/srv/irclogs.ubuntu.com/2014/04/10/#ubuntu-us-mi.txt

jrwrenHavenstance_: yes, looks like it.00:13
Havenstance_jrwren, that was a virtual machine running it. I just shut it off.00:13
jrwrenHavenstance_: bummer that you had to reboot. I went from 4TB to 12TB (adding 2 - 4TB drives) without a reboot00:14
Havenstance_jrwren, I rebooted cuz the mobo was too old to support hot swap :)00:15
Havenstance_at home I use a bunch of old stuff that i've thrown together00:15
mrgoodcatHavenstance_: if you want to check if you are vuln to the heartbleed to `openssl version -a` and check your build date00:25
mrgoodcatshould be built in the last 2 days00:25
Havenstance_okay00:34
Havenstance_yeah those in #xubuntu were rather rude and unhelpful about it00:34
Havenstance_mon apr 7 :) should be good, ty man00:35
cmaloneyhttp://magnatune.com/artists/albums/superdirt-algoriddims00:43
cmaloneymrgoodcat:00:43
jrwrenHavenstance_: dpkg -p libssl1.0.000:44
jrwrenthe Version field there should be newer than what is listed on this page: http://www.ubuntu.com/usn/usn-2165-1/00:45
Havenstance_jrwren, thanks for the info man :)00:45
Havenstance_I just built this install from USB like 2 days ago00:46
Havenstance_idk if that matters but not really worried about it, i'll be upgrading to 14.04 lts soon as it goes live00:46
mrgoodcatupgrade tomorrow00:47
mrgoodcatfinal beta00:47
mrgoodcatand the tubes will be faster00:47
jrwrenit matters :)00:54
jrwrenupgrade now. help test the betas.00:54
Havenstance_sadly enough, this hardware won't run 14.04 yet I tried a daily build the other day00:57
Havenstance_it died00:57
cmaloneyhttp://www.lordi.fi/01:05
jrwrenam tip:  echo BYOBU_PYTHON=python >> .byoburc   to prevent byobu from running python -c 'import snack' EVERY time it refreshes status line01:13
=== mrgoodcat_ is now known as mrgoodcat
cmaloneyjrwren: I stopped using byobu in favor of tmux01:22
cmaloneyhttps://github.com/paultag/hy01:38
cmaloneyhttps://github.com/hylang/hy/blob/master/hy/importer.py01:39
jrwreni use byobu-tmux01:47
jrwreni am a sucker for status line01:48
cmaloneymrgoodcat: http://openmetalcast.com02:13
cmaloney;)02:13
greg-gholy shit, this wikipedian died this weekend in a climbing accident, this is her last edit: https://en.wikipedia.org/w/index.php?title=Wikipedia:Peer_review/Bringing_Up_Baby/archive2&diff=prev&oldid=60166376406:44
greg-gso sad.06:44
cmaloney:(10:46
cmaloneyAlways sad to hear someone pass away10:46
Havenstanceis there a list of sites somewhere that were hit by heartbleed?13:13
HavenstanceI keep getting questions on this because our local news channel just picked this up this morning13:13
brouschAll of them13:14
Havenstancebrousch, that's kind of what I was leaning towards.13:14
Havenstancebecause even if the site in question doesn't use openSSL that doesn't mean that the DNS Server or something else wouldn't be using it potentially exposing passwords13:15
jrwrenDNS Server or something else?13:17
HavenstanceI know our network server has openssl 1.0.1d or something crazy like that on it.13:17
Havenstancejrwren, gateways, hosts, datacenters. all the information goes thru them first does it not?13:17
jrwrenumm... yes?13:18
jrwrenwell, not "hosts"13:18
jrwreneverything is a "host"13:18
Havenstanceor am i understanding this wrong13:18
jrwrenit sounds like you are understanding this wrong.13:18
jrwrenall information definitely does not go to a dns server.13:18
jrwrenthis isn't a packet sniffing vulnerability either, so just becuase https traffic traverses a gateway, does not make it inspectable13:19
Havenstanceokay so the purpose of open ssl is you call out thru the DNS Server gateway all that jazz, then establish a secure connection with that site alone13:19
jrwren"call out thru teh dns server" does nto makes sense.13:20
Havenstancebut if the site you are calling out to is vulnerable then your secure connection is compromised. DNS, Gateway, and anything in between no longer matter after the secure connection is made with the website no?13:21
jrwrenI can't understand what you are saying. You aren't using the common words used to describe network connections and sessions.13:21
HavenstanceI havent even finished my first cup of coffee cut me some slack :D not fully awake yet :)13:22
jrwrenhahah! me too.13:22
Havenstancewhat im asking is when you establish a secure connection, does it still call for DNS Translation after the connection is established? My understanding of OpenSSL is about zero to be honest13:23
jrwrenafter? no.13:24
HavenstanceCase in point, My network configuration here, I have the client machines, who route through the server, the server hosts DHCP, DNS, and a VPN Tunnel, Then I route to a router which does essentially the same thing as the server except its DNS calls to my ISP's DNS Server, from there its handed to my ISP and they route the traffic through the closest datacenters and on to the destination13:24
Havenstanceif there's a breach at any point in between isn't there a problem?13:25
jrwrendefine "breach"13:25
Havenstancebreach being a heartbleed vulnerability13:25
jrwrenright.13:25
jrwrenthen no, no problem.13:25
Havenstanceokay, because my system actually establishes a SSL connection with the destination not the points in between13:26
jrwrenright13:26
Havenstanceperfect, I understood it right, I just couldn't explain it to save my ass this morning lol13:26
Havenstancebtw, list of sites here https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt13:26
Havenstanceshows some vulnerable, some not vulnerable and some not using SSL13:27
Havenstanceincase you get bombarded with questions about this over your office coffee pot this morning too13:27
=== Klaudioh_ is now known as Klaudioh
rick_h_party party here come pycon!16:19
jrwrenyay!16:19
cmaloneyWoo woo16:35
greg-ghttps://blog.wikimedia.org/2014/04/10/wikimedias-response-to-the-heartbleed-security-vulnerability/17:05
brouschhttp://pyjvm.org/17:15
jrwrendifferent from jython?17:15
jrwrenOH GOD!17:15
jrwrenbrousch: why?!?!   why!!?!?17:16
brouschI don't know, but I wanted to share the wonder with you all17:17
brouschjython on pyjvm would be awesome17:18
jrwrenpyjvm on jython on pyjvm17:22
brouschCan we run pyjvm on pypy?17:23
jrwrenprobably17:30
mrgoodcathahahahahhaa20:36
mrgoodcati wonder what posessed them to make that20:36
jrwrenpython + json + performance => terrible terrible terrible21:10
rick_h_jrwren: there's json libs that use c-helpers to go faster21:26
rick_h_actually thought the built in json did now :/21:26
cmaloneylo21:28
jrwrenrick_h_: they suck.21:28
jrwrenits like whoever wrote json and simplejson weren't python programmers and weren't C or Java programmers either.21:28
jrwrenI'm pretty sure with a minor incision, I can make it much faster for my meniacle use case.21:29
Havenstance_...22:42
Havenstance_so I get home, old lady packed up the house, she gone...22:43
gamerchick02whoa really? :(23:01
jrwreni got simplejson to do what I want. it ain't pretty.23:44

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!