[04:46] morning everyone ;-) [05:37] cocooncrash: this sounds a little FUDy to me... http://codahale.com/how-to-safely-store-a-password/ [06:15] morning superfly [06:36] morning sakhi! [06:46] inetpro: that blog post is more FUD than fact... sure it takes longer, but that doesn't make it any safer [06:46] just longer to crach [06:46] *crack [06:47] * inetpro that were my thoughts as well [06:48] superfly: its interesting nevertheless [07:16] superfly: It's true [07:16] Password hashing should be slow. [07:17] (Nimbula uses bcrypt ;-) ) [07:20] Maaz: 62**8 [07:20] cocooncrash: 218340105584896 [07:20] Maaz: 218340105584896/700000000/3600 [07:20] cocooncrash: 86.6428990416 [07:22] Just over 3 days to bruteforce an 8 character alphunumeric password hashed with MD5 using 4 GPUs. [07:42] s/MD5/SHA1/ [07:43] (See also scrypt, which is designed to protect against hardware attacks by forcing more memory to be used.) [07:43] http://www.tarsnap.com/scrypt.html [07:46] cocooncrash: but it doesn't make it more difficult to hack, just slower [07:46] http://chargen.matasano.com/chargen/2007/9/7/enough-with-the-rainbow-tables-what-you-need-to-know-about-s.html [07:46] superfly: Which is the whole point [07:46] Days is feasible, centuries is not. [07:50] Maaz: 86.6428990416 * 1000 / 24 [07:50] cocooncrash: 3610.1207934 [07:50] If you use a hash function 1000 times slower than SHA1, then it'll take abotu 10 years to bruteforce an 8 character password. [07:52] cocooncrash: like I said, slower doesn't mean safer... it's a side effect that the person will probably give up, but I wouldn't call that "safe" [07:53] But if you change your password once a year, it becomes highly unlikely that it'll be bruteforce if the expected time is 5 years [07:54] If the expected time is a day or two it becomes very possible [07:55] superfly: All cryptography is based on the premise that it is not feasible to bruteforce [07:56] it's also pretty safe to say anything you encrypt today can be trivially decrypted in the future [07:56] If you use bcrypt with a 100ms hashing time, the expected time becomes centuries. [07:57] Maaz: 218340105584896 / 10 / 50000 / 4 / 3600 / 24 [07:57] cocooncrash: 1263.54227769 [07:59] 3 years to bruteforce an 8 character password with 100ms bcrypt hashing using the whole of EC2. [07:59] damn [07:59] Maaz: 62**10 / 10 / 50000 / 4 / 3600 / 24 / 365 [07:59] cocooncrash: 13307.0041519 [08:00] 13 centuries for a 10 character passsword. [08:32] * drubin likes this conversation [08:33] superfly: Where did that link just randomly come from? [08:57] drubin: you mean where did I find it? [08:58] superfly: Well you kinda popped out of the blue and pasted that link to cocooncrash [08:58] jut wanted to know context (although it was interesting0 [08:59] drubin: just that I tihnk cocooncrash has recommended bcrypt to be before [08:59] marcog: your xdg-open bug got accepted into maverick-proposed. Care to test it? [08:59] tumbleweed: i've starred it, will test [10:33] Ubuntu hour Sunday 12pm Gino's, Stellenbosch [10:46] http://loco.ubuntu.com/events/team/666/detail/ [11:19] drubin: I tweeted it but seriously, don't ask me where I got it, I can't remember [11:29] inetpro: tweeted what? [11:29] 02/02 10:33:06 superfly: Where did that link just randomly come from? [11:31] inetpro: Ah hehe [11:58] marcog: nice, someone else dealt with it [11:59] tumbleweed: i assume that means i don't have to do anything? [11:59] indeed [12:00] obviously it was quite the me too bug [12:00] marcog: I suffered that bug for ages :) [12:01] with chrome? [12:01] chromium [12:01] same thing :P [12:01] not at all [12:01] same thing [12:01] nobody even knows what's in chrome [12:03] Maaz: reverse karmaladder [12:03] froztbyte: 0: ubuntuforums (-3), 1: tomtom (-2), 2: empathy (-2), 3: hal (-1), 4: virtualbox (-1), 5: KnightRider (-1), 6: car services (-1), 7: kde (-1), 8: ucf (-1), 9: virtualenv (-1), 10: drl (-1), 11: wordpress (-1), 12: Nokia (-1), 13: opendns (-1), 14: digests (-1), 15: kspread (-1), 16: --. --- --- -.. -- --- .-. -. .. -. (-1), 17: Nepomuk (-1), 18: Virtuoso (-1), 19: Strigi (-1), 20: KDE's Desktop Search (-1), 21: sars (0), 22: w [12:03] seems like we are rather positive around here [12:03] Maaz: karmaladder [12:03] froztbyte: 0: superfly (20), 1: cocooncrash (18), 2: maiatoday (11), 3: drubin (10), 4: tumbleweed (10), 5: Vhata (8), 6: morgs (7), 7: confluency (6), 8: highvoltage (6), 9: Kilos (6), 10: ubuntu-za (2), 11: nuvolari (2), 12: russell (2), 13: Symmetria (2), 14: |3o|3 (2), 15: yusuf (2), 16: youtube-dl (1), 17: ScorpKing (1), 18: Web Africa (1), 19: Lenovo (1), 20: fnb (1), 21: ibid devs (1), 22: Hodgestar (1), 23: Android (1), 24: doghouse [12:04] Maaz: morsecode --. --- --- -.. -- --- .-. -. .. -. [12:04] linuxboy: Encodes as -.-. --- -.. . -....- -....- .-.-.- -....- -....- -....- -....- -....- -....- -....- .-.-.- .-.-.- -....- -....- -....- -....- -....- .-.-.- -....- .-.-.- -....- .-.-.- .-.-.- .-.-.- -....- .-.-.- [12:04] Maaz: morse --. --- --- -.. -- --- .-. -. .. -. [12:04] tumbleweed: Decodes as GOOD MORNIN [12:06] how did I get up there? [12:07] Maaz: superfly ftw [[ clearly ]] [15:07] bye [15:54] cocooncrash: that grub error i'm getting is actually "out of disk" [15:54] superfly: Hrm [15:55] return grub_error (GRUB_ERR_OUT_OF_RANGE, "%s out of disk", disk->name); [15:56] superfly: Looks like a geometry issue actually [15:56] nope, no disk name, just "error: out of disk." [15:56] Oh [15:57] So that seems to happen if it's got a sector number that lies outside the disk [15:57] I booted into a live cd and did a grub-install, so now I get "GRUB loading." and then "error: out of disk.", and then the grub rescue prompt [15:57] Only thing I can think of is that the partition table has a partition extending past the last sector [16:00] ooh :> I have karma :D [16:00] ok, home time [16:00] gtg [16:04] evening superfly and every one else [16:04] we got data again yoohoo [16:05] used gumtree for the first time [16:06] lo bmg505 how do you do [16:06] Kilos: I got ADSL, uncapped, no more data worries for me [16:06] hehe that so lekker superfly [16:06] is it darem faster [16:07] I already downloaded like 9 or 10 gigs last night [16:07] Kilos: no, it's about the same speed as my HSDPA [16:07] aw [16:07] mind you with ians modem here on hsdpa it was fast at times [16:08] much better than a cell [16:08] Kilos: ja, I had the super fast modem [16:09] oh well, at least you rid of the data cap hassle [16:09] and the costs of course [16:09] when I get that sorted out, yes [16:09] for this month (and probably next) I'm paying double :-( [16:10] eish [16:11] at least now I can do a clean install here and get rid of that bug [16:12] ah, cocooncrash... "19457 cylinders" ... "19267 - 19458" [16:12] that doesn't look quite right [16:22] That looks a bit dubious [16:22] Try to work in sectors though, fdisk should set CHS sensibly [16:23] fdisk -u [16:43] yeah, i've done that - still getting that error [16:44] hey all nlsthzn here *waves*... how to upgrade from Kubuntu 10.10 to 11.04... ubuntu is easy, I am finding Kubuntu a bitt less so [16:45] neil__: how are you doing it? via alternate CD or via apt-get and friends? [16:46] want to use apt-get or what ever means to do it via the net... ubuntu I would just run update-manager -d -c but in Kubuntu I am stumped :/ [16:48] 10 months and 23 days to xmas :) [16:48] hello south africa [16:49] so long to wait for x-mas QQ [16:52] just run do-release-upgrade and added a -d and something is happening... cheers [16:52] hi neil__ bmg505 [16:52] bmg505, where are you [16:53] Kilos: hey uncle :) [16:53] hehe [16:55] thanks... IRC server going down for maintenance... catch u guys later [16:55] cheers neil__ [17:31] cocooncrash: I just did a complete reinstall, and I still get that stupid error [17:31] recreated the partitions, everything [17:46] hey folks [17:50] ohi [17:50] * superfly restarts to experience KDE 4.6 [18:00] lol [18:01] superfly: you having issues [18:02] * Symmetria contemplates doing remote medical procedures over south african internet [18:02] * Symmetria is scared at the very thought [18:03] "Sorry about the 3 dead people, the internet went down" [18:03] hehe [18:03] "Please do nawt be fishing the med today, if you cut SEMEWE people gonna dieeeee" [19:22] night all. sleep tight [19:34] superfly: Oh bleh [19:34] indeed [19:36] Try using grub-legacy? [22:00] fp