Re: [Discuss] Logging question for SOX compliance

2011-09-22 Thread Bill Ricker
On Thu, Sep 22, 2011 at 6:49 AM, scottmarydavid...@gmail.com < scottmarydavid...@gmail.com> wrote: > Changing the process down the road might be an option but for now I'm > simply > looking to capture info about file transfer activity. > Can you switch from SCP to SFTP on same transport & credent

[Discuss] Fotoxx (and Forth) at BLU

2011-10-20 Thread Bill Ricker
Dick and Jill, Great presentation on Fotoxx and how it fits the FOSS story arc at MMS. Had I realized the first third would be a trip down memory lane, I'd have brought my big MMSForth binder ! FORTH <3 IF HONK THEN I keep thinking we should hack a FORTH kernel into the open firmware for Canon ca

[Discuss] The RSA Keying links

2012-02-15 Thread Bill Ricker
Study #1 *"Ron was wrong, Whit is right"* *Arjen K. Lenstra and James P. Hughes and Maxime Augier and Joppe W. Bos and Thorsten Kleinjung and Christophe Wachter* Abstract http://eprint.iacr.org/2012/064/ Paper (short form) http://eprint.iacr.org/2012/064.pdf Reported in NYT as http://www.nytim

Re: [Discuss] AMD FX-8120 update

2012-03-05 Thread Bill Ricker
2012/3/5 Shankar Viswanathan > please see my colleague Sean White's presentation at > last year's Hotchips conference: > Thanks, that helps ! > I'd be happy to explain the high-level details of the architecture to > anyone that cares. > So is the Northbridge effectively half on-die and half

Re: [Discuss] camera files

2012-04-18 Thread Bill Ricker
find may avoid crossing filesys . do df or mount before and after to see where it's mounting. On 4/18/12, Nathan Meyers wrote: > On Wed, Apr 18, 2012 at 10:54:51AM -0400, dan moylan wrote: >> >> in yesteryear, when i plugged a camera into my computer, the >> camera files would show up under

Re: [Discuss] camera files

2012-04-18 Thread Bill Ricker
which os and version? -- Bill @n1vux bill.n1...@gmail.com ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

[Discuss] RedHat Summit @ Hynnes

2012-06-27 Thread Bill Ricker
Anyone else going ? -- Bill @n1vux bill.n1...@gmail.com ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

[Discuss] understanding the Unix/Linux Command Line (geekblog via G+)

2012-09-30 Thread Bill Ricker
Gabor Szabo originally shared this post : An interesting explanation of the Unix/Linux command line and how things got their name.

[Discuss] UEFI secure boot pre-loader security considered further Re: Fwd: [linux_forensics] Did you see this ? - Linux Foundation Announces Secure Boot Solution ....

2012-11-02 Thread Bill Ricker
On Thu, Nov 1, 2012 at 4:02 PM, Rich Pieri wrote: > This is a lie. Harsh. Not all errors are lies. Sometimes people are just wrong without malice. Writing is an inexact science. Sometimes editing for style destroys accuracy, even with formerly technical people doing it. The statement is closer

Re: [Discuss] Disabling UEFI and dual booting Linux and Windows

2012-11-24 Thread Bill Ricker
Even if one doesn't want to dual boot, even if one CAN disable secure boot [which may be easy or not], there's still a reason to want to use Secure boot with Ubuntu or whatever -- it will provide an added layer of protection from malware for you Linux, just as it does for Windows. (The malware is

[Discuss] re-enabling ctrl-alt-backspace in Xubuntu 12.04

2012-12-08 Thread Bill Ricker
Graphical menu option buried deep in Ubuntu 12.04 ( http://www.inforbiro.com/blog-eng/ubuntu-12-04-how-to-enable-ctrl-alt-backspace/ ) is not in Xubuntu http://ubuntuforums.org/showthread.php?t=2019107 *Re: How to enable Ctrl + Alt + Backspace in Xubuntu 12.04?* -- Th

[Discuss] Tech 7/9 7pm MIT - Perl and Java, together at last ?

2013-07-31 Thread Bill Ricker
*Tuesday, July 9, 2013, E51-376 7pm-10pm* speaker William Cox and David Larochelletopic Using Inline::Java with Perl This talk is a report on inquiry begun on the [ mailing list http://www.mail-archive.com/boston-pm@mail.pm.org/index.html#07176 ] Talk begins at 7:30. Refreshments in the hallway p

[Discuss] Fwd: Boston Linux Meeting Wednesday, September 18, 2013 - PGP/GnuPG Keysigning Party XIV

2013-09-14 Thread Bill Ricker
KEYSIZE for this year is 2048. Key size 1024 is no longer considered safe for public keys expiring later than Dec 2013. Please use size 2048 this year, whether choosing RSA/RSA or DH/DSA (or RSA or DSA signing-only keys) Folks who have 1024 size keys should make 2048 keys. (You can sign the new 2

[Discuss] Fwd: Boston Linux Meeting reminder today, September 18, 2013 - PGP/GnuPG Keysigning Party XIV

2013-09-18 Thread Bill Ricker
-- Forwarded message -- From: Bill Ricker Date: Wed, Sep 18, 2013 at 11:23 AM Subject: Re: Boston Linux Meeting reminder today, September 18, 2013 - PGP/GnuPG Keysigning Party XIV To: Jerry Feldman Cc: BLU , Greater New Hampshire LUG < gnhlug-disc...@gnhlug.org> Based on

Re: [Discuss] Boston Linux Meeting reminder today, September 18, 2013 - PGP/GnuPG Keysigning Party XIV

2013-09-21 Thread Bill Ricker
threatlevel/ e.g., overview - http://www.technologyreview.com/news/519171/nsa-leak-leaves-crypto-math-intact-but-highlights-known-workarounds/ On Wed, Sep 18, 2013 at 11:43 AM, Bill Ricker wrote: > > > -- Forwarded message -- > From: Bill Ricker > Date: Wed, Sep 18, 2013 at 11:

Re: [Discuss] BLU Keysigning CAFF (CA Fire and Forget) vs bash script

2013-09-23 Thread Bill Ricker
re scripted email failures / workings ... Scripts that assume your ISP will let you push SMTP:25 out from home are likely problematic today. If your Sendmail is configured to route via ISP it'll work ... but if only Thunderbird is so configured, smpt/mailx may both fail. I uploaded the mailx file

Re: [Discuss] Boston Linux Meeting reminder, tomorrow, October 16, 2013 - SEO and Social Media Marketing

2013-10-16 Thread Bill Ricker
As a follow-up to the "good content" recurring theme in tonight's presentation, Canadian Broadcasting Corp's SPARK program today aired an interview on WWW Link Rot as a threat to academic footnote integrity, particularly in Law Reviews. Link Rot at the U.S. Supreme Court - Spark - CBC Player www.c

[Discuss] Gwibber Re: BLU October - SEO and Social Media Marketing

2013-10-17 Thread Bill Ricker
Interesting, Gwibber has improved a lot since i last used it. (I gave up when Twitter changed Auth systems. It works again.) Do you know if Gwibber will manage multiple Twitter IDs simultaneously ? I probably ought to split my Twitter persona by interest area ... -- Bill @n1vux bill.n1...@gmai

[Discuss] Fwd: Can I borrow a mDP to HDMI adapter for the next meeting?

2013-11-13 Thread Bill Ricker
On Wed, Nov 13, 2013 at 10:14 AM, Jerry Feldman wrote: > > Or does it search for any active input? If that's the case I'll slum > > with VGA. > I don't have an adapter, but you select the input on the screen at the > instructor console. However, I can stop at MicroCenter or possibly Best > Buy t

Off topic - science book signing this week: the astronomer who killed Pluto

2011-01-24 Thread Bill Ricker
Of possible interest to the omni-nerds on the list - Mike Brown "How I Killed Pluto and Why It Had It Coming" Public lecture, book signing, Wednesday, January 26 · 7:00pm - 9:00pm Tommy Doyles Irish Pub & Restaurant (downstairs Crimson Lounge) 96 Winthrop St. - Harvard Square Cambridge, MA Hosted

Re: [Discuss] Relevance of PGP?

2011-06-10 Thread Bill Ricker
On Fri, Jun 10, 2011 at 8:12 AM, Edward Ned Harvey wrote: > Go get a free > certificate from a signature with a free CA cert deserves no trust - it verifies the email address was the email address on a certain date only. -- Bill @n1vux bill.n1...@gmail.com __

Re: [Discuss] Relevance of PGP?

2011-06-12 Thread Bill Ricker
On Sat, Jun 11, 2011 at 9:14 AM, Edward Ned Harvey wrote: > Same as PGP. wrong. >  It's the external context that gives you more trust. Correct. Most people don't know what the context in a SSL cert really is, though. Free certs from Commercial CA's provide a trusty flavor with no actual trus

Re: [Discuss] Surprises at the June Supercomputing conference

2011-06-21 Thread Bill Ricker
On Tue, Jun 21, 2011 at 10:23 AM, Richard Pieri wrote: > Betting the bank on [SPARC].  The x86 architecture is getting there for > high-end server use, but it isn't there, Are we reading the same tea leaves? They're betting the bank on Exadata and Cloud. Which is Exadata built with? Xeon, not Sp

Re: [Discuss] Relevance of PGP?

2011-08-18 Thread Bill Ricker
> > easier for end users, ... and not cost money… That would be nice! And it would be even nice if the nice person doing all that for free managed not to compromise security while doing it, but that's rather less likely. "Easy, Secure, Free, pick two" isn't guaranteed the way quick, good, cheap -

Re: [Discuss] Dev Ops - architecture (local not cloud)

2013-12-06 Thread Bill Ricker
On Fri, Dec 6, 2013 at 10:56 AM, Richard Pieri wrote: > Greg Rundlett (freephile) wrote: > >> I think it's pretty obvious why it's not performing: user home >> directories >> (where developers compile) should not be NFS mounted. [1] The source >> repositories themselves should also not be store

Re: [Discuss] Why use Linux? (back to original question)

2014-02-12 Thread Bill Ricker
A discussion of the ethics of Apache/MIT license vs GPL, however interesting, has long since departed from Micky's requested topic still on the Subject: line, which was motivated as, how to sell (Gnu/)Linux as alternative to Windows Server as host for Drupal. So can i rephrase OP's question as ,

Re: [Discuss] Why use Linux? (back to original question)

2014-02-12 Thread Bill Ricker
The question was Why Linux meant in context, Why Linux Not Windows, for an audience that may not know there's a choice at all. Of course *We* know that Mac Server, OpenBSD, *BSD, and all the Linux are all better than the old-school Unix Sys V/BSD/... servers, and thus any of them would be better t

[Discuss] follow-ups from meeting

2014-03-19 Thread Bill Ricker
1. Thanks Christoph! 2. The answer to the Massachusetts geography question in Q&A is http://en.wikipedia.org/wiki/Southwick,_Massachusetts ( I guess you could remember it as it wicks to the south. ) -- Bill @n1vux bill.n1...@gmail.com ___ Discuss mail

Re: [Discuss] Redundant array of inexpensive servers: clustering?

2014-03-30 Thread Bill Ricker
Hi Rich ! Commercial practice varies. The nicest HA solutions available today do require apps be "cloud" enabled, which is to say fully virtualized; you can then in-house them by building your own mini-cloud. Choice 1 is whether storage is replicated or shared. Shared can be a cluster FS or a bac

Re: [Discuss] Redundant array of inexpensive servers: clustering?

2014-03-30 Thread Bill Ricker
On Sun, Mar 30, 2014 at 7:31 PM, Richard Pieri wrote: > Just be sure to do your backups because DRBD will happily replicate > trashed data to the cold node. I've seen a big-name commercial block-replication solution duplicate trashed data to the cold spare ... wasn't pretty ! -- Bill @n1vux

Re: [Discuss] Redundant array of inexpensive servers: clustering?

2014-03-31 Thread Bill Ricker
On Mon, Mar 31, 2014 at 11:03 AM, Richard Pieri wrote: > Bill Ricker wrote: > >> I've seen a big-name commercial block-replication solution duplicate >> trashed data to the cold spare ... wasn't pretty ! >> > > Another great example of how replication is

Re: [Discuss] Redundant array of inexpensive servers: clustering?

2014-03-31 Thread Bill Ricker
On Mon, Mar 31, 2014 at 4:06 PM, Richard Pieri wrote: > How hard could it be? Really hard. Designing and building reliable HA > clusters from scratch is one of the hardest things a sysadmin can be called > upon to do. Yup. Very tough for legacy apps not designed for anything fancier than reboot

Re: [Discuss] easy clustering of applications

2014-03-31 Thread Bill Ricker
On Mon, Mar 31, 2014 at 5:33 PM, Tom Metro wrote: > It does seem like every application has its own unique approach to > clustering. > or, for legacy applications, their own assumptions that need to be worked around with kludges to repackage for HA. -- Bill @n1vux bill.n1...@gmail.com

Re: [Discuss] AeroFS

2014-04-19 Thread Bill Ricker
On Sat, Apr 19, 2014 at 6:32 PM, Richard Pieri wrote: > Dropbox for example does the encryption properly but they can and do hand > over the keys to law enforcement upon request. ​If you can hand over keys, you're not doing it right ! ​ -- Bill Ricker bill.n1...@gmai

Re: [Discuss] AeroFS

2014-04-19 Thread Bill Ricker
e better, you'd be shocked whose CA your browser will trust to sign *.google.com .)​ -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] AeroFS

2014-04-19 Thread Bill Ricker
On Sat, Apr 19, 2014 at 7:59 PM, Richard Pieri wrote: > Which is a matter of trust rather than of implementation. Like I said. > ​I am not talking Implementation but Requirements. ​ Deaf ears.​ ​Quite. ​ -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in

Re: [Discuss] Building a non-profit membership list?

2014-04-20 Thread Bill Ricker
rships and event-signups but in a properly-secured way. WordPress > has > > two completely separate plugins (WP-CRM and Events Manager) that don't > > seem to > > solve my problem in a way that non-tech people can grasp. > > > > -rich > > > > > > ___

Re: [Discuss] OpenBSD and LibreSSL

2014-04-23 Thread Bill Ricker
needs doing ! -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Facebook backups?

2014-04-28 Thread Bill Ricker
eel for those that prefer such; looks like Ruby has.)​ -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Is Sharp AL-1540CS a paperweight on Linux

2014-05-05 Thread Bill Ricker
On Mon, May 5, 2014 at 2:34 PM, Dan Ritter wrote: > It's a GDI printer: it relies on Windows to produce a rasterized > image for it to print. It won't work. > ​So GDI-printer is the printer-equivalent of a WinModem ? ​ -- Bill Ricker bill.n1...@gmail.com https://www.li

Re: [Discuss] Is Sharp AL-1540CS a paperweight on Linux

2014-05-05 Thread Bill Ricker
On Mon, May 5, 2014 at 7:45 PM, Dan Ritter wrote: > Yes. GDI is the API that Windows applications use to ​Yes, i remember GDI from MFC (and Win95). I didn't remember that they connected printers to it. ​ ​Premature optimization is evil​ ​So true.​ -- Bill Ricker bill.n1...@gmail.c

[Discuss] Fwd: BLU Desktop GNU/Linux SIG Meeting - Free Software for Photographers - Weds, May 7, 2014

2014-05-08 Thread Bill Ricker
s Dick pointed out, the author Mike has great tutorial videos http://www.kornelix.com/fotoxx_videos.html (​There has been slight improvements to menus and dialogs since he last recorded those, but the basics work the same even though rearranged.) Bill Ricker

[Discuss] (ot) Android

2014-05-22 Thread Bill Ricker
Who wanted the notes for upgrading MicroCenter loss-leader Android? -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] DMARC issue, Yahoo and beyond

2014-05-29 Thread Bill Ricker
cribed from Gmail, a few posts from Yahoo could supposedly get *me* kicked from the list for excessive bouncing. I suppose I could try posting from Yahoo to prove the point, but the fingers i'd burn are my own. ​ ​ -- Bill Ricker bill.n1...@gmail.co

Re: [Discuss] TrueCrypt EOL, what's next?

2014-05-30 Thread Bill Ricker
two minor corrigenda - * I'd read earlier the new binaries are signed with a new signing key, but that it was provisioned from same CA previously used, prior to the fraca, because old key was expiring, so not particularly suspicious, but rather best practice. (One might like to see the new key sign

Re: [Discuss] TrueCrypt EOL, what's next?

2014-05-30 Thread Bill Ricker
son said, the "new" key was gotten early enough it would have been well before current incident​ -- if malicious, would show significant premeditation. -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss maili

Re: [Discuss] GPS feature in cellphones?

2014-06-06 Thread Bill Ricker
Navigation display), but requires a transmission to have anyone else see it (GPS tracking devices, E911). -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] GPS feature in cellphones?

2014-06-06 Thread Bill Ricker
On Fri, Jun 6, 2014 at 3:50 PM, Richard Pieri wrote: > It's because > they're not really off. > ​If it's off enough to make an airline happy, it's not reporting anything, even *if* it's passively tracking​ -- Bill Ricker bill.n1...@gmail.com

Re: [Discuss] peer to peer software

2014-06-07 Thread Bill Ricker
way will be awkward at best. -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] DMARC issue, Yahoo and beyond

2014-06-07 Thread Bill Ricker
t it in my *SPAM* folder with a warning, i did not get unsubscribed. Maybe Gmail has put in some logic to soften ​ *dmarc=fail (p=REJECT dis=NONE) header.from=yahoo.com <http://yahoo.com>* processing? Full headers follow below. -- Bill Ricker bill.n1...@gmail.com https://www

Re: [Discuss] DMARC issue, Yahoo and beyond

2014-06-08 Thread Bill Ricker
s just upgraded to 2.18 and I'm debating what to do with the Boston lists, that seems like the least un-desirable option. ​ -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://li

Re: [Discuss] color laser printer

2014-06-10 Thread Bill Ricker
l Ethernet interface, not just WiFi. I don't want my printer serving as a WiFi intrusion point. Just a few weeks ago, I > replaced it with a LaserJet M451dn for about $350. The > ​Nice price. What's the M prefix mean? -- Bill Ricker

[Discuss] Jim Gettys and BLU Re: seminar Thursday June 26: Jim Gettys on "(In)Security in Home Embedded Devices"

2014-06-24 Thread Bill Ricker
370. Presenter. Jim Gettys ... The State of X11 - Boston Linux & Unix User Group blu.org/cgi-bin/calendar/*2004-oct* Oct 20, 2004 - Presenter. Jim Gettys - Jim.Gettys hp com. Summary. Jim discusses the historical and ongoing development of the X Window System. Abstract. ​ -- Bill Ricker bi

Re: [Discuss] OpenERP and general Linux support for nonprofit

2014-07-20 Thread Bill Ricker
openerm/> I suspect one of the consultants on Boston.pm could help, I can poll them if you're interested.​ -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Seeking information on binaries called "entities" and "fixup"

2014-07-28 Thread Bill Ricker
etect MACscii and convert that too.) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] signal propagation in old houses

2014-07-28 Thread Bill Ricker
loor (and create some null spots due to standing waves as well). In general, the longer wave / lower frequency devices will have larger hot / dead zones, and shorter/higher=smaller. If *your* ceilings are free of wire lath (or expanded metal sheet lath), you may be able to establish vertical c

Re: [Discuss] Why the dislike of X.509?

2014-08-25 Thread Bill Ricker
can be blocked by an aggressive adversary with local or regional DNS/BGP poisoning ability, which is needed for most MITM anyway ! ) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Why the dislike of X.509?

2014-08-25 Thread Bill Ricker
lly escrow too. But that would be wrong. Moving RSA-style private keys of an asymmetric public/private is a mortal sin in cryptography; if you are sharing a secret, might as well be a shared symmetric key. Multiple Load-balancers all terminating connections for same

Re: [Discuss] Why the dislike of X.509?

2014-08-25 Thread Bill Ricker
stem remotely as him, and it's him in all the logs, without having to -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Why the dislike of X.509?

2014-08-25 Thread Bill Ricker
frame the session; they may well use browser SSL implementation. Good luck with that ! Rich's concern seems to be different, that any central store is less trustworthy than distributed/compartmentalized, in part due to damage limitation or la

Re: [Discuss] Why the dislike of X.509?

2014-08-25 Thread Bill Ricker
garbage even if connection was secure. The ability to create Man In The Middle attacks dynamically lets one capture new sessions, which is good enough for many Aggressor purposes. It's not a perfect Key Escrow, it doesn't let one recover OLD messages not through a MITM, but it also doesn&#

Re: [Discuss] Why the dislike of X.509?

2014-08-28 Thread Bill Ricker
ace instead of concentrating it, and implements session key negotiation without requiring asymmetric (PubKey), although public key is available for authentication. pretty slick. ( Don't think it would scale to the whole internet though, as we have other requirements there. ) -- Bil

Re: [Discuss] vnc

2014-08-28 Thread Bill Ricker
ms. (For those whose $work require Winders desktop, Putty PAgent.) >> People. People are the problem. > Yes, well, people are often the weakest point in any security system. Amen. Sing it ! If the people are NOT the weakest link, it's a terrible system ! -- Bill Ricke

Re: [Discuss] vnc

2014-08-28 Thread Bill Ricker
... should know ... jokes ... wears army boots # is 4th. your mother we...ars army boots ...ars combat boots movie ...ent to college looks like 10-16 bits for either phrase, depending how m

Re: [Discuss] vnc

2014-08-28 Thread Bill Ricker
k to 1.9 bits per char! (On this Ubuntu, gzip compresses 'words' file to 20.6 bits per 'word', which says even though gzip doesn't know English it gets pretty close.) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] vnc => passphrase entropy

2014-08-29 Thread Bill Ricker
of the offline password cracker suites have a Markov sentence generator? (if not why not?) (I'm pretty sure they already have a list of cliché/quotes for pass-phrases. They should have harvested IMDB and Bartletts quotes at the very least ! ) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] vnc => passphrase entropy

2014-08-29 Thread Bill Ricker
ongs 'ch' etc that it generates as urn units; but since equal frequency 'a' and 't' are more or less likely in a position based on vowel/consonants around it, as filtered in actual use it delivers rather less. Probably still more than 3 bits though, since a strict CA

Re: [Discuss] How do I add entropy?

2014-09-06 Thread Bill Ricker
Yes. Noise-bits from timing of Mouse, keyboard, and disk access are likely all to be harvested. -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] What key lengths are currently adequate?

2014-09-07 Thread Bill Ricker
not* affected by the presumed backdoor in Dual_EC_DRBG in FIPS 182-2 TLS. Same underlying EC Maths but, Different curves, Different use. ] -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] How do I add entropy?

2014-09-07 Thread Bill Ricker
s on a virtual box could be very very slow as they don't have hardware entropy sources available.) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] How do I add entropy?

2014-09-07 Thread Bill Ricker
you attend a PGP/GPG key-signing, bit efficiency is rather less relevant than gas mileage to get there. -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] SysVinit vs. systemd

2014-09-11 Thread Bill Ricker
that.) While we can debate artistic design choices and complain about personalities, it seems we don't have a lot of choice: if RedHat and Ubuntu and Gentoo and Debian will all be shipping SystemD, only the most fringe distros will keep SysV init on pid 1 or find a third path. -- Bill Ricker b

Re: [Discuss] SysVinit vs. systemd

2014-09-11 Thread Bill Ricker
7;m guessing it was Team Gnu; it's not a POSIX flag[*]. The SysIII/V, BSD, and Gnu teams all added a lot of flag features to the core executables and built-ins, but Gnu team style is furthest removed from the "do one thing well" style of Bell Labs through v6, PWB, & v7. [*] http:

Re: [Discuss] SysVinit vs. systemd

2014-09-11 Thread Bill Ricker
traction. ( From a security point of view, the Control Groups use in SystemD *should* actually be a good thing, so I'm wait and see here.) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] SysVinit vs. systemd

2014-09-11 Thread Bill Ricker
ommercial/IT usage point of view, the firms offering Slackware virtual hosting are pretty fringe, and no major IT suppliers are shipping it. Red Hat, Ubuntu, and maybe still Suse are the only major providers to IT. (There are others in the embedded spaces of course.) -- Bill Ricker bi

Re: [Discuss] SysVinit vs. systemd

2014-09-11 Thread Bill Ricker
OOD thing in isolation... does hurt portability, ties it to Linux Kernel, unless/until the other Kernels adopt them. Which might be a good thing, irrespective of the Init controversy?) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] SysVinit vs. systemd

2014-09-11 Thread Bill Ricker
reep too. Maybe more later ... -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] SysVinit vs. systemd

2014-09-11 Thread Bill Ricker
evel-headed advocacy for systemd without insulting people or SysV Init (says it isn't badly broken). It's not by a SystemD DEV but by a working sysadmin. http://utcc.utoronto.ca/~cks/space/blog/linux/SystemdWhyItWon?showcomments & http://utcc.utoronto.ca/~cks/space/blog/linux/S

Re: [Discuss] SysVinit vs. systemd

2014-09-15 Thread Bill Ricker
restart a failed service some > configurable threshold number of times in a configurable threshold period of > time, and if the service continually fails, then the service gets disabled. > I assume something similar exists for systemd. > _

Re: [Discuss] SysVinit vs. systemd

2014-09-17 Thread Bill Ricker
erminate dialog up on the server's console, defeating auto-restart. (So we had to change the default DrWatson setting, which was same on server as on workstations, so wrong.) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux _

Re: [Discuss] automatic daemon restarts

2014-09-17 Thread Bill Ricker
han others when folks assume otherwise. But being human, we also each assume our experience is more representative than not. ) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.

Re: [Discuss] SysVinit vs. systemd

2014-09-17 Thread Bill Ricker
t shift load to a N/N+m survivor) and keep the failed offline, you can debug at leisure while continuing/restoring service. [ how much debugging you can do off-line with it cut off from other tiers is a separate question, but you can at least collect 'forensics' that will be destroyed at re

Re: [Discuss] SysVinit vs. systemd

2014-09-17 Thread Bill Ricker
a critical DB server's data storage, i might use it again in similar max-uptime situation, but not as ubiquitously; for other things, other more virtual forms of disk access may be more resilient in reality. (And they're coming for our DBs too.) -- Bill Ricker bill.n1...@gmail.com h

Re: [Discuss] SysVinit vs. systemd

2014-09-17 Thread Bill Ricker
or Slackware or *BSD or Plan 9/Inferno. Commercial SysV/BSD UNIX derivatives probably provide a safe haven for 5-10 years too. AIX, Solaris, HPUX, ... -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discu

Re: [Discuss] Boston Linux Meeting reminder, tomorrow Wednesday, September 17, 2014 - Crypto News, TOR, and our PGP/GnuPG Keysigning Party XIV

2014-09-18 Thread Bill Ricker
djourn to the official after meeting meeting > location at The Cambridge Brewing Company > http://www.cambridgebrewingcompany.com/ > > -- > Jerry Feldman > Boston Linux and Unix > PGP key id:3BC1EB90 > PGP Key fingerprint: 49E2 C52A FC5A A31F 8D66 C0AF 7CEA 30FC 3BC1 EB90 > > > > > > > > > > > > > > > > > > > > > > > > > > > > -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Boston Linux Meeting reminder, tomorrow Wednesday, September 17, 2014 - Crypto News, TOR, and our PGP/GnuPG Keysigning Party XIV

2014-09-18 Thread Bill Ricker
t; - bill > > Here? http://blu.org/meetings/2014/09/2014-Crypto-notes.odt Yes. > I get, "You don't have permission to access > /meetings/2014/09/2014-Crypto-notes.odt on this server." > > Same for the OpenCL notes, but not for the one before that (IPv6). Looks

Re: [Discuss] Boston Linux Meeting reminder, tomorrow Wednesday, September 17, 2014 - Crypto News, TOR, and our PGP/GnuPG Keysigning Party XIV

2014-09-19 Thread Bill Ricker
st *hate* when that happens? :) > > Fixed. > > On Thu, Sep 18, 2014 at 2:59 PM, Bill Ricker wrote: >> >> On Thu, Sep 18, 2014 at 2:53 PM, Mike Small wrote: >> >> JABR has posted the notes for my Q&A-time update on The Last Year in >> >>

Re: [Discuss] raid controller drivers

2014-09-26 Thread Bill Ricker
Raid is fine when a system vendor is maintaining the cabinet with guaranteed replacement supplies. And must be replaced when vendor says it's going out of support. But not suitable for shoe-string systems. -- Bill Ricker bill.n1...@gmail.com https://www.link

Re: [Discuss] raid controller drivers

2014-09-26 Thread Bill Ricker
On Fri, Sep 26, 2014 at 11:46 AM, Richard Pieri wrote: >> That's great to know... what is hot then? When should I start to worry? > > > Ballpark? Around 95C, +/-5C. Agreed. Which is why video on this laptop is scary ... -- Bill Ricker bill.n1...@gmail.com https://www.l

Re: [Discuss] selinux nightmare

2014-09-28 Thread Bill Ricker
Chuck is spot on. Dan is the center of wisdom, and other advise looked good. ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Shellshock

2014-09-30 Thread Bill Ricker
I take exception to the Lisp.org quote. Yes, it's a fair point that Gnu project is older than either Apache or Linux, but that doesn't exempt Bash from criticism. (And if this bug is only 20 years old as claimed, being when ENV function overrides were invented, it's maybe a year older than Apache.

Re: [Discuss] Shellshock

2014-10-01 Thread Bill Ricker
ble, unlike commercial closed source where it's forbidden (except when actively required by Military contract). -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Need speaker and topic for October BLU meeting

2014-10-01 Thread Bill Ricker
boil it down. -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Shellshock

2014-10-01 Thread Bill Ricker
tations using pool processes and RPC for non-spawning CGI emulation avoid *this* problem, plenty of other room for trouble. ] -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Shellshock

2014-10-01 Thread Bill Ricker
e an incurable problem for Shell-Shock, but even if they are mod_cgi, they're nearly all using (/bin/sh, /bin/bash) => busybox alias. They sometimes APPEAR to have a bash, but do not, as it's too bloated for embedded use. (Cheapness made a goo

Re: [Discuss] Wire tester (like a tone tester)

2014-10-02 Thread Bill Ricker
ew additional parts, you just tee the sweep into the test port and watch for the reflection. You need to know the velocity factor to translate from time to distance, since C=3E8m/s is only in (near)vacuum; there are tables around. 73 de n1vux -- Bill Ricker bill.n1...@gmail.com https://www.li

Re: [Discuss] Wire tester (like a tone tester)

2014-10-03 Thread Bill Ricker
nt trolls - http://www.amazon.com/Smartronix-Linkcheck-Ethernet-Tester/dp/B000RGI6R6 http://www.amazon.com/Britta-Products-271710-Coupler-Straight/dp/B000BSLW8U/ -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

Re: [Discuss] Wire tester (like a tone tester)

2014-10-03 Thread Bill Ricker
ting up for TDR, or otherwise detected with DSP sampling.) -- Bill Ricker bill.n1...@gmail.com https://www.linkedin.com/in/n1vux ___ Discuss mailing list Discuss@blu.org http://lists.blu.org/mailman/listinfo/discuss

[Discuss] Perl Tech meeting Tues Oct 14th - Shell-Shocker CGI and Perl DoS bugs

2014-10-10 Thread Bill Ricker
ROOM: E51-376 SPEAKER: Bill Ricker (lead) We will examine the implications for the ShellShock BASH bug for Perl -- it's much wider than just about BASH CGI or even Perl CGI scripts -- and also a recently discovered/fixed but comparably long-lurking Perl DoS bug in a core module (Data::Dumper

Re: [Discuss] Perl Tech meeting Tues Oct 14th - Shell-Shocker CGI and Perl DoS bugs

2014-10-13 Thread Bill Ricker
n't affect me.) TOPIC: Shell-Shocker CGI and Perl DoS bugs DATE: Tuesday, October 14 TIME: 7:00 – 10:00 PM ROOM: E51-376 SPEAKER: Bill Ricker (lead) We will examine the implications for the ShellShock BASH bug for Perl -- it's much wider than just about BASH CGI or even Perl CGI scripts --

  1   2   3   >