/srv/irclogs.ubuntu.com/2014/11/14/#ubuntu-us-mi.txt

mrgoodcative never used code.google.com before but i think it says a lot that the Go project is moving to github13:10
mrgoodcatmaybe not, but its just funny that a google sponsored project would move away from google hosting13:11
rick_h_morning13:24
rick_h_google's had a lot of stuff on github for a while13:25
rick_h_I think there's some angular stuff, android stuff,13:25
rick_h_https://github.com/google lol 16 pages of projects13:25
mrgoodcatlots of android13:25
rick_h_ok, can't +1 that enough https://twitter.com/kirtan/status/532730437177581568/photo/113:27
cmaloneyGood morning14:21
cmaloneymrgoodcat: Google's been trying to offload Google Code for a while.14:21
* cmaloney is listening to Kalabi - Slow Boat to Nowhere14:22
cmaloneyBah, hasn't caught up14:22
cmaloneyApparently the album of the morning is Public Image Limited's Acid Drops.14:23
mrgoodcatjust trying to discontinue another product i guess14:47
mrgoodcatat least this time you can see it coming a long way off14:47
cmaloneyWatching rick_h_ rock the Juju Gui15:20
rick_h_woot rock rock rock15:54
cmaloneyWell now I can't say I didn't participate in UOS. ;)15:55
dzhoheh15:57
dzhoso, is that happening now? ;-)15:57
rick_h_lol16:00
cmaloneyUOS is happening now16:00
rick_h_https://plus.google.com/116120911388966791792/posts/6YDBe3zwEih16:00
rick_h_just wrapped up16:00
cmaloneyI think it's the last day iirc16:00
rick_h_please +1 and reshare and allt hat16:00
rick_h_yea, friday friday16:00
mrgoodcatjust learned chase bank's passwords are case insensitive16:05
mrgoodcatcahse--16:05
mrgoodcatchase-- even16:05
cmaloneymrgoodcat: Oh that's handy16:06
greg-gare they still limited to 12 or something characters?16:07
mrgoodcatidk but probably16:07
mrgoodcati don't use chase16:07
mrgoodcathuntington is limited to 12 or less, no special chars16:07
mrgoodcatits like pls hack my bank16:07
mrgoodcati use simple now. full unicode password support ftw16:08
cmaloneyI don't understand that at all16:08
cmaloneyStop parsing my password and just hash kthxbai.16:08
mrgoodcatyea thats all simple does i think16:09
mrgoodcatno min/max length that i know of16:09
mrgoodcatactually the advertised no max length when i set mine up16:09
greg-gI'm fine with reasonable minimums (like 6 or 8 or so)16:11
cmaloneyI'm fine with them parsing the password client-side and saying things like "that password is your cat's name. Seriously don't use that"16:12
cmaloneybut rejecting it once it hits the server == bad.16:12
_stink_CHASE-- and chase-- and chASe--16:13
cmaloneyunless they're decrypting the password16:13
cmaloney_stink_: hahahahaha16:13
mrgoodcat"We'll grade your passphrase strength and require at least a C to pass"16:16
mrgoodcatlooks like client side16:16
mrgoodcatits doing it as i type16:16
cmaloneyYeah, that I don't mind in the slightest16:17
mrgoodcatno max length it looks like16:17
cmaloney++16:17
greg-gI forget who it was, but some bank just truncated after 12 characters and hashed/whatever that16:21
greg-gso, 123456789012A and 123456789012B were the same to them16:21
greg-gthought it was Chase, but /me shrugs16:21
cmaloneygreg-g: Seriouslyt16:22
cmaloney?16:22
greg-gyeppers16:23
cmaloneySadly I'm sure the reasoning was because someone read that passwords 8-12 characters long were secure and someone else didn't want to waste the space on the drives for the extra characters. ;)16:23
greg-gcleartext ftw!16:23
cmaloney(Even though the results were likely salted / hashed, or encrypted)16:24
greg-gmost likely, PCI DSS and all that16:25
greg-gbut seriously, not sure how "truncate after 12 chars, oh, and don't tell the user" is PCI DSS compliant16:25
cmaloneyThe results are hashed / encrypted16:26
cmaloneyso [x]16:26
* greg-g nods16:26
cmaloneyThat's why I have to laugh at some of the compliance audits16:26
cmaloneySometimes they codify stupid behavior16:26
greg-gI'm glad I know Zero about PCI DSS other than the 6 letters, I easily forget what they stand for even :)16:26
cmaloneyPeople Can Infer Dumb System Specs?16:27
greg-g:)16:27
cmaloneys/INfer/ Implement/16:27
greg-gsomethign like that16:27
rick_h_greg-g: that was windows at one time16:28
cmaloneyOh yeah, Windows XOR passwords. :)16:28
cmaloneyThat was Windows 95-era, iirc16:28
cmaloneyrick_h_: I think I found your next computer: http://www.rave.com/products/xeon-21-tri-screen/16:32
cmaloneyUnfortunately it has a trackpad though16:33
rick_h_cmaloney: hah, I'm trying to make https://play.google.com/store/devices/details?id=nexus_9_keyboard_folio_black my next travel computer but it's still coming soon16:33
cmaloneyresponsive mechanical keyboard16:33
jrwrenwindows used xor passwords?16:33
cmaloneyI don't think that means what you think it means16:33
rick_h_cmaloney: heh, yea only for travel16:34
mrgoodcatmost banks use the same software for their online banking16:34
mrgoodcatit was made by a 3rd party16:34
rick_h_I'm not giving up my kenisis, 4k, standing desk any time soon16:34
mrgoodcatand only supported up to 12 characters16:34
cmaloneyjrwren: Yeah, there was a pretty simple password-cracker for Windows iirc.16:34
mrgoodcatcan't rmbr what company made it16:34
greg-gCDC?16:35
greg-g:)16:35
greg-goh, wait, I was mixing cmaloney and mrgoodcat :)16:35
cmaloneyhar har16:35
greg-g(CDC == Cult of the Dead Cow, for those that didn't get the reference)16:35
jrwrencmaloney: it wasn't just ntlmv1?16:35
cmaloneyjrwren: My memory and Google-fu are failing me at the moment16:36
cmaloneyhttp://insecure.org/sploits/windoze.sharepasswords.html <- This is the only thing I'm noticing ATM16:36
cmaloneyI think the screensaver password was XOR as well16:37
cmaloneyMaybe that's what I'm conflating16:37
jrwrenmaybe old lanman compat, so not even ntlm16:37
cmaloneyYeah, nothing recent16:37
cmaloneyThough there was a way to reset the admin PW on a Windows machine using a Linux / NTFS disk16:37
cmaloneyRemember using that on Chrysler machines to get access to the admin accounts16:38
cmaloneyBut that's not the fault of Windows, rather the fault of having physical access.16:38
jrwrencmaloney: i think that still works.16:38
jrwrencmaloney: yeah, can definitely do that with linux too.16:38
mrgoodcatyea you can do that on any of the 3 major OSs16:39
mrgoodcati've done it on my own linux machine actually16:40
mrgoodcatbut my encrypted homedir was toasted16:40
cmaloneyouch16:40
mrgoodcatits fine i back up16:40
cmaloney http://www.jonobacon.org/2014/11/14/ubuntu-governance-reboot/19:12
cmaloneySo far this morning my Squeezebox has been picking out great albums at random19:18
cmaloneyThough I had to tell it that I didn't want to listen to live Pigface this morning19:18
akellinghttp://depressedalien.com/Large/253.png21:00
cmaloneyhttp://www.metalinjection.net/av/mike-portnoys-contribution-to-the-new-haken-ep-is-just-astounding21:42
cmaloneyApparently the band had a competition to figure out what Mike Portnoy's contribution was21:42
cmaloneyand someone guessed almost, but not quite right21:42
cmaloneyakelling: hah. :)21:43
cmaloneyI'm about 2 seconds away from enabling a pep8 git hook that will reject any commit that fails pep822:27
mrgoodcatlol22:27
mrgoodcatat work?22:27
mrgoodcatcould probably add it to the CI tests pretty easily22:28
mrgoodcatbuild:failed "pep8 fail"22:28
cmaloneyyeah22:29
cmaloneyalso: "log message too long"22:29
mrgoodcatnot even necessarily a bad idea as long as people would fix it and recommit22:29
cmaloneyalso: commented code detected22:29
mrgoodcatcommented code is not always bad22:30
mrgoodcatmostly yes22:30
mrgoodcatnot but always22:30
mrgoodcatcame across a comment at work the other day that was basicall "# don't even try to fix this function if it breaks. just rewrite it"22:30
* cmaloney is listening to Motorpsycho - Don't Wait22:31
cmaloneymrgoodcat: Was that one you left in there?22:31
mrgoodcatnot that i remember?22:31
mrgoodcatdidn't git blame22:31
mrgoodcatprobably22:32
mrgoodcatlol22:32
cmaloneySounds like something I'd leave in there22:32
mrgoodcatit is something i merged at the very least though22:32
mrgoodcatsince its in a part of the code that is not older than my employment22:32
derekvso, here's a nonsense question, if you have a 1to1 relation, what language do you normally use to describe the situation where, the entity on one side is meaningless without the other (maybe, ownership?), vs both sides exist independently of each other23:44
mrgoodcatenglish23:44
mrgoodcat:)23:45
mrgoodcatlike user has one phone but phone is useless without user?23:45
mrgoodcati'd say ownership23:46
derekvfound this http://stackoverflow.com/questions/762937/whats-the-difference-between-identifying-and-non-identifying-relationships23:46
derekvmrgoodcat: yes23:46
mrgoodcatwhy are they in separate tables?23:47
mrgoodcatif B is meaningless without A and its 1-1 couldn't B just be in table A?23:47
derekvin a relational db, you'd probably put them in the same table23:47
derekvbut i'm playing with the idea of a data model to describe data models =P23:48
derekvand was trying to decide if there was more than one type of 1to1 relationship23:48

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!