[00:46] hmm anyone know what do do here? [00:46] https://github.com/matrix-org/synapse/blob/master/README.rst#synapse-installation [00:46] I get to the part that says "To set up your homeserver, run (in your virtualenv, as before):" [00:46] and I am lost [00:52] what are you lost on? Squirm [00:52] squish102: [00:54] how to run the commands? [00:54] you can just paste it. It is 1 python command [00:54] "\" is used for multi-line pastes [00:54] it says in your virtualenv though [00:55] is your virtualenv activated? [00:56] paste your user@something info to the left of the command-line [00:57] hi kulelu88 squish102 [00:57] i think it is working... [00:57] ty squish102 [00:58] Hello oom. how are you? [00:58] squish102: it should already be active, cause you ran the /bin/activate on it [00:58] im ok ty, hows things there [00:58] kilos, i'll try again after payday [00:58] im fekking exhausted. [00:59] kulelu88 you shoulda been asleep long ago [00:59] why you up so late/early [00:59] work Kilos . think it is time for me to resign [00:59] wow [00:59] night shift [01:00] kak shift. you out of hospital oom? [01:00] kulelu88: it worked thanks [01:00] shot squish102 [01:00] yes ty lad im home, was only in hospital for 3 days, [01:00] back in SA or parking with the Aussies? [01:01] still in aus with my girls [01:02] till end of november [01:02] then the long trip home [01:02] ai! [01:02] you made us scared oom, getting sick and shit [01:04] sorry lad, it was a surprise for me as well. strange to have a heart attack when only walking and at home i could run and catch sheep and do farm work without hassles [01:04] must be the aussie people oom. hows the life there? Are you allowed to live there beyond November? [01:07] only a 3 month visa. the people are ok, have some habits that are strange to us, but basically normal peeps [01:07] much more expensive than SA? [01:08] "no worries mate, no worries" :D [01:08] when you directly convert costs things seem very expensive to us but then they earn more [01:09] like a 10mm socket cost $6.50 which is R65 [01:09] that seems expensive [01:10] yes i think its between R20 and R30 [01:10] oom checking tool prices <3 hahhaa [01:10] i have to buy as we can afford so i can repair a toploader washing machine for the girls [01:11] laundromat costs about $50 a week [01:11] R20 is cheap. it is about $3 in US [01:11] you have more than 1 daughter oom? [01:12] no one and the mother of course [01:12] hehe [01:12] we are almost like teenagers [01:12] like 30 years apart never happened [01:13] hahahaha. [01:14] squish102 where are you now lad? [01:15] i live in a little town in the US [01:15] ah [01:15] close to a largish city. Charlotte, north carolina [01:16] squish102 is now an American Boer. Hy bly op die "Ranch" [01:16] :D [01:16] hehe [01:16] https://goo.gl/maps/pGnCgPhfR9E2 [01:16] My house [01:17] nope, small property [01:17] cool [01:18] ive been here for 15 years, so pretty american [01:18] only visit sa every couple years now [01:18] your kids born there? Squirm [01:18] wow [01:19] squish102: [01:19] yes, they american [01:19] squirm is gonna murder me :D accidentally pinging the owe [01:19] yes, tab sucks with the name so close [01:20] time to become zquish [01:20] btw Kilos, aussie also have open house plots, or is it all walls like sa? === squish102 is now known as zquish012 [01:21] LOL I was kidding, but thank you! [01:21] was the strangest thing to drive into a residentual area and no walls. they actually not allowed, low open fences only [01:22] Squirm: will thank me :) [01:22] zquish012: in your state? I've heard of some places in America being as dangerous as Hillbrow [01:22] all fencing like in our old days but many walled places as well [01:24] kulelu88: i'm sure there are some dangerous places, none that i know of close to me [01:24] kulelu88 i don't bother to lock my cars, or my house for that matter [01:24] NC must be very safe though [01:24] no buglar bars, or alarm system [01:24] Republican and religious right? [01:24] although i don't leave stuff in my car [01:25] i think democrat and religious [01:25] aah, well politics doesn't matter. they must be old-school friendly kinda people [01:26] only think i left in my car was my car keys because i hoped someone would steel it and i could claim insurance. insurance was higher than i could sell car [01:26] after a couple months, i ended up selling my car :) [01:27] no the real reason i left the keys in the car, was i had another car in the garage, so i had to move my other car every day. was easier to leave keys in the car :) [01:27] i'm also not in the city but about 50 k's from the city [01:28] you work remotely? [01:28] hahahaha [01:29] sometimes.. but work is about 30k's away [01:29] not far, about 40 min drive [01:30] you must be driving on roads with cows and sheep :D [01:30] which is nothing, my next job, if i get it, is an hour and 15 minutes away :( [01:31] why do you live in the middle of nowhere? [01:31] wifes dumb idea. house was cheap and she liked the rural small town feel [01:32] she must be regretting it now :D [01:33] she still loves it. her car is 4 years old and has about 120000 km on it [01:33] 0.o [01:33] and she doesn't work [01:33] that is shopping miles [01:33] lucky petrol is so cheap [01:34] very rare to hear a wife not working in the US. you must be raking in the moola [01:34] jys nou n larnie [01:35] i would say more than half my friends don't have working wifes... it is all about the children and raising them correctly [01:35] and i couldn't afford a maid [01:35] and i miss my maids and gardners :) [01:35] not plural [01:35] now you are the gardener ;) [01:36] i'm the gardner and my wife is the maid [01:36] how is the weather there throughout the year? [01:37] where i am, it is pretty good. we have seasons, so summer is hot, about 28-40 and winter is cold, about -5 to 10 [01:38] -5 ... rough [01:38] but houses all have aircon and heat, so your house is always at the temp you want it [01:38] i keep house at about 22-24, somewhere around there [01:39] * zquish012 having to convert from farenheight [01:39] coldest we get is -12, but no wind (ever) [01:40] except when a hurricane comes through, like yesterday [01:41] ok so now I have a http://matrix.org/ server running.... what to do with it... hmmmmm [01:43] that reminds me... I need to ask in this # when people are here for good managment tools of debian [01:44] i plan to deploy about 13000 raspberry PI's into stores, how am i going to manage them :( [01:44] wow [01:45] one in each store. i have to patch them and send app updates and any config changes. i need tools [01:46] are there so many stores there [01:46] i can see security team saying something like "switch all ssh ports to port 32453 by tomorrow" [01:46] yes, my company has that many [01:46] wow [01:47] so when you say, let me replace the thin terminals with new ones, and the unit price is $400 for a wyse thin terminal [01:48] and then i say i need $5 mil... they go.. um no [01:49] so we go with a cheap $60 raspberry PI. they said yes but now i am stuck with how to manage them [01:51] anyway, i gtg, it is getting late here now [01:52] look here [01:52] https://www.google.com.au/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&ved=0ahUKEwjMv96BkM_PAhXCnZQKHRFyCVIQFggqMAA&url=https%3A%2F%2Fwww.raspberrypi.org%2Fblog%2Fraspi-ltsp-is-now-pinet%2F&usg=AFQjCNFir6l2PZf0Zp2LX6GBTOLS2GtFoA [01:52] might give you an idea [01:55] zquish012 [01:56] Maaz time in charlotte usa [01:56] Kilos: I'm not feeling too well [01:56] ai! [01:59] thanks Kilos, will check it out tomorrow [01:59] Maaz: time 28173 [01:59] zquish012: Sorry... [02:00] Maaz: time charlotte usa [02:00] zquish012: Huh? [02:00] about 10pm, but i have to get kid on school bus tomorrow at 6:20am [02:01] zquish012: somebody once said changing ports is security theatre [06:04] Goeiemore Kilos tyd vir 'n bietjie Afrikaans daar in Oz [06:06] Hoe gaan dit met jou en jou omstandighede rondom die medieserekeninge? [06:27] hmm... [06:29] Maaz tell Langjan Skuus oom. Ek was buite. Of ek het n middag slaapie geniet. As jy nie so haastig was nie kon ons gesels [06:29] Kilos: Got it, I'll tell Langjan on freenode [09:03] Hello all\ [09:20] morning everyone [09:20] hi ra1v3n [09:22] Hello Kilos [09:28] hi inetpro thatgraemeguy and everyone else as well [09:29] wake up za [09:29] lol [09:47] morning :) [09:54] Kilos: i'm awake... i'm awake [09:55] can i go back sleep now :P [09:55] LOL [09:55] ok [11:19] One of the long time opensource and ubuntu contributor, Miles Sharpe (IRC NICK : Kilos) need your help and donations, please read the full story and help him, https://www.gofundme.com/reunionroadblock [18:40] good evening [18:43] ON THE MONEY: Wits SRC’s funding proposal flawed by Stuart Theobald, 10 October 2016, 05:37 http://www.bdlive.co.za/opinion/columnists/2016/10/10/on-the-money-wits-srcs-funding-proposal-flawed [18:43] kulelu88, MaNI: some interesting points there ^^ [18:45] they came up with some bullshit funding model in 2 weeks. politics students at their 'best' [18:45] young naive socialist marxist students publish document that ignores half of reality, in 10 years time they will be sitting in real jobs condemning the exact people they used to be. The joys of youth. [18:48] as I tried to allude to the other day, one of the 'elephants in the room' that everyone is ignoring, is that the most popular degrees are also the ones that don't even necessarily lead to a bright future. [18:49] If we burn all of our remaining resources to churn out a bunch of unemployed bachelor of arts students does that really help anyone? [18:49] it sure as heck doesn't make sense to be funding the next 30,000 marketing students when we need more doctors :D [18:49] Would people be okay if "free education" also came with the clause that the education had to be in something deemed "in demand"? [18:50] fair points [18:50] When I used to write my unisa exams, the exam hall was always full, but I was often literally the only person writing the exam for the computer science subjects [18:50] anyways, that topic is exhausting. [18:50] does anybody know how to generate your own SSL certs? [18:50] but yeah it makes me sad just to talk about this stuff, back to work :p [18:51] you couldn't even copy from your peers MaNI :( [18:51] kulelu88: https://letsencrypt.org/ [18:51] every year it got less [18:51] first year 10 of us [18:51] kulelu88: letsencrypt? Or do you want self signed? [18:51] second year 5 [18:51] final year 2 [18:51] honours, just me [18:52] felt like I was going to get taken away by a death figure at some point :P [18:52] paddatrapper: self-signed for local dev. I want to generate server-certs and client-certs [18:52] MaNI: 2 as in 2 in the venue? [18:52] 2 in the row for comp sci subject [18:53] 300 in the row(s) for economics, hehe [18:53] they usually have multiple subjects in the venue for each day [18:54] joburg venue? MaNI [18:54] germiston [18:55] though I had to do one once in cape town while traveling and it was a similar story [18:55] kulelu88: https://www.linux.com/learn/creating-self-signed-ssl-certificates-apache-linux [18:55] Good work through there [18:56] paddatrapper: you know how to generate client certs? [18:56] kulelu88: sorry that I'm not sure about [19:41] paddatrapper: https://gist.github.com/mtigas/952344 [19:43] kulelu88: thanks [19:45] so fekking hard to find examples like that [20:18] ahoy ZA! === DalekSec_ is now known as DalekSec [22:39] any advice on managing raspberryPI's. like windows sccm. push patches and app updates as well as config changes? [22:40] i don't want to pay microsoft money to manage the PI's [22:49] zq [22:49] zquish012: I answered you yday [22:50] checked that out. pretty neet, problem was that it basically loads the OS from a central server [22:51] you need an agent on the Pi itself? [22:51] and no, Ansible doesn't do that [22:51] with 13000 stores all opening and they all have (i think) 1.5mbit connections, i don't think i have enough bw [22:52] you need to architect a solution [22:52] is it 1 Pi per store? [22:52] yes, one maybe 2 [22:53] and the Pi has access to a 1,5MB connection to the internet? [22:53] one as a think terminal, basically running a web browser, for ppl to apply for jobs [22:53] and one to be used to monitor temps in fridges.. IoT stuff [22:53] 0.o you plan on running a browser via a Pi [22:54] geez, your company could have invested about 40 bucks for decent ARM processors instead [22:54] yes, boot up into chromium and lock it down. public facing [22:54] needs to have wifi, bluetooth and video [22:55] nah man, that's insane. have they bought this stuff already? [22:56] nope, piloting it in a couple stores [22:56] $40 bucks cannot get anything, i don't think [22:56] you need a more powerful board to run chromium at any decent speed on a thin client [22:57] 40 bucks gets you the highest performing Pi [22:57] ya, you mentioned a decent arm processor for 40 bucks [22:57] 40 bucks gets you an entry level android, which is more powerful than a Pi [22:58] we have an android stick too, but doesn't have bluetooth (i don't think) [22:59] Pi seems fine for browsing, not that i have used one for very long [22:59] break down the functionality of what the thin client must do: ? [23:00] and you should start by explaining to your company about botnets101 [23:01] 13,000 Pis would be a good botnet to send DDoS from :D [23:01] 1. browser for job applications. 2. RDP client to hit internal rdp farm to get to websites internal. 3. bluetooth to talk to IoT devices in fridges [23:01] 4. maybe a 3rd to try do triangulation of customers in store [23:02] 5. Possibly also a cash register, if we can compile the C code to work in debian [23:02] 0.o [23:02] but need to be able to patch them and update them. keep the bots out [23:03] not sure how secure debian is with security patches. will have 2 sites whitelisted for public [23:04] Ansible can patch and update without an agent. Salt can do so as well, but it uses an agent. Unless you're not a Python guy, then Puppet, Chef are also options [23:04] is 1) public-facing or to be used internally by the staffers? [23:04] public facing, to 2 whitelisted websites [23:05] pi should be bolted behind monito in vesa slot [23:05] your security policy is a bit flawed then. you'll have an RDP client connected as well. If I pwn just 1 Pi (like literally break in and connect to it directly), I then have access to the entire RDP farm [23:06] my worry with all those, is i need to be able to manage that number. if puppet has a good console to report problems, re-apply patches etc [23:06] the only way to know which is the best is to test them all at a scale going upwards. [23:07] RDP farm requires AD authentication (but no 2FA yet) [23:07] does it have brute-force protection? [23:07] built into AD afaik [23:08] 10 attempts and locked account [23:08] i do that to myself all the time. running scheduled tasks on windows and password changes. bam, lock my account :) [23:09] botnets are a real thing, so the security of your architecture needs to be good [23:09] so start with ansible, salt, puppet or Chef? [23:10] hmmmm, let me check quickly [23:12] http://www.infoworld.com/article/2609482/data-center/data-center-review-puppet-vs-chef-vs-ansible-vs-salt.html [23:13] I'd do an agentless setup first. SSH into a box for updates seems normal for anyone managing a server (or a Pi in this case) [23:15] i leave the networking up to our mpls cloud provider and hope they running the network securly [23:15] ok, will check that out, thanks for the help [23:16] They all have sizeable learning curves too. Good luck though [23:16] it will take the company from running 13000 thin terminals running windows XP with SP2 to the new age [23:17] A Pi can't replace a thin terminal though, you need a bit more power [23:17] they only running rdp on them. they very small and old, think the have 256 meg memory in them [23:19] I can see how I'd quickly grow frustrated with this companies IT policies [23:21] me too, that is why i have to get out [23:22] the grass is probably not greener though [23:22] job market is good, but wife doesnt want to move to different city [23:23] since being purchased, the team has gone from about 20 people to 5 [23:24] about 10 of those, i still have lunch with to keep in contact [23:24] their grass is so much greener [23:24] they lol at me staying :( [23:24] heh??? you want to manage 13,000 stores with a team of 5 0.o [23:24] keep sending me pics of the xbox in cafeteria for when they need a mental break [23:25] no, i need to manage 13000 devices with one person and that is in a different department [23:25] that is a botnet waiting to happen [23:26] you need at least 24 hour log monitoring for so many terminals [23:26] it department in total is about 800 ppl [23:26] how many sysadmins? [23:28] like 3 for storage, 5 for virtualization, 4 for AD/exchange, risk/security has about 14 and a company that monitors qradar logs [23:31] but security team is a bit like https://i.ytimg.com/vi/ycQV62iNSrs/maxresdefault.jpg [23:32] the IoT botnets are really scaring ppl [23:32] probably need laws to make a change to IoT devices [23:33] that is why 13,000 Pis is like "whoa, fun times" [23:33] if my lights are part of a botnet, but they still work... /me don't care [23:33] ^^ that is the issue [23:34] well we 70000 pc's in the stores.. bigger botnet [23:34] Updating a Pi is not so hard, updating those smaller IoT devices is difficult [23:35] because if the IoT device works, ppl not going to update it [23:37] zquish012: they shouldn't. If the device is already on the interwebz, it can be updated by itself [23:39] like my accesspoint at home. unified networks, or something... does a sweet job of updating itself [23:41] well it's an american problem, in SA our internet network is too shit to support any IoT stuff [23:42] american internet is about 20th on the world list [23:42] need more competition to get fiber in everywhere [23:43] only once google fiber came into city did my isp go from 20mbit to 100mbit. hey free upgrade guys, stay with us [23:44] how is netflix on 100MB? [23:46] it was fine on 20MB, 2-3 streams in HD (i think they were all HD) [23:47] now you can stream in 3D :D [23:47] wish i had a 3d tv. not too big on 3d though [23:47] waiting for a tv to blow up before i replace it [23:48] can see you're not american. jy is spaar vir geld. is jou vrou American? [23:48] nope she also south african [23:49] :D [23:49] i could not justify spending money on another tv. better things to buy [23:50] i have already "sized" up the tv's in the house. buy a bigger tv for HT room, move the other around, and throw out the smallest [23:51] living in a dorpie, I thought your kids would have no TV [23:51] at this point the guest bedroom has a 40 inch [23:51] "gaan daar uit die huis en kyk National Geographic" :D [23:51] they don't ever watch TV, it is so sad [23:52] do they have a mixed S.African accent or full blown "howdy y'all" ? [23:52] use ipads/phones to watch tv, even though they have a tv in their room with a chromecast... but noooo they watch it on ipad [23:53] they don't understand us, and we don't understand them :) [23:53] fascinating [23:53] and we in the "south". different accent to the west "TV" accent [23:54] when we came over when we emigrated, we were like wtf, this is not how americans sound on TV [23:54] what made you decide to leave? [23:56] well we looked at SA and for us, back then, didn't see anything that showed any signs for improvements [23:57] and we wanted kids to have a future without being based on colour [23:57] now you'll have superfly you can hang with :D [23:57] notice i can still spell south african [23:57] "color" "colour" [23:58] i should warn superfly [23:58] moving to a new country is SOOOOOOOOOOOOOOOOOOOOOOOOO hard, hardest thing I have ever had to do [23:59] easiest thing would be to have stayed in SA [23:59] so you never moving ever again? [23:59] naaa, other than the pain, i am very happy here. would never leave. (ive been brainwashed or something :) )