Myrtti | popey: http://www.aliexpress.com/item/New-2014-300Mbps-WT3020A-Multiprotocol-Portable-Mini-WIFI-Router-with-USB-data-line-Wireless-Router-wi/1691403728.html | 06:51 |
---|---|---|
=== zmoylan-1i is now known as zmoylan-pi | ||
foobarry | what do i need to do re: poodle? | 08:34 |
diplo | poodletest.com | 08:35 |
diplo | If it fails, update your browser | 08:35 |
diplo | Is basically what I've read | 08:35 |
foobarry | and the server side? | 08:35 |
diplo | ( I could be wrong, but seems the case ) | 08:35 |
diplo | From what I've read it seems to be a browser issue with the implementation ? | 08:36 |
Myrtti | go on your firefox to about:config | 08:40 |
Myrtti | search for security.tls.version.min | 08:40 |
Myrtti | set to 1 | 08:40 |
Myrtti | if using Chrome/Chromium, update it to latest, and/or start it with --ssl-version-min=tls1 | 08:41 |
foobarry | thanks all | 08:42 |
Myrtti | "As a server operator, it is possible to stop this attack by disabling SSLv3, or by disabling CBC-mode ciphers in SSLv3. However, the compatibility impact of this is unclear. Certainly, disabling SSLv3 completely is likely to break IE6. Some sites will be happy doing that, some will not." | 08:48 |
JamesTait | Good morning all; happy Information Overload Day! :-D | 08:48 |
foobarry | is there a nifty test i can run on the server? e.g. a php file copy to it? | 08:49 |
foobarry | SSLProtocol all -SSLv2 | 08:50 |
foobarry | hmm | 08:50 |
directhex | sorry, i can't take this ssl vuln seriously | 08:52 |
directhex | where's the logo? | 08:52 |
diplo | hah directhex, I've seen that mentioned by quite a few people :D | 08:53 |
shauno | I saw someone suggest "SSLappening", if that helps | 08:53 |
foobarry | anyone running centos here? | 08:55 |
directhex | YES! poodletest.com | 08:57 |
diplo | Lots of servers yes foobarry | 08:57 |
diplo | From 4 up to 6.5 | 08:58 |
diplo | even have a v8 at one site :/ | 08:58 |
brobostigon | morning boys and girls. | 09:08 |
foobarry | diplo: | 09:09 |
zmoylan-pi | and unafilliated | 09:09 |
foobarry | bash -c "f() { x() { _;}; x() { _;} <<a; }" 2>/dev/null || echo vulnerable | 09:09 |
foobarry | can u try that pls | 09:09 |
foobarry | fails on centos for me | 09:17 |
davmor2 | JamesTait: we work with open source everyday is information overload day :P | 09:17 |
zmoylan-pi | then stop reading update logs davmor2 :-) | 09:21 |
diplo | foobarry, bash -c "f() { x() { _;}; x() { _;} <<a; }" 2>/dev/null || echo vulnerable | 09:21 |
diplo | Segmentation fault | 09:21 |
diplo | vulnerable | 09:21 |
foobarry | yeah, i get that too | 09:23 |
directhex | centos only security-supports the latest point release in a series | 09:31 |
directhex | 6.5, 5.11, etc | 09:31 |
awilkins | Anyone know if Estonia's ID card scheme has key escrow? | 09:42 |
davmor2 | awilkins: I'm assuming it will say on the gov site somewhere maybe if you are lucky :) | 09:52 |
=== drunk-admin is now known as Monotoko | ||
davmor2 | best hotair ballon Ever http://www.darthvaderballoon.be/ | 10:31 |
foobarry | the SNP are keen on fish. first alex salmon, now nicola sturgeon | 10:35 |
davmor2 | foobarry: that sound a little too fishy to me, I think the fish people might be taking over the Scots, time to invade it's for their own good | 10:38 |
awilkins | Sighted off the coast near the experimental submarine pens in Scotland : http://i866.photobucket.com/albums/ab227/sabredelamar/vlcsnap-211824.png | 10:41 |
zmoylan-pi | anything can happen in the next half hour..... | 10:43 |
* awilkins turns off the looped bongo drums sample | 10:44 | |
=== Lcawte|Away is now known as Lcawte | ||
Laney | bongo bongo drums | 11:10 |
davmor2 | Laney: awilkins: https://www.youtube.com/watch?v=SrlhLaNClgw | 11:21 |
=== Lcawte is now known as Lcawte|Away | ||
=== Guest73218 is now known as NET||abuse | ||
=== Lcawte|Away is now known as Lcawte | ||
=== Lcawte is now known as Lcawte|Away | ||
Myrtti | oh man | 16:16 |
Myrtti | I'm on Telegraph. | 16:16 |
Myrtti | Kinda. | 16:16 |
Myrtti | popey: http://np.reddit.com/r/privacy/comments/2j9caq/anonabox_tor_router_box_is_false_representation/ | 16:38 |
MartijnVdS | http://www.google.com/nexus/6/ | 16:51 |
Myrtti | what surprises me is that even Nexus 4 is apparently getting Lollipop | 16:53 |
Azelphur | NO. I BOUGHT THE NEXUS 5. STOP TRYING TO TAKE MY MONEY :< | 16:53 |
=== alan_g is now known as alan_g|EOD | ||
dwatkins | is it my imagination, or did someone mention a site called "pimp my spice rack" a while ago? | 17:29 |
dwatkins | can't find any mention in my logs | 17:29 |
Myrtti | aw, the domain is gone | 17:30 |
Myrtti | and the site. | 17:30 |
shauno | I gotta say, the irish post office amaze me. after dealing with parcel farce, these guys seem super-human | 18:11 |
shauno | I just got a package addressed to "shaun oneil, 2A, cork". no street name, wrong city. and they found me | 18:11 |
jdca | Popey: Will the "Ubuntu phone" be released in december ? | 18:25 |
popey | jdca: thats up to the manufacturer | 18:32 |
popey | we don't dictate the production runs | 18:32 |
popey | we "just" make the software | 18:32 |
jdca | Popey: allright, thanks :) another thing. Will we be able to use all the gnu goodies in the terminal on ubuntu touch? | 18:34 |
popey | jdca: dunno what you mean by "gnu goodies" but are you talking about coreutils? that kind of thing? if so, yes | 18:57 |
foobarry | shauno: would be more impressed if it was addressed: shauno, #ubuntu-uk | 19:01 |
foobarry | but impressive nonetheless | 19:02 |
jdca | Popey: yeah. Awesome. Thanks for the info :) | 19:03 |
=== Lcawte is now known as Lcawte|Away |
Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!