shinohai: ok asciilifeform i need a redo on the above, i had to recalculate correct 'n' and now will verify both mine and your sigs fine.
shinohai: ~/devel/Ada # ./litmus.sh wot/shinohai.peh seals/ffa_ch4_ffacalc.kv.vpatch.shinohai.sig patches/ffa_ch4_ffacalc.kv.vpatch
shinohai: WARNING: The '?' command will use DEFAULT entropy source : /dev/random !
shinohai: WARNING: The '?' command will use DEFAULT entropy source : /dev/random !
shinohai: WARNING: The '?' command will use DEFAULT entropy source : /dev/random !
shinohai: VALID GPG RSA signature from shinohai <btcinfo@sdf.org>
asciilifeform: shinohai: post the pub, i can edit if you like
shinohai: asciilifeform: http://btc.info.gf/paste/ab4d6e@raw
asciilifeform: shinohai: updated
shinohai: tyvm
asciilifeform: np
shinohai: overall, very nifty. Will scratch head over the clearsign problem
asciilifeform: shinohai: 'clearsign' needs slightly different logic (to find & extract the payload, then reprocess the newlines as the idjit rfc demands; and iirc 'class' field differs) but that's afaik it
asciilifeform: shinohai: i'ma fix the warnings crapola in the next rev ( sig verification obv. dun use rng )
asciilifeform: really that warning oughta trigger strictly on 1st use of '?' on tape and not otherwise
shinohai: Saved your .peh key and mine to http://btc.info.gf/devel/ada/ffa/wot/
asciilifeform: a++
asciilifeform: still need to patch vtron to ride on this.
asciilifeform: (i'ma patch v.py , other folx can do others if/when want)
asciilifeform: observe that litmus already behaves like vtron wants gpg to behave (i.e. dun need gymnastics to work around 'keychain' crapola)
asciilifeform: i looked at my .wot , found that virtually erryone had their gpg set to emit sha256 or even sha1
shinohai: mine set to 512
asciilifeform: right, or wouldn't have eaten
asciilifeform: but apparently shinohai and asciilifeform the only ones w/ correctly-configured gpg..
asciilifeform: prolly oughta put in support for the sad hashes, or good bit of material from folx whose trees i'm still using, but no longer tuned in, won't press.
shinohai: worx a++ with esthlos-v, literally two commands builds entire orchestra
asciilifeform: ( will need switch statement after sig_digest_algo , and corresponding values for HASHER , ASN, and MD_LEN )
asciilifeform: shinohai: neato.
asciilifeform notyet tried esthlos-v
snsabot: Logged on 2019-12-06 15:22:56 asciilifeform: the patch viewer i'ma have to reimplement (w/ hopper for in-wot sigs) unless he somehow comes back to life
snsabot: Logged on 2019-12-30 17:07:28 asciilifeform: shinohai: realized the need for this while attempting this earlier item -- apparently gpg 1.4 has known (but afaik not fixed) cpu wedge attacks via crafted input turds (and some unknown # of unknown... massive ball o'shit) and really not suitable for 'anyone can feed' www system
asciilifeform: it is prolly possible to implement similar item in e.g. php. but i'ma leave that to the php aficionados.
shinohai: keks
asciilifeform: hey, folx who are into coprophagia, can... who am i to say.
adlai: asciilifeform: /topic link gives a broken redirect, to 127.0.0.1:5002/log
adlai: easiest fix - delete /log/asciilifeform from the link, looks like the landing page of logs.nosuchlabs.com defaults there anyway
adlai: http://logs.nosuchlabs.com/log/asciilifeform/2020-01-05#1004837 << indeed, first time I ever played Go against Meni Rosenfeld, he had said something like "it's not a game if there's no clock" about chess to the people who were there to play chess against him
snsabot: Logged on 2020-01-05 17:29:50 asciilifeform: http://logs.nosuchlabs.com/log/asciilifeform/2020-01-05#1004831 << nuffin stops you even now from making bets with a friend
adlai: so i told him it's not a game if we don't bet, and earned iirc... 5 bitcents, in the days when that was about the price of a solid dinner
shinohai: ./pehkey asciilifeform
shinohai: ^ for when asciilifeform awakens
asciilifeform: http://logs.nosuchlabs.com/log/asciilifeform/2020-01-07#1004945 << it worx, i have nfi what you saw
snsabot: Logged on 2020-01-07 10:59:00 adlai: asciilifeform: /topic link gives a broken redirect, to 127.0.0.1:5002/log
asciilifeform: http://logs.nosuchlabs.com/log/asciilifeform/2020-01-07#1004947 << wasn't he an infamous con man ? where didja run into him ?
snsabot: Logged on 2020-01-07 11:02:09 adlai: http://logs.nosuchlabs.com/log/asciilifeform/2020-01-05#1004837 << indeed, first time I ever played Go against Meni Rosenfeld, he had said something like "it's not a game if there's no clock" about chess to the people who were there to play chess against him
asciilifeform: http://logs.nosuchlabs.com/log/asciilifeform/2020-01-07#1004950 << this is neat, shinohai , but howabout some vpatch ?
snsabot: Logged on 2020-01-07 11:56:33 shinohai: ./pehkey asciilifeform
shinohai: patience, asciilifeform ,patience!
shinohai: le
feedbot: http://fixpoint.welshcomputing.com/2020/errata-for-gbw-node-drafts-to-date-and-bitcoin-txid-collisions/ << Fixpoint -- Errata for gbw-node drafts to date, and Bitcoin txid collisions
feedbot: http://qntra.net/2020/01/sha1-collisions-get-cheaper/ << Qntra -- SHA1 Collisions Get Cheaper
feedbot: http://www.loper-os.org/?p=3636 << Loper OS -- "Finite Field Arithmetic." Chapter 20B: Support for Selected Ancient Hash Algos in "Litmus."
shinohai: heh works in my browser
asciilifeform: seems to be a selection but missing the actual article ?p=xxx
shinohai: anywho, latest vpatch no longer complains "Digest Algo must equal 0A; instead is 02."
asciilifeform: well yes
asciilifeform: it supports 2,8,9,10,11.
asciilifeform: fwiw asciilifeform also had sha1 sigs in very very early days (afaik none of the items thusly signed are currently in use anywhere)
asciilifeform has nfi wai some folx are still emitting sha1 sigs, the fix was discussed repeatedly in #t, and doesn't require reissuing pubkey
asciilifeform: shinohai: this also fixed.
snsabot: Logged on 2020-01-07 00:27:12 shinohai: WARNING: The '?' command will use DEFAULT entropy source : /dev/random !
shinohai: ~/devel/ada # ./litmus.sh wot/diana_coman.peh ffa_ch1_genesis.kv.vpatch.diana_coman.sig patches/ffa_ch1_genesis.kv.vpatch
shinohai: WARNING: This sig was made with SHA-1, which is cheaply breakable!
shinohai: WARNING: Please contact the signer (Diana Coman <office@dianacoman.com>) !
shinohai: VALID GPG RSA signature from Diana Coman <office@dianacoman.com>
shinohai: ^ no warnz
asciilifeform: shinohai: as pictured in ch20b yes