:
asciilifeform: now if camel fucker army had brains and used pgp and gave half a shit, one could send 0day to them and have at least the pleasure of knowing that it will be used to deal max damage.
asciilifeform: this is the kind of bind folks end up in because it is impossible (to a first approximation) to sell 0days.
assbot: Logged on 05-07-2015 15:10:28; asciilifeform: http://log.bitcoin-assets.com/?date=05-07-2015#1188163 << this is why, when dealing with a usg-powered entity, the correct procedure is not 'disclosure', which will be censored and hushed up; but - total annihilation
assbot: Logged on 06-07-2015 01:24:01; mircea_popescu: "you wanted to benefit from responsible disclosure protections, you should have been in the wot" "but at the time i made that decision it seemed a no brainer, why expend the effort" "right. this is why you die."
punkman: good god man, why did you tell them about the second exploit
punkman: thousands of dollars, maybe even Millions if the exploit was executed correctly with the right amount of people. Anyway so after i got my bounty and moved on they put some kind of "secret" ban on my account"
punkman: "Instead of abusing the exploit i have decided to help Coinbase fix the exploit by telling them step to step instructions on how to reproduce the bug on hackerone. After they were able to fix the exploit i was rewarded a measly $5,000 bounty, which i thought was unfair and was expecting to get upwards of $25,000. I helped them fix something that could have damaged them in hundreds of
assbot: Logged on 20-12-2015 17:09:24; mod6: So with the post-press hash validator in place, here's some debugging/info output while pressing in verbose mode: http://dpaste.com/2EM6P8S.txt
asciilifeform: thestringpuller: wasn't that a week from now
asciilifeform: and the fiddy pounds of maths
asciilifeform: also gotta love the 'million of anonymous' and 'ddos resistant' claim.
mod6: So with the post-press hash validator in place, here's some debugging/info output while pressing in verbose mode: http://dpaste.com/2EM6P8S.txt
asciilifeform: 'Vuvuzela uses efficient cryptography (NaCl) to hide as much metadata as possible and adds noise to metadata that can't be encrypted efficiently. This approach provides less privacy than encrypting all of the metadata, but it enables Vuvuzela to support millions of users. '
asciilifeform: 'Vuvuzela assumes the existence of a PKI in which users can privately learn each others public keys. This implementation uses pki.conf as a placeholder until we integrate a real PKI.' << ahaha
assbot: Logged on 20-12-2015 08:51:17; assbot: Hitler really did have only one testicle, German researcher claims | World news | The Guardian ... ( http://bit.ly/22hEyXu )
asciilifeform: http://log.bitcoin-assets.com/?date=20-12-2015#1348378 << now it remains to be learned whether '...musso, he has none at all'
asciilifeform: would be interesting (for a laugh) to see the actual code, but this is improbable
asciilifeform: http://log.bitcoin-assets.com/?date=20-12-2015#1348422 << by now everybody knows the usg academitard modus operandi
gribble: Bitfinex | This order would exceed the size of the order book. You would sell 328927.03 bitcoins for a total of 7885661.1167 USD and take the price to 0. | Data vintage: 0.0046 seconds
assbot: Logged on 20-12-2015 12:42:13; punkman: mircea_popescu: was that the new phuctor box?
asciilifeform: http://log.bitcoin-assets.com/?date=20-12-2015#1348397 << nah that thing is still up (though at the moment the only thing properly built there is a trb node)
asciilifeform: http://log.bitcoin-assets.com/?date=20-12-2015#1348398 << 'The breach is believed to be the work of a foreign government, U.S. officials said, because of the sophistication involved. The U.S. officials said they are certain U.S. spy agencies themselves aren't behind the back door. China and Russia are among the top suspected governments...' << mega-l0l
assbot: Logged on 20-12-2015 12:29:21; mircea_popescu: in other news, sprint.pl "one the most advanced centers in Poland for data storage and processing, created in response to the growing demands of the market" ran off with muh boxen.
assbot: Logged on 20-12-2015 11:51:26; mircea_popescu: <asciilifeform> it is the prehistoric clay pipes which are the problem << clay pipes are best pipes. really.
jurov: have their communication protected if their two clients, and
jurov: controls all but one of the Vuvuzela servers (users need not
punkman: ah they have an indiegogo
punkman: mircea_popescu: was that the new phuctor box?
mircea_popescu: in other news, sprint.pl "one the most advanced centers in Poland for data storage and processing, created in response to the growing demands of the market" ran off with muh boxen.
mircea_popescu: man i like the smell of new hardware.
mircea_popescu: trinque> to 62.210.90.95 ... why the fuck are you downloading the logs bundle over and over ? << try an' guess.
mircea_popescu: ben_vulpes> whatever did happen to bitcointa.lk << the guy had a good idea back when a few people still thought tardstalk might possibily matter. that was... well over a year ago.
mircea_popescu: <asciilifeform> it is the prehistoric clay pipes which are the problem << clay pipes are best pipes. really.
assbot: Hitler really did have only one testicle, German researcher claims | World news | The Guardian ... ( http://bit.ly/22hEyXu )
trinque: Anduck: a gentleman might consider funding the bot's address after using a terabyte of bandwidth
trinque: to 62.210.90.95 ... why the fuck are you downloading the logs bundle over and over ?
gabriel_laddel: Heh. Having the first mirror machine and the prospect of automating the install process within arm's reach is a strong motivation to... job hunt.
ben_vulpes: (and your other work)
gabriel_laddel: ben_vulpes: how is the family, work, life?
assbot: Trust relationship from user thestringpuller to user jgarzik: Level 1: 0, Level 2: 0 via 0 connections. |http://www.btcalpha.com/wot/trust/?from=thestringpuller&to=jgarzik | http://www.btcalpha.com/wot/user/jgarzik/
BingoBoingo: What the fuck is this prove you are a good fiat business before we'll even show you laser and hazmat prices business https://archive.is/pBOQL
assbot: Logged on 20-12-2015 01:13:56; mod6: asciilifeform et. al. V question: Should I verify the hashes after all patches are vpressed, or after each pressed vpatch in the topological order?
mod6: <+asciilifeform> http://log.bitcoin-assets.com/?date=20-12-2015#1348246 << and waitsec how on earth would you even try to verify hashes ~after all the patches are pressed~ << yah, i dunno. didn't go that direction. it validates now after each vpatch is pressed.
mod6: then if everything passes, etc, will publish a new version [v99996]
mod6: it's not fully tested yet -- tomorrow I'll pass the testable version around and some people can give it a try.
BingoBoingo: https://archive.is/rmZSy "During tonight's Democratic debate in New Hampshire, Clinton was running late again returning from a commercial—it's not clear whether a bathroom was involved" << Springtime for Clitler
asciilifeform: the being-broke thing also 'helps'
BingoBoingo: They keep making the same mistakes
BingoBoingo: Because you can't take reddit out of the redditors in exile?
asciilifeform: (otherwise, why??)
asciilifeform: http://log.bitcoin-assets.com/?date=20-12-2015#1348269 << folks who associate with the profoundly, frothingly mentally ill, tend to have some issue also
asciilifeform: the only choices are to verify nothing (what we have now), verify only last one (why???) and verify after each (the screamingly correct way)
assbot: Logged on 20-12-2015 01:13:56; mod6: asciilifeform et. al. V question: Should I verify the hashes after all patches are vpressed, or after each pressed vpatch in the topological order?
asciilifeform: http://log.bitcoin-assets.com/?date=20-12-2015#1348246 << and waitsec how on earth would you even try to verify hashes ~after all the patches are pressed~
asciilifeform: it is the prehistoric clay pipes which are the problem
BingoBoingo: asciilifeform: It is. Copper sulfate helps with that. Still fat fuck trees are so hungry they'll happily turn the shit pipe into a buffet. Behaviorally the things are hamplanets.
assbot: Logged on 20-12-2015 02:03:02; BingoBoingo: Fucking trees with their rootspreading
BingoBoingo: Fucking trees with their rootspreading
BingoBoingo: We need to start recording the blockchain on paper, stat.
mircea_popescu: and it doesn't affect their health, either.
mircea_popescu: from what i hear past 300 or so a valid strategy becomes to just ejaculate and wait for the flies.
BingoBoingo: mircea_popescu: Not when the Chicoms can get to 450 a piece
BingoBoingo: "Weighing in at nearly 900 lbs China’s heaviest couple has decided to undergo weight-loss surgery so they can have kids. Lin Yue and Deng Yang have been married since 2010 yet they haven’t been able to consummate their marriage because of their massive fupas. "
assbot: Too Fat to Fuck! China's Fattest Couple gets weight-loss surgery so they can have a baby. - NotYourGoodFatty.com ... ( http://bit.ly/1ODnAsx )
mircea_popescu: s to capture leads (since I had no product, that was just a test to see if there was demand). Then I bought a few dollars in Adwords to drive traffic to it."
mircea_popescu: I was reading The Lean Startup at that time, which is a great book, but not completely fool proof (here is a fool who got it wrong). I started well: in December I created a very basic idea and rough screens of my team management web tool. In January I built a very basic 2 page website with a video explaining what Teamometer.com did and a “try it free” button, which then lead to a page for inputting the email addres
mircea_popescu: "Validating the MVP
mircea_popescu: "Two years ago, on December 2011, I was generating ideas for a business that would help team managers to not suck so much at managing their teams. I came up with this idea because I had some pretty terrible managers in my life. At the same time I worked for about 5 years with leadership development and had some pretty great teams and team experiences. Exactly January 1st 2012 I registered the domain teamometer.com."
assbot: @Fatandflawless can't see the lifespan of the obese is etched in stone! - NotYourGoodFatty.com ... ( http://bit.ly/1ODmYTF )
BingoBoingo: e battery plant and related investments, with their ensuing local jobs, would be made in the U.S. by VW."
BingoBoingo: "In contrast to the punishments and recalls being considered, this proposal would be a real win for California emissions, a big win for California jobs, and a historic action to help derail climate change. The bottleneck to the greater availability of zero emissions vehicles is the availability of batteries. There is an urgent need to build more battery factories to increase battery supply, and this proposal would ensure that larg
assbot: Elon Musk Wants California To Forgive Volkswagen For Dieselgate (But There's A Very Big Catch) - The Washington Post ... ( http://bit.ly/1ODlRU6 )
mod6: <+mircea_popescu> if you check "at the end" now you have state. << do we want this?
punkman: "Possible optimistic conclusion: the new definition of “improved” is going from 34% to 21% success rate. Long (and painfully) live improvements!" lol
mircea_popescu: if you check "at the end" now you have state.
mod6: if we wait until the end, we'll save some cycles -- and mathematically the hashes wouldn't come out right if somehow the files were diddled inbetween. but I can see some merit in checking after each patch is pressed.
mod6: asciilifeform et. al. V question: Should I verify the hashes after all patches are vpressed, or after each pressed vpatch in the topological order?
mod6: <+mircea_popescu> anyone in the foundation leadership familiar with the military strategy concept ? ben_vulpes mod6 ? << not in a very formal sense.
assbot: Logged on 20-12-2015 00:49:28; mircea_popescu: in other news, i'm getting used to the ~$30 contractor bills around here. 4 hour's labour, with tools and consumables. reasonable.
asciilifeform: iirc the main difficulty was the firing pin, it really does not want to be made of ceramic
asciilifeform: by various accounts, these are long ago sop
mircea_popescu: should be interesting once the plastic guns with plastic bullets start showing up at airports.
asciilifeform: these are merely nylon-JACKETED lead bullets
mircea_popescu: a ? okthen
asciilifeform: there are !
mircea_popescu: i know why they went for it, but really. fucking dumb.
asciilifeform: but they buy it, yes
asciilifeform: it is also 'grungy' and ill-burning and american shooting aficionados scoff at the iron shells
mircea_popescu: in other news, i'm getting used to the ~$30 contractor bills around here. 4 hour's labour, with tools and consumables. reasonable.
mircea_popescu: if you're happy with ammo dollars (kinda dubious), pretty much every warlord in the middle east got himself as much this decade.
mircea_popescu: they didn't have that much did they.
asciilifeform: when the idiot ukrs sent their gold reserve to usg
asciilifeform: when even was the last time anybody gave somebody 100mn ~turkey dollars~
mircea_popescu: s, for example, with teachers being able to choose the one that’s best for their needs.”
mircea_popescu: The company also wants to help educators locate standards-aligned instructional resources from multiple providers, matching them to students’ individual needs. “We want to create more choice for schools and educators,” Streichenberger says, but not in a way that is overwhelming or makes their lives more confusing. “But in a way that allows startups and companies to create different versions of learning analytic
assbot: With $100M From The Gates Foundation & Others, inBloom Wants To Transform Education By Unleashing Its Data | TechCrunch ... ( http://bit.ly/1O0fm1u )
mircea_popescu: from gates & the happy lizzard club.
asciilifeform: the CORRECT place for pseudonode is...
mircea_popescu: the article is gone. they had ONE HUNDRED MILLION
mircea_popescu: We stepped up to the occasion and supported our partners with passion, but we have realized that this concept is still new, and building public acceptance for the solution will require more time and resources than anyone could have anticipated.
mircea_popescu: It is a shame that the progress of important innovation has been stalled because of generalized public concerns about data misuse.
asciilifeform: and thus do not really shitbury the dem00000cracy of redditors on cable modems
asciilifeform: one problem with this scheme is that they'd all live in aws ip space
asciilifeform: sorta the equivalent of the syrian flood
asciilifeform: kill in the sense of severing from the actual living meat
mircea_popescu: wouldn't kill anything. just make the "electoral process" a direct equivalent of the time man-of-the-year competition,.
asciilifeform: after the gossified one is up
asciilifeform: but it'd be a not-altogether-terrible way to kill the rangers' net
mircea_popescu: "The first great step was taken long ago," said Mr. Monk,–"taken by men who were looked upon as revolutionary demagogues, almost as traitors, because they took it. But it is a great thing to take any step that leads us onwards."
asciilifeform: and the possibility of it existing is a bug
asciilifeform: imho rather than a useful thing, it is actually a molasses-attack vector on the btc net
asciilifeform: that'd there be pseudonode.
mircea_popescu: asciilifeform you don't have to store anything to get the version string out.
assbot: Logged on 30-01-2015 05:51:36; mircea_popescu: which is why i am not ever giving it up. the freedom to threaten is not merely my fundamental, unassailable sovereign property, but moreover essential for the construction of effectual instruments to squash the socialists and their golums.
mircea_popescu: links nicely to anchoring stuff such as "the freedom to threaten" (see http://log.bitcoin-assets.com//?date=30-01-2015#998185 ) and so on.
asciilifeform: aws storage is, iirc, costly. this was one of the motivations for the enemy 'spv' crud etc
mircea_popescu: amusingly, it's a converse/correlate concept to the overton window.
mircea_popescu: anyone in the foundation leadership familiar with the military strategy concept ? ben_vulpes mod6 ?
mircea_popescu: costs significantly less than what's in the foundation coffers to line up 10k amazon instances and let it rip.
asciilifeform: and yet if we had 10,001 of these it would make for some mild lulz
BingoBoingo: Yeah, but in the plus side only takes 10 more to make it into the top 30
asciilifeform: BingoBoingo: part of the motivation for my experiment is to see how long it will be before they start 'accidentally' censoring it
BingoBoingo: In other news "/therealbitcoin.org:0.9.99.99/ (99999)" is tied for 38th place by nodecount per 21.co's thing
mircea_popescu: <asciilifeform> http://log.bitcoin-assets.com/?date=19-12-2015#1348050 << you know what's great? rat poison STILL WORKS even if you don't explain to the rats exactly ~how~ ! <<< precisely. moreover, every new generation of rats agrees that it doesn't work. which somehow does not have any deleterious effects on the rat poison itself.
asciilifeform: and incidentally BingoBoingo, should he make use of this patch, can easily set another
asciilifeform: otherwise it simply happens to be the version string used by my nodez.
asciilifeform: BingoBoingo: if the latest patch is ratified by the latter, then yes
asciilifeform: BingoBoingo: my patches do not represent the official papal view of therealbitcoinfoundation
BingoBoingo: So is "/therealbitcoin.org:0.9.99.99/ (99999)" the recommended version string for 0.5 branch until diddling because so few
BingoBoingo: Yeah, the orphanage kill was a great thing
asciilifeform: not even speaking of these.
BingoBoingo: Oh, dulap is the one I've been connected to for a while nao
asciilifeform: this is a press of the programmable-versionstring patch and down.
asciilifeform: with the frozen deps
asciilifeform: what we have now, takes the vpatch's word for it.
asciilifeform: mod6: ideally a vtron would follow along as the patches are applied and actually verify the hashes, yes
mod6: asciilifeform: ok, so add the ability to check the hash of the output file (post press) against 'b' in the vpatch?
assbot: Logged on 19-12-2015 23:49:50; punkman: the basic idea of segwit is not bad, should have been there from the start, without the "softfork" complexity, no ANYONECANPAY-looking crap, without making another merkle tree, without blocksize discounts and enlargements, without planning to use it as a vehicle for future "painless" shitgnovation
asciilifeform: http://log.bitcoin-assets.com/?date=19-12-2015#1348050 << you know what's great? rat poison STILL WORKS even if you don't explain to the rats exactly ~how~ !
asciilifeform: http://log.bitcoin-assets.com/?date=19-12-2015#1348027 << this cost a good number of chumps their coin, aha
assbot: Logged on 19-12-2015 23:26:49; mod6: <+asciilifeform> ;;later tell mod6 does yours (or anybody else's) 'v' verify the hashes ? << mine uses the vpatch hashes to build the dep map
asciilifeform: http://log.bitcoin-assets.com/?date=19-12-2015#1348022 << there is no other way to do it! what i was asking was whether anybody's 'v' actually verifies that patching in the given sequence actually yields files having specified hashes.
mircea_popescu: the chances of the reverse being possible decrease with every "everyone" and every "reasonable" and every "users came to expect" and so on.
mircea_popescu: trb transactions will necessarily, always and everywhere be translatable to whatever shit-flavour-of-the-day "everyone" is using because "no reasonable objections".
mircea_popescu: little conception of how the actual bitcoin people see things.
mircea_popescu: but hey, they're fiat-based leeches and think in terms of "can i sell this bitcoin"
mircea_popescu: nevertheless, YOU being forked off the real bitcoin can happen quite easily, and is incurable. so you think "you sent bitcoin" ? i don't see it.
mircea_popescu: anyway, to round off that luke-jr inanity from before : you can't "fork off" the real bitcoin. yeah, you can maybe make it appear (to yourself) that you have a coupla confirms. it costs you more than you have anyway, and nobody looks at hte shit you look at, so it's mostly an exercise in masturbation. expensive, but ultimately pointless.
mircea_popescu: but they're kids, with the life experience, intellectual/emotional maturity and general bandwidth of the average pubescent afghan. so... takes a little longer.
mircea_popescu: as far as the faux developers are concerned, it's rather obvious that even people with just a little ego will nevertheless necesitate the psychological maneuver of working themselves out of it through "projects" rather than just stopping.
mircea_popescu: as far as the faux users were concerned, this was stated as obvious in 2012.
mircea_popescu: point remains : as far as bitcoin is concerned, the thing is as irrelevant as the messages blockchain.info keeps "tagging" transactions with. the people who have no business in bitcoin but for whatever emotional/psychogenic reasons are misrepresented or misrepresenting themselves as involved WILL necessarily find a way out. there's just no way to stay attached if you;'re not attached.
punkman: the basic idea of segwit is not bad, should have been there from the start, without the "softfork" complexity, no ANYONECANPAY-looking crap, without making another merkle tree, without blocksize discounts and enlargements, without planning to use it as a vehicle for future "painless" shitgnovation
assbot: [BTC-dev] Taming the mempool ... ( http://bit.ly/1NvyaEi )
mod6: <+jurov> mod6 asciilifeform: the turd http://therealbitcoin.org/ml/btc-dev/2015-December/000186.html << thx for posting this! will review tonight.
mircea_popescu: ever since they came up with the idiotic notion of a vulgate, you're stuck playing the calvin. fuck that.
mircea_popescu: certainly the muppets can not be expected to figure things out, so...
mircea_popescu: im not aware anyone undertook the effort to write an equivalent of january's "here's the list of gavin xt idiocies and their rebuttals", 10k words over 3 articles sorta thing.
mircea_popescu: anyway, birdy on my shoulder whispers that what's meant by "reasonable" certainly is "reasoned". yes, there are no reasoned objections, chiefly because fuck you, that's why.
assbot: You rated user theymos on 15-Nov-2014, with a rating of -10, and supplied these additional notes: defrauded the tardstalk community by throwing ~half a million dollars worth of BTC at some obscure service provider for kickbacks. a lenghty history of fraudulent behaviour, http://trilema.com/2012/scammer-tag-nefario-theymos-others-known-and-unknown/.
mircea_popescu: !rated theymos
mircea_popescu: thanks the gods above for "reasonable", especially if it can be made to mean "the wolves agree"?
mircea_popescu: or to marquardt's little glbse insider-trading scam back in the day.
mircea_popescu: there were no "reasonable" objections to pirate, either.
BingoBoingo: Fucking Thermos
BingoBoingo: And Aaron encouraged the Hebrew people to make a new God of gold rather than Bitcoin while Moses was on Mount Sinai verifying the Godchain https://archive.is/ukHT5
BingoBoingo: Thermos: "No, it basically already has consensus from dev/expert community because it solves so many problems in one go and is pretty simple to understand if you know how Bitcoin works. There are no reasonable objections to SegWit AFAIK." https://archive.is/Q60SC#selection-2433.0-2433.227
mod6: so no, it does not verify them.
mod6: <+asciilifeform> ;;later tell mod6 does yours (or anybody else's) 'v' verify the hashes ? << mine uses the vpatch hashes to build the dep map
mircea_popescu: why does ecc.c include string.h or should't i be asking these sorts of questions ?
mircea_popescu: "after dropping them off I sat in the rental car staring at air. Crying. Feelings of fear, anger, self-righteousness and uncertainty overwhelmed me." << he has all the patience to consider all the inept minutia of his gender-confused identity. he has not the slightest fucking shred of interest or self-awareness to go "hey, waitasecond, why do i gotta lie again ?"
punkman: this might be the shortest one I've seen, no 256k1 though https://github.com/esxgx/easy-ecc/blob/master/ecc.c
mircea_popescu: had a speaking engagement in the other end of the country, pitching to a huge room full of potential customers. It was an absurd experience. I was crumbling on the inside but had to pose confidently. " << why the fuck ? just... why ? nobody ever asks this. "i had to lie". really ? why did you have to lie ?
mircea_popescu: "My presentation was ok. The mandatory Q&A afterwards was horrible. The only two people in the room that we hadn’t gotten prior support from were skeptical to say the least. As I left the room I was shattered. And as my contact at Accelerace didn’t call me later on that day I knew where it was going. My chairman didn’t either. Not a good sign. I left messages and they didn’t return my calls. In the afternoon I
punkman: BingoBoingo: perhaps a good project for students, dump all the blocks from a therealbitcoin node, verify sigs with python-ecdsa or other
BingoBoingo: But electrum ecsda only has to sign transaction, not verify the BritneyChain
asciilifeform: whether you and i can demonstrate how, or not.
asciilifeform rather surprised anybody still has one of these for sale
punkman: with a single signature leaks the current private key, and with 16 signatures leaks an additional 256 bit secret (e.g. a master private key, with a failure rate of around 1:1000 for 16 signatures, ~1:1e6 for 17 signatures)." interesting
punkman: "I actually have two implementations of example malicious signers:  One produces non-deterministic signatures and leaks a 256 bit private key, to the holder of a specific public key and no one else, in ~33 signatures with very high probability (failure rate of 1 in 1000 for 33 signatures, around 1 in a million for 34). The other produces a seemingly RFC 6979 like deterministic signatures and
BingoBoingo: <punkman> they are putting it in next version iirc << Signing tx with since 0.10 iirc
asciilifeform: the up-side of slow and finicky comps was that there was a lower limit to the dev iq and a hard upper limit to code bloat.
punkman: asciilifeform: but did they need to have two dozen TVs for testing?
asciilifeform: (my brother did this, still has some of the very peculiar hardware)
asciilifeform: anyway ipnohe devs think they have a terrible time, but try being a '90s game dev for consoles
asciilifeform: quite the zoo.
ben_vulpes: 6 american regular, 6 small, 5, 5s, the whole gamut.
ben_vulpes: it had yet to be shitted up by the rubros.
ben_vulpes: there is a big user-friendly button: "run this on my ipnohe or in the simulat0r"
ben_vulpes: there isn't much of a separation of concerns in the ios toolchain.
ben_vulpes: mircea_popescu: yes you see it needs the debug symbols transmitted to some leprous SaaS thing for in-the-field device debugging
mircea_popescu: nevertheless!
asciilifeform: 'only usg knows how to open this box therefore nobody'
asciilifeform: this is quite like the 'rng whitening'.
asciilifeform: but you ALSO get same if the same mathematical relationship can be derived from deterministic k.
asciilifeform: you get the leak in a straightforward way if k is REUSED
mircea_popescu: asciilifeform the idea is that it's not random, so you don't get two data points, so you can't use the particular leak thing\
ben_vulpes: remind me to tell y'all about the ios build toolchain plugin that makes curl calls ON COMPILE
asciilifeform: Since the k is deterministically generated from the data you are signing (and the private key), these concerns about the PRNG are no longer as relevant, as you will always produce the same signature for the same piece of data. This also makes writing ECDSA unit tests easier.'
asciilifeform: 'Also note that one of the key benefits of using this construction is that you need not worry about a weakness in your PRNG being exploited in the signing process. For example, signing different pieces of data with the same k value instantly leaks your private key. A similar attack can also be exploited if the PRNG is weak enough to determine the relationship between different k values used when signing the same piece of data.
mircea_popescu: let the code fucking compete already.
mircea_popescu: i wish to pick which pissing app to use by how many times the alternatives call std::anything.
asciilifeform: http://bitcoin.stackexchange.com/a/36142 << i am unable to grasp how the claims could possibly be true
mircea_popescu: hence the massive "coding streak" and other "productivity' measures, as if coding is a sort of stationary bicycle and who knows, "maybe you wanna know" aka "your boss does"
ben_vulpes: "show the non-technicals what the nerds are doing! with color!"
asciilifeform: mircea_popescu: aha. you can go and read the gcc (or even clang) front end and see how.
asciilifeform: punkman: i am still hard pressed to see how it is anything other than a disastrously bad idea
asciilifeform: mircea_popescu: EXACTLY as hard as the graph
asciilifeform: see the callgraph thread!
punkman: asciilifeform: can anybody tell me WHY ? << well it says it right there, because rfc6979
mircea_popescu: "here's a list of all oither lines where this string appears"
asciilifeform: because (as we learned in the callgraph escapade) this is hard.
mircea_popescu: tokenize motherfucker.
asciilifeform: btw that is the ONLY supported nonce gen fuct ~despite~ a carefully crafted appearance to the contrary
mircea_popescu: "fuck your mother"
asciilifeform: but idiots will tell you that shit is the new food
asciilifeform: each of the latter individually enclosing a totally nonportable turd
asciilifeform: but if we're gonna terraform existing item, i'd much prefer the nano ecc thing.
asciilifeform: was there a commissar standing, 'add moar codez'

|