5h 13m11d 10h 28m16h 58m3d 6h 41m15h 13m4d 17h 59m

Show Idle (>14 d.) Chans

feedbot: << trinque -- A Republican OS - Part 2
asciilifeform: shinohai: yer bot dun know how to reconnect, does it
shinohai: Yup, I was doing a few tweaks to it early this morning and eschewed having it auto-rejoin your chan to avoid spam.
asciilifeform: shinohai: y'know it's entirely ok to genesis a '90% worx' proggy. ( i did, and on >1 occasion )
shinohai: nb, just lots of pots on the stove atm and I want to decide *which* parts to publish.
shinohai: First order of business is to publish post on esthlos-v before anything, since gonna be using that as my primary vtron moving forward.
asciilifeform: shinohai: for my part i've a draft of ffa-powered verifier for legacy gpg sigs (presently, only detached sigs, as used in vtrons) but also needs moar massage before posting ( and in particular, human-readable explanation of how sawed apart the format, the published docs were of ~0 help, had to vivisect the koch turd)
shinohai: Oh neato! Look forward to it. My estlos-v thing isn't nearly as exciting, simple modification of Makefile to build the keccak bits at same time as presser, and install 'em all. (Temporarily added phf's as well until I come up with solution for that.)
asciilifeform: shinohai: realized the need for this while attempting this earlier item -- apparently gpg 1.4 has known (but afaik not fixed) cpu wedge attacks via crafted input turds (and some unknown # of unknown... massive ball o'shit) and really not suitable for 'anyone can feed' www system
snsabot: Logged on 2019-12-06 15:25:23 asciilifeform: diana_coman: i'd rather prefer one where patch viewer and folx can upload sigs which then go where ought to
asciilifeform: koch's liquishit is at any rate looong 'past its sell-by date'.
shinohai: Will gladly modify cl-v to use this mechanism when battle-tested, etc. (As was mentioned previously, the verify portions are just gpg callouts, so should be trivial to implement).
asciilifeform: shinohai: since already 'spoilered' this item -- also dispensing w/ the 'subkeys' nonsense. to verify against legacy gpg pubkey, the latter 1st gets sliced into however many public moduli in there, and operator henceforth responsible for invoking against the right one
asciilifeform: none of the garbage w/ 'expirations', 'revocations', etc. is carried over, either.
shinohai: I never could truly wrap head around the subkeys thing, or why one would want a key to "expire". Perhaps smarter folx than I know answer to this.
asciilifeform: shinohai: the pgp format was, by all indications, designed by same sorta nsa stooges as erry other period atrocity (e.g. 'ipsec', 'ssl', etc)
asciilifeform: was made specifically to be a) maximally difficult to implement b) provide minefield of 'null cipher toggles' c) ensure that any half-conformant implementation is multi-megabyte of ???
asciilifeform: so, i've no intention of supporting ~any~ part of rfc4880 except as required to process e.g. this example .
asciilifeform: i.e. signatures made via gpg 1.4.10 , set to max supported hash (sha512) on 2048...8192b rsa keys, specifically, supported. anyffing else can go pound sand.
shinohai: As far as creating a "public" rsa key, just have to have ffa calculate your "N" and "E" neh?
asciilifeform: shinohai: current ffa/peh lacks hashing so cannot yet advertise 'replace gpg universally'
asciilifeform: ( need hashing for (utterly retarded terminology, but...) 'padding' )
shinohai: Ah I just saw this in above comments: "the operator is responsible for padding and otherwise preprocessing his payloads as he sees fit, using external tools."
asciilifeform: but even after 100% replacement, will still need to eat old-style (both old, and sometimes 'from other side of berlin') sigs
shinohai is currently swallowing Ch.5 has not advanced to 6 yet.
asciilifeform: shinohai: initially i wasn't even gonna include hashing at all. but realized that there's very little practically-useful crypto that doesn't call for hash at some point
asciilifeform: and ~0 in the way of usable external tooling. so it'll have to be in.
asciilifeform: shinohai: i saw that you've eaten ch4 btw.
shinohai: Yup, finally got sig posted up to www and your comments. (Holiday madness had eaten a lot of time)
asciilifeform: shinohai: had any headaches in 1--4 ?
shinohai: Not yet, the ch.4 puzzle was a head-scratcher though in quite a fun way.
asciilifeform: !q seen-anywhere mike_c
snsabot: mike_c last seen in #asciilifeform on 2019-12-27 03:58:15: i have much more reading to do.. thanks for the links ascii.
feedbot: << Qntra -- Armed Texan Kills Would Be Mass Shooter In Church, New York Incident Ends Differently

Random(asciilifeform) | Download hourly DB snapshot | Get Source Code