00:26 |
shinohai |
ok asciilifeform i need a redo on the above, i had to recalculate correct 'n' and now will verify both mine and your sigs fine. |
00:27 |
shinohai |
~/devel/Ada # ./litmus.sh wot/shinohai.peh seals/ffa_ch4_ffacalc.kv.vpatch.shinohai.sig patches/ffa_ch4_ffacalc.kv.vpatch |
00:27 |
shinohai |
WARNING: The '?' command will use DEFAULT entropy source : /dev/random ! |
| |
↖ |
00:27 |
shinohai |
WARNING: The '?' command will use DEFAULT entropy source : /dev/random ! |
00:27 |
shinohai |
WARNING: The '?' command will use DEFAULT entropy source : /dev/random ! |
00:27 |
shinohai |
VALID GPG RSA signature from shinohai <btcinfo@sdf.org> |
00:27 |
asciilifeform |
shinohai: post the pub, i can edit if you like |
00:28 |
shinohai |
asciilifeform: http://btc.info.gf/paste/ab4d6e@raw |
00:28 |
asciilifeform |
shinohai: updated |
00:29 |
shinohai |
tyvm |
00:29 |
asciilifeform |
np |
00:31 |
shinohai |
overall, very nifty. Will scratch head over the clearsign problem |
00:32 |
asciilifeform |
shinohai: 'clearsign' needs slightly different logic (to find & extract the payload, then reprocess the newlines as the idjit rfc demands; and iirc 'class' field differs) but that's afaik it |
00:42 |
asciilifeform |
see also. |
00:44 |
asciilifeform |
shinohai: i'ma fix the warnings crapola in the next rev ( sig verification obv. dun use rng ) |
00:45 |
asciilifeform |
really that warning oughta trigger strictly on 1st use of '?' on tape and not otherwise |
00:56 |
shinohai |
Saved your .peh key and mine to http://btc.info.gf/devel/ada/ffa/wot/ |
00:56 |
asciilifeform |
a++ |
00:57 |
asciilifeform |
still need to patch vtron to ride on this. |
00:57 |
asciilifeform |
(i'ma patch v.py , other folx can do others if/when want) |
00:58 |
asciilifeform |
observe that litmus already behaves like vtron wants gpg to behave (i.e. dun need gymnastics to work around 'keychain' crapola) |
01:00 |
asciilifeform |
i looked at my .wot , found that virtually erryone had their gpg set to emit sha256 or even sha1 |
01:00 |
shinohai |
mine set to 512 |
01:01 |
asciilifeform |
right, or wouldn't have eaten |
01:01 |
asciilifeform |
but apparently shinohai and asciilifeform the only ones w/ correctly-configured gpg.. |
01:02 |
asciilifeform |
prolly oughta put in support for the sad hashes, or good bit of material from folx whose trees i'm still using, but no longer tuned in, won't press. |
01:03 |
shinohai |
worx a++ with esthlos-v, literally two commands builds entire orchestra |
01:03 |
asciilifeform |
( will need switch statement after sig_digest_algo , and corresponding values for HASHER , ASN, and MD_LEN ) |
01:04 |
asciilifeform |
shinohai: neato. |
01:04 |
* |
asciilifeform notyet tried esthlos-v |
01:10 |
asciilifeform |
'litmus' really for this ( in light of this ) but oughta fit any vtron. |
01:10 |
snsabot |
Logged on 2019-12-06 15:22:56 asciilifeform: the patch viewer i'ma have to reimplement (w/ hopper for in-wot sigs) unless he somehow comes back to life |
01:10 |
snsabot |
Logged on 2019-12-30 17:07:28 asciilifeform: shinohai: realized the need for this while attempting this earlier item -- apparently gpg 1.4 has known (but afaik not fixed) cpu wedge attacks via crafted input turds (and some unknown # of unknown... massive ball o'shit) and really not suitable for 'anyone can feed' www system |
01:13 |
asciilifeform |
it is prolly possible to implement similar item in e.g. php. but i'ma leave that to the php aficionados. |
01:15 |
shinohai |
keks |
01:16 |
asciilifeform |
hey, folx who are into coprophagia, can... who am i to say. |
| |
~ 9 hours 42 minutes ~ |
10:59 |
adlai |
asciilifeform: /topic link gives a broken redirect, to 127.0.0.1:5002/log |
| |
↖ |
10:59 |
adlai |
easiest fix - delete /log/asciilifeform from the link, looks like the landing page of logs.nosuchlabs.com defaults there anyway |
11:02 |
adlai |
http://logs.nosuchlabs.com/log/asciilifeform/2020-01-05#1004837 << indeed, first time I ever played Go against Meni Rosenfeld, he had said something like "it's not a game if there's no clock" about chess to the people who were there to play chess against him |
| |
↖ ↖ |
11:02 |
snsabot |
Logged on 2020-01-05 17:29:50 asciilifeform: http://logs.nosuchlabs.com/log/asciilifeform/2020-01-05#1004831 << nuffin stops you even now from making bets with a friend |
11:03 |
adlai |
so i told him it's not a game if we don't bet, and earned iirc... 5 bitcents, in the days when that was about the price of a solid dinner |
| |
~ 53 minutes ~ |
11:56 |
shinohai |
./pehkey asciilifeform |
| |
↖ |
11:56 |
btcinfobot |
http://btc.info.gf/wot/rsa/asciilifeform.peh |
11:56 |
shinohai |
^ for when asciilifeform awakens |
| |
~ 4 hours 42 minutes ~ |
16:39 |
asciilifeform |
http://logs.nosuchlabs.com/log/asciilifeform/2020-01-07#1004945 << it worx, i have nfi what you saw |
16:39 |
snsabot |
Logged on 2020-01-07 10:59:00 adlai: asciilifeform: /topic link gives a broken redirect, to 127.0.0.1:5002/log |
16:40 |
asciilifeform |
http://logs.nosuchlabs.com/log/asciilifeform/2020-01-07#1004947 << wasn't he an infamous con man ? where didja run into him ? |
16:40 |
snsabot |
Logged on 2020-01-07 11:02:09 adlai: http://logs.nosuchlabs.com/log/asciilifeform/2020-01-05#1004837 << indeed, first time I ever played Go against Meni Rosenfeld, he had said something like "it's not a game if there's no clock" about chess to the people who were there to play chess against him |
16:40 |
asciilifeform |
http://logs.nosuchlabs.com/log/asciilifeform/2020-01-07#1004950 << this is neat, shinohai , but howabout some vpatch ? |
16:40 |
snsabot |
Logged on 2020-01-07 11:56:33 shinohai: ./pehkey asciilifeform |
| |
~ 20 minutes ~ |
17:01 |
shinohai |
patience, asciilifeform ,patience! |
17:01 |
shinohai |
le |
| |
~ 1 hours 17 minutes ~ |
18:19 |
feedbot |
http://fixpoint.welshcomputing.com/2020/errata-for-gbw-node-drafts-to-date-and-bitcoin-txid-collisions/ << Fixpoint -- Errata for gbw-node drafts to date, and Bitcoin txid collisions |
| |
~ 1 hours 32 minutes ~ |
19:51 |
feedbot |
http://qntra.net/2020/01/sha1-collisions-get-cheaper/ << Qntra -- SHA1 Collisions Get Cheaper |
| |
~ 1 hours 5 minutes ~ |
20:56 |
feedbot |
http://www.loper-os.org/?p=3636 << Loper OS -- "Finite Field Arithmetic." Chapter 20B: Support for Selected Ancient Hash Algos in "Litmus." |
| |
~ 1 hours 16 minutes ~ |
22:13 |
asciilifeform |
shinohai: http://www.loper-os.org/?p=3636&cpage=1#comment-19866 |
22:17 |
shinohai |
heh works in my browser |
22:18 |
asciilifeform |
seems to be a selection but missing the actual article ?p=xxx |
22:19 |
shinohai |
anywho, latest vpatch no longer complains "Digest Algo must equal 0A; instead is 02." |
22:19 |
asciilifeform |
well yes |
22:20 |
asciilifeform |
it supports 2,8,9,10,11. |
22:20 |
asciilifeform |
fwiw asciilifeform also had sha1 sigs in very very early days (afaik none of the items thusly signed are currently in use anywhere) |
| |
↖ |
22:24 |
* |
asciilifeform has nfi wai some folx are still emitting sha1 sigs, the fix was discussed repeatedly in #t, and doesn't require reissuing pubkey |
| |
~ 29 minutes ~ |
22:53 |
asciilifeform |
shinohai: this also fixed. |
22:53 |
snsabot |
Logged on 2020-01-07 00:27:12 shinohai: WARNING: The '?' command will use DEFAULT entropy source : /dev/random ! |
22:56 |
shinohai |
~/devel/ada # ./litmus.sh wot/diana_coman.peh ffa_ch1_genesis.kv.vpatch.diana_coman.sig patches/ffa_ch1_genesis.kv.vpatch |
22:56 |
shinohai |
WARNING: This sig was made with SHA-1, which is cheaply breakable! |
22:56 |
shinohai |
WARNING: Please contact the signer (Diana Coman <office@dianacoman.com>) ! |
22:56 |
shinohai |
VALID GPG RSA signature from Diana Coman <office@dianacoman.com> |
22:56 |
shinohai |
^ no warnz |
22:56 |
asciilifeform |
shinohai: as pictured in ch20b yes |