[01:06] <wrst> minasota: yeah not really concerned with the privacy stuff but a good looking open type machine would be nice
[01:06] <wrst> for that price I would just buy a macbook
[02:16] <|Ubik|> uh oh...
[02:16] <|Ubik|> Anyone else getting errors about debian testing suppositories no longer being signed?
[02:17] <|Ubik|> E: Splitting of file /var/lib/apt/lists/ftp.us.debian.org_debian_dists_testing_InRelease failed as it doesn't contain all expected parts 0 1 0
[02:17] <|Ubik|> W: The repository 'http://ftp.us.debian.org/debian testing InRelease' provides only weak security information.
[02:17] <|Ubik|> N: Data from such a repository can't be authenticated and is therefore potentially dangerous to use.
[02:17] <|Ubik|> N: See apt-secure(8) manpage for repository creation and user configuration details.
[02:17] <|Ubik|> W: GPG error: http://shell.ninthgate.se/packages/debian wheezy Release: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 0B38CE01521D8275
[02:17] <|Ubik|> E: The repository 'http://shell.ninthgate.se/packages/debian wheezy Release' is no longer signed.
[02:17] <|Ubik|> N: Updating from such a repository can't be done securely, and is therefore disabled by default.
[02:17] <|Ubik|> N: See apt-secure(8) manpage for repository creation and user configuration details.
[02:17] <|Ubik|> A bit concerning...
[02:29] <cyberanger> Nope, not at the moment
[02:29] <cyberanger> let me update and see if that's changed since the AM
[03:35] <Omnifrog_> holy shit!
[03:35] <Omnifrog_> TALKING!
[03:36] <Unit193> Pasting, really.
[03:38] <Unit193> Also yes I'd like to note that I had no problems with stretch earlier.
[03:50] <cyberanger> |Ubik|: http://vwakviie2ienjx6t.onion/debian/ isn't giving me issues right now
[03:50] <cyberanger> sid & experimental
[03:54] <|Ubik|> cyberanger: Interesting. May try it at the office tomorrow and see.
[03:54] <|Ubik|> We ditched Charter up there.
[03:54] <cyberanger> Really? wow
[03:54] <|Ubik|> Yeah.
[03:54] <|Ubik|> You'd be surprised what we have, lol
[03:54] <cyberanger> AT&T or Windstream?
[03:54] <cyberanger> |Ubik|: dpkg --get-selections | grep apt-transport
[03:55] <|Ubik|> apt-transport-https    install
[03:56] <cyberanger> |Ubik|: You have apt-transport-https, give a try using https://mirrors.kernel.org/debian/
[03:56] <|Ubik|> lemme try that
[03:56] <cyberanger> (and I'd add apt-transport-tor for a rainy day at least)
[03:57] <|Ubik|> Which could be Friday.
[03:57] <|Ubik|> Oh, and, Uverse is what we have now
[03:57] <cyberanger> AT&T, wow
[03:58] <|Ubik|> however, it's Uverse over fiber
[03:58] <|Ubik|> yeah, that was a circus to get installed
[03:58] <cyberanger> If that gives you an issue (it shouldn't) also try https://cloudfront.debian.net/debian/
[03:58] <|Ubik|> There's fiber to that place in the front of the building (I think that was there when you were), then they ran fiber back to our office.
[03:59] <|Ubik|> It's still updating the sources, so we shall see.
[03:59] <|Ubik|> Only problems we ran into... it took 4 days to get it working, someone built the order to be delivered over CAT5 from the front to us, which is why the fiber port never activated.
[03:59] <|Ubik|> They had to do a whole new order to fix it (can't just login to the Ciena and change it???), new account # and all.
[04:00] <cyberanger> Wow, somebody was special on that one.
[04:00] <|Ubik|> Then today all our port 80 traffic gets hijacked, about 30 minutes on the phone reveals we've been "suspended" because the bill (which we have yet to receive, because they sent it to the wrong place) hadn't been paid. I switched port 80 to go over the VPN until tha tis ironed out.
[04:00] <|Ubik|> Then we track down said bill
[04:01] <|Ubik|> I have two welcome letters, a password reset, two bills, and two disconnect notices.
[04:01] <|Ubik|> Evidently even though the first install never worked, and the modem supposedly ended up in the dumpster (because there's no way to fix it if it gets the "wrong" IP), they left that account active and are still billing us for it.
[04:01] <|Ubik|> I should have known when I saw port 5 on the Ciena (which WAS ours) is empty and we're on #6, lol
[04:01] <|Ubik|> Can we say...gross incompetence?
[04:02] <cyberanger> I thought that was AT&T's company motto
[04:02] <|Ubik|> Now, the service... the modem sucks, the state table dies at 2500 connections, and if you turn off NAT, SPI, etc. it STILL tracks everything and has issues.
[04:02] <|Ubik|> Aside from that, it actually works okay
[04:02] <|Ubik|> we can get faster upload than Charter, we're on 50/10 right now, but could go up to gigabit I think
[04:02] <cyberanger> apt-get update still updating?
[04:02] <|Ubik|> yeah
[04:02] <|Ubik|> that has to be the slowest mirror ever
[04:02] <cyberanger> Hrm, seems slow
[04:02] <|Ubik|> 150kB/sec
[04:03] <cyberanger> Oh, that'd be about right then (and I run it so often the pdiff's make it faster too)
[04:04] <|Ubik|> http://pastebin.com/KxunMu1G
[04:04] <|Ubik|> that's what I ended up with
[04:04] <|Ubik|> something must be pooched somewhere
[04:04] <|Ubik|> or the feds are trying to mess with me
[04:05] <cyberanger> What is your /etc/apt/sources.list ?
[04:06] <cyberanger> Oh, it's only giving you an error on testing/updates
[04:06] <|Ubik|> yeah
[04:08] <|Ubik|> http://pastebin.com/AXPs3R9q
[04:08] <|Ubik|> blah, they make you do a captcha now, I'm guessing to "encourage" you to take a pro account
[04:09] <cyberanger> not the rest of it, wondering if they phased that out...
[04:12] <|Ubik|> http://pastebin.com/pfPLbrec
[04:12] <|Ubik|> that was the original problem
[04:13] <cyberanger> Is it supposed to be testing/updates and not testing-updates?
[04:16] <cyberanger> |Ubik|: give it a try as testing-updates
[04:20] <|Ubik|> hmmm
[04:20] <|Ubik|> good question
[04:21] <|Ubik|> actually
[04:21] <|Ubik|> it's in my sources.list both ways
[04:21] <|Ubik|> or wait no, two different hosts
[04:22] <|Ubik|> although on our icecast server (which I just redeployed with testing yesterday), it's using testing/updates
[04:23]  * Unit193 perks up.
[04:23] <Unit193> Hello, icecast2.
[04:24] <|Ubik|> yeah
[04:24] <|Ubik|> had to manhandle it to get 2.4.0kh
[04:25] <cyberanger> Unit193: is something going on with testing/updates
[04:25] <cyberanger> being phased out maybe?
[04:26] <|Ubik|> Get:1 http://mirrors.digitalocean.com/debian testing InRelease [251 kB]
[04:26] <|Ubik|> Get:2 http://mirrors.digitalocean.com/debian testing-updates InRelease [124 kB]
[04:26] <|Ubik|> Hit:3 http://security.debian.org testing/updates InRelease
[04:26] <|Ubik|> Hit:4 http://www.deb-multimedia.org testing InRelease
[04:26] <|Ubik|> Fetched 374 kB in 2s (159 kB/s)
[04:26] <|Ubik|> Reading package lists... Done
[04:26] <Unit193> Bleh, kh. :P  And only one I knew for that was -proposed-updates or something.
[04:26] <|Ubik|> That works, FWIW
[04:26] <cyberanger> Hrm
[04:27] <Unit193> http://paste.openstack.org/show/577205
[04:27] <|Ubik|> Unit193: Yeah, the -kh builds allow the web-based players to work from some stations, I think was the thing.
[04:27] <cyberanger> Weird, mirrors.kernel.org is very close to the root mirror, so idk
[04:28] <Unit193> |Ubik|: I'd wonder if the newer normal builds work, but I dunno.  At least you have a good reason and not just "it's cooler" or something! :P
[04:28]  * Unit193 miiiight be biased.
[04:30] <|Ubik|> lol
[04:30] <|Ubik|> I think mirrors.kernel.org doesn't carry testing/updates (whereas security.debian.org does)
[04:30] <Unit193> (I'm not really, I use what works.  Including streaming in mp3. >_> )
[04:30] <|Ubik|> and the files at http://security.debian.org/dists/testing/updates/ were last updated today..my guess is they pooched something
[04:30] <Unit193> That's some freeze trick to get it in without having to go through the migration, right?
[04:31] <cyberanger> That's a good point, we're getting ready for a new stable aren't we?
[04:32] <|Ubik|> probably
[04:32] <|Ubik|> actually
[04:33] <Unit193> cyberanger: No, I ignore stable. :P
[04:33] <Unit193> ...Unless I'm told not to and have a pre-offer of sponsorship.
[04:34] <cyberanger> Unit193: Well, same here, sid+experimental
[04:34] <cyberanger> Okay, got this from #debian-next on oftc
[04:35] <cyberanger> somiaj | oh wait, testing/updates. That can't be mroe than a place holder and I would jsut comment out the sources
[04:35] <Unit193> cyberanger: That migration time is pretty handy to weed out bad updates, though.
[04:35] <cyberanger> Oh yeah
[04:35] <cyberanger> I get why they do it
[04:36] <Unit193> No I mean as a user.
[04:37] <|Ubik|> Something must of got pooched somewhere, clearing /var/lib/apt/lists/* and then apt-get update seemed to fix that problem.
[04:38] <cyberanger> Including the 404?
[04:38] <|Ubik|> seems to, I'm back to my original sources.list and it works
[04:38] <|Ubik|> gave me an error about appstream, ran it again, and no errors
[04:38] <cyberanger> Huh
[04:39] <Unit193> Oh bleh, purge appstream. :P
[04:42] <Unit193> cyberanger: Also could just try using httpredir or deb.debian.org.
[04:42] <|Ubik|> might just do that
[04:43] <|Ubik|> cyberanger: so no https for security.debian.org ?
[04:44] <Unit193> You already verify using gpg, there's simply no need for https.
[04:44] <cyberanger> Unit193: I used to prefer httpredir, and I have some commented out servers (including httpredir) as a quick backup. Favor http://vwakviie2ienjx6t.onion/debian/ now.
[04:45] <Unit193> cyberanger: Of course, didn't mean for you.  Generally have a very specific setup. :)
[04:45] <cyberanger> and I disagree on not needing https, I think gpg and https are fixing two different security threats.
[04:46] <Unit193> (FWIW, Ubuntu version of that is  deb mirror://mirrors.ubuntu.com/mirrors.txt xenial main restricted universe multiverse)
[04:46] <cyberanger> |Ubik|: nope, sadly
[04:46] <|Ubik|> Wow. Well, if *you* don't have a solution to that one, then I don't feel so bad leaving it http... lol
[04:46] <Unit193> cyberanger: Oh?  Gpg verifies that it's coming from Debian.
[04:47] <|Ubik|> brb
[04:51] <cyberanger> Right, GPG verifies against the debian archive key that signed the release. HTTPS prevents MITM & evasedropping of what am I fetching too.
[04:51] <Unit193> MITM shouldn't matter, worst it does it make you re-try.  But ACK on the second.
[04:52] <cyberanger> GPG doesn't stop a MITM, it makes sure packages weren't modified by a MITM  or prevents installation.
[04:52] <Unit193> Right.
[04:53] <cyberanger> if GPG had some kind of bug and one could use it towards an exploit, I'd like the extra layer with openssl.
[04:56] <Unit193> Or, gnutls in the case of apt-transport-https. ;)
[04:59] <cyberanger> Right.
[05:00] <cyberanger> Never hurts to layer either
[05:44] <|Ubik|> Send it all via carrier pigeon for extra bonus.
[05:45] <cyberanger> lol
[05:45] <cyberanger> I'm not against that, it'd be faster than my connection.
[05:51]  * cyberanger needs to find a way to run tor for initramfs
[15:39] <zphreaker> are you guys w. tn or e. tn?
[15:52] <cyberanger> zphreaker: Depends on which one of us your asking, and don't forget Middle TN too.
[15:52] <cyberanger> (Metro Chattanooga for me)
[16:45] <zphreaker> I've thought of moving to Chattanooga.  How's the gigabit fiber to the house?
[16:46] <zphreaker> What are some IRC names of some of your W. TN people?
[16:53] <cyberanger> I am just outside the EPB market, what I've used at the Chattanooga Library or the Choo Choo hotel, awesome.
[16:53] <cyberanger> I'll let them speak up, main one I'm thinking of is offline atm
[17:23] <zphreaker> that's cool.  Wondering if I know any W. TN folks.. been using *NIX since '91 and started in BBS scene back in '83..
[17:25] <zphreaker> My wife and I have been considering Chattanooga.  What are housing prices like? Would be looking for something like 3500 - 4500 sq ft and neighbors house not right on top of me.
[17:25] <zphreaker> and gigafiber :)
[17:26] <cyberanger> Doable, can't speak on price too much as I rent
[21:06] <minasota> Tullahoma and Chattanooga (TUB and EPB) offer gigabit. Only 7 municipalities offer that speed, 2 of which are in Middle Tennessee
[21:07]  * minasota considers Chat middle tn...
[21:10] <minasota> Minus Clarksville