/srv/irclogs.ubuntu.com/2013/10/23/#ubuntu-us-tn.txt

=== DJOmnifrog is now known as Omnifrog
=== eli-away is now known as elijah-mbp
elijah-mbp... i wish ubuntu et al would quit trying to reinvent things and just  build a solid, reliable experience.15:57
elijah-mbpi have 20 years of linux experience and a bunch of the desktop shit is just fucking confusing.15:57
elijah-mbpi mean, i'm actively considering just running OLVWM again.  from 1992/1993.  just so my head doesn't hurt all the time.15:58
wrstha ha elijah-mbp, have you tried xfce lately?16:01
cyberangerelijah-mbp: I'm with you, debian sid and openbox like I ran on lucid16:02
wrstnah, you two are just old farts that yell at the kids to get off your yard :P16:03
cyberangeractually that was further back, crunchbang running off of jaunty's repo's16:03
cyberanger...and keep it down will ya, I'm trying to rock climb here16:03
wrstha ha16:03
wrstI'm weird I really like Gnome3.10 they had been making me mad up until that point but I really like 3.1016:04
average_guyI'm definately in the "old fart" camp16:36
average_guythings are changing a bit fast for me16:39
elijah-mbphaha16:45
elijah-mbpi like things to really slow down.16:46
elijah-mbpi actually didn't mind the gnome3 / 'unity' stuff all that much.  it was just slower than i had hoped.16:46
elijah-mbpi really think that simple is better, and a bunch of the current features are... not doing what people need.16:46
elijah-mbpi mean, i fyou want to use a 10MB tiff as your wallpaper - go ahead, but it's going to be slow - but don't make everyone else do it.16:47
wrstI don't mind the lack of things being light weight so much, becuase most reasonably "new" hardware say last 5 years will run most things16:53
cyberangerbut how much resources are you saving for other tasks16:56
wrstI have found especially with something like kde it can be fairly light as in no kwin compositing that type of thing16:58
wrstand then you have xfce, xlde etc too16:58
cyberangertrue, and with virtualbox and a ram disc...I go overboard elsewhere, so openbox works17:00
wrstbut all the developement towards the new user, I'm not really for sure if the new user really exist17:03
wrstas in the person that is computer illeterate moving to linux17:04
cyberangerwell, are they moving to the windows 8 tiles, or OSX17:08
netritiouscyberanger: they are all moving back to DOS17:36
wrsthowdy netritious17:40
wrstcyberanger: I must say gnome is somewhat doing its own thing as much as any body does their own thing17:40
cyberangernetritious: lol, sad part is that might not be a joke17:55
cyberangerthe way people have held onto XP17:56
wrstafternoon chris458518:33
netritioushowdy wrst18:46
wrsthow are you doing netritious?18:46
netritiouscyberanger: compared to vista xp is da bomb lol18:47
wrstagreed !18:47
netritiouswrst: could always be worse, right? :)18:48
wrstyes so they tell me :)18:48
wrstnetritious: I'm excited I have a nexus 7 tablet (old one from 2012) supposed to be in the mailbox when I get home18:48
cyberangerit could be ME18:49
wrstcyberanger: that's a sore subject I rushed out and bought that mess as soon as it was released :\18:49
netritiousME was rebranded 98 with very few feature additions and quite a few feature removals18:50
wrstthe installer crashed repeatedly on me... that should have been my first sign18:51
cyberangerand did not include a complementary bottle of advil18:51
netritious2000 was very solid, much better than NT, 98, or ME IMHO...that year I switched to NTFS for primary partition lol18:51
wrstor a swear jar18:51
average_guyI have still never seen Vista.  Only heard how much it sucked. Rocked ME though18:51
netritiousnice1 wrst18:51
wrstnetritious: I'm happily using ext4 and zfs now at home18:52
* wrst hasn't drank the btrfs kool-aid yet18:52
netritiousne neither, but i'm closers18:52
netritious*closer18:52
wrstif I bork my install I might give it a go next tim18:53
* cyberanger has been on some systems with force compress on18:53
wrstcyberanger: didn't eat your hamster?18:55
cyberangernope18:55
wrstI might give it a try I've been feeling the need for an adventure and my install has been way too smoothe18:56
netritiousforce compress? as in the FS is flagged to compress everything?18:56
cyberangeryep18:56
netritiouswrst: what are you running?18:56
wrstarch still on my laptop, debian on the little vps I have18:57
cyberangereverything but boot18:57
netritiouswhy would someone do that cyberanger?18:58
netritiouswrst I keep finding myself back on ubuntu19:00
netritiousunless i want to build stuff then i use debian19:01
wrstnetritious: I do less modifying with arch than ubuntu, I like stock gnome, which is getting harder and harder to get a good experience on ubuntu19:01
cyberangernetritious: do what, force compress?19:01
netritiouslooking at either trying gentoo or going back to bsd land, but will most likely stay on ubuntu/debian for a while still19:02
cyberangermy case, make cryptanalysis next to impossible without a rubber hose19:02
netritiouscyberanger: yes19:02
netritiousthats a decent reason cyberanger19:03
netritious*'s19:03
netritiousgentoo has an active system hardening project and portage which is like freebsd ports19:06
netritiousI'm a long time fan of the freebsd ports system19:07
cyberangermakes it harder to correlate encrypted data with known plaintext, between that an my other peices of the process, leaves little room for any vector short of attacking me19:07
netritiouscyberanger: I figured as much when you said that19:07
netritiousi'm not to worried about my data minus keeping it backed up.19:09
Unit193Pretty sure I don't need to link to http://xkcd.com/538/ ? :D19:09
wrstUnit193: :)19:09
netritiousnice1 Unit19319:10
average_guyHahaha to tru19:10
Unit193By that time you can't remember anymore though. ;)19:11
netritiouscyberanger: I do use volume and file crypto in the event my systems are stolen by some random theif.19:11
netritiousTheif: "Oh, that computer looks cool! Bet it's worth a lot!"...proceeds to yank from wall while powered on19:13
Unit193Said the theif, to the moon...19:14
netritiousit happened to a freind who was giving a next door neighbor's teenage son some music lessons, who then broke in and stole everything when my friend went out of town.19:16
netritiousthe VGA and RJ45 port were still attache dot the cables19:17
netritious*ports19:17
netritiousand *attached to the cables19:18
netritiouscyberanger: are you using a system with a TPM module?19:20
* netritious thinks that module after TPM is a little redundant, but whatever19:21
netritiousandroid on a stick...any one here use one? and have you tried to put something other than android on it?19:24
wrstnetritious: I have never used one but researched it a while back didn't seem like they were powerful enough at the time that much would be very effective on them19:26
cyberangernetritious: nope, I don't agree with the TPM spec19:27
cyberangerif you don't fully control a cryptosystem, you have no control19:27
netritiouscyberanger: not sure i understand how TPM gives you less control?19:28
netritiouswrst: http://www.tronsmart.com/Item/4619:28
wrsthmm netritious now that has soome kick behind it19:30
netritiousyeah i've been waiting on something like this for a while now.19:32
netritiousgot a little taste of quad-core+1GB ddr with daughter's tablet (agptek i think) and it works very very well19:33
cyberangernetritious: it relates to the manufacture process with the  endorsement key19:34
netritious*1GB ddr319:35
netritiouscyberanger: please elaborate19:35
wrstI'm doing some googling on that little device that could be fun19:37
cyberangernetritious: I'm trying to remember fully, but the endorsement key is burned into the TPM at manufacture, which means the plant in china had at that moment access to the public and private keys19:48
cyberangerand hence the ability to compromise the TPM19:49
netritiousIf I were a gvt official or something, and had to travel to china, then yes, I might be worried a little.20:06
cyberangerI fall under the "or something" and am just as worried about them travelling here20:13
netritiousso how do you go about mitigating evil maid, cold/warm boot attacks, etc? "hands on attack" is how I think about it20:16
netritious"hands on console attack" is better..."HAC attack" lol20:18
cyberangerusb key holds boot partition, and nothing is kept in the MBR20:18
cyberangerso nothing for evil maid to latch onto20:18
netritiousI haven't heard of it done, but evil made could also be performed via firmware attacks20:20
cyberangercold boot and warm boot is a bit more challenging, aside from the systems using ECC ram, what I've tried doing is powering it down and then power it up and hope that it gets overwritten, or at least reassigned as free and screw up the read20:20
cyberangernot I power it up but don't decrypt20:21
cyberangerif it's firmware in the dvd drive, and is meant for linux, then I'm screwed20:21
netritiouslol20:22
netritiousdo you use encrypted swap cyberanger?20:22
cyberangerhowever part two of all these efforts is to send something home, so in theroy If I'm travelling, I'd be checking my network connections more so20:22
cyberangeryeah, encrypted swap and btrfs20:23
cyberangerhonestly, I'm more concerned of travelling to them and getting arrested by MSS20:23
cyberangerwith my gear not on me20:24
netritiousthinking about a bootable usb thumb drive that on boot, mounts your system's /boot ...20:42
netritiouson first run generates hashes, and on subsequent boots compares the file's hashes20:43
netritiousmaybe play a beep sequence based on what it finds and displays filenames that don't match20:44
netritioususe boot as an evil maid detector20:44
netritious*the system's /boot20:45
netritiousoh and the MBR would need to be dumped and checked20:54
netritiousmaybe in addition to that, a dd of /boot as backup so you can restore in the event of tampering20:56
netritiousoh and MBR hehe20:57
cyberangermy case, that's pretty much what I've done, just different methods20:57
cyberangerignore the MBR, since I'm telling it to USB boot20:57
cyberangerany files not in /boot are encrypted, any files in /boot are on the usb key along with kali linux21:01
cyberangerI can't check the firmware though21:01
cyberangerand I don't worry about /boot, leave it stock, nothing to protect, if it's compromised, regenerate it21:02
cyberangerand if it leaves my side, it's as good as compromised21:03
Unit193cyberanger: Kali, gnome right?  Did you ever review Backbox?21:06
cyberangeryeah, come to think of it, when using that boot mode21:09
cyberangerand backbox idk, not recently21:11
netritiouscyberanger: i see how your methods mitigate tampering without the usb /boot, but I don't see how you could determine if any one tried.21:45

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!