00:32:43 <cayce> mmm
00:33:39 <cayce> that's pretty bad, because we all know undernet is mostly bots anyway
00:33:47 <cayce> quakenet too
00:49:04 <cayce> "This is the time of the revolution... Cooking the next step... Converting vegetarians....
02:04:24 <wh1t3r4bb1t> when you md5 hash an sha1 hash of something it can't be reversed as far as I can tell. interesting.
02:11:11 <wh1t3r4bb1t> Sweet sexiness! I have the registration process working, media uploader works and puts the users' stuff in their own folder. Working on account activation now. Next, posting in the stream. Fux WP/BP. This is a much better social engine so far.
02:12:41 <wh1t3r4bb1t> 99% original code. Only using a highly forked version of jQuery filer uploader hacked by yours truley. :P
02:13:00 <wh1t3r4bb1t> filer = file*
02:13:55 <wh1t3r4bb1t> Praise sleep and MK+FG for getting me unstuck from a simple overlooked issue!
02:16:20 <cayce> does sha'ing an md5 bias the output?
02:25:56 <wh1t3r4bb1t> cayce: to the best of my knowledge, no. Try to reverse this hash... ade234c9246f91ada4fd90a8e4c94fb62eb38caf
02:26:22 <cayce> Don't ask me to do anything
02:26:43 <cayce> I don't know how to do any of that shit, I just remember everything and ask questions.
02:29:06 <cayce> I can't find anything in google, but I remember at one point there were situations where you could bias the output of hashing algorithms by combining them. I don't, however, remember what those situations or hashing algos were.
02:29:24 <cayce> It's possible it isn't a thing
03:00:47 <cayce> I haven't read this yet, but fuck it's cool that this is a thing:
03:00:56 <cayce> official UK gov policy stances on nice clean page
03:01:00 <cayce> fuck yeah
03:01:08 <cayce> my little polisci heart beats faster
03:30:00 <joepie91> This update is important as it may solve critical problems.
03:30:00 <joepie91> The /etc/sysconfig/security uses "PERMISSIONFSCAPS" as variable, while chkstat queried PERMISSIONSFSCAPS... The chkstat binary was adjusted the correct PERMISSION_FSCAPS name.
03:30:02 <joepie91> rofl
03:30:27 <joepie91> this would be a good moment for that GIF about "when you realize you've pushed a critical bug to production"
03:30:37 <joepie91> also
03:30:38 <joepie91> <wh1t3r4bb1t>when you md5 hash an sha1 hash of something it can't be reversed as far as I can tell. interesting.
03:30:38 <joepie91> nonsense
03:30:48 <joepie91> md5 and sha1 cannot be reversed by definition
03:31:00 <joepie91> and all that happens when you combine them is just adding another layer of hashing
03:31:19 <joepie91> and it's unclear whether this may have adverse effects on security
03:31:20 <joepie91> so don't do it
03:56:21 <cayce> ^
04:23:06 <wh1t3r4bb1t> how do I get free third party validation for my development server ssl?
04:58:46 <joepie91> wh1t3r4bb1t: if you *really* need a CA-signed certificate, you can try startssl
04:58:56 <joepie91> but self-signed will work fine if you don't care about red screens in browsers
05:22:20 <wh1t3r4bb1t> joepie91: I just used self signed. It's for the dev server so who cares.
05:26:18 <joepie91> wh1t3r4bb1t: pretty much :P
05:26:36 <joepie91> the only point of a signed certificate is that a client can supposedly verify that it's legitimate and not spoofed/MITMed
05:27:07 <joepie91> by relying on the authority, security and proper verification process of a few hundred different CAs
05:27:28 <joepie91> only one of which has to be compromised on any of those points to completely break the 'security' provided by signed certificates
05:27:50 <joepie91> in other words: signed certificates make the annoying red screen in your browser go away, and that's about all they are good for
05:28:03 <joepie91> or rather, makes it go away for others
05:28:08 <joepie91> for yourself you can just add yourself as a trusted issuer
05:29:30 <wh1t3r4bb1t> joepie91: this is true. :)
05:32:06 <ElectRo`> i feel like the feds can easily ask the major CA providers for keys and its game over.
05:33:44 <joepie91> ElectRo`: basically, yes
05:33:51 <joepie91> well
05:33:58 <joepie91> specifically
05:34:10 <joepie91> they could easily ask the major CA providers for their root cert privkeys
05:34:17 <joepie91> and just sign their own certs
05:34:19 <joepie91> and MITM people
05:35:26 <wh1t3r4bb1t> lol they don't usually ask. The gov employees counter security people and measures.
05:36:29 <wh1t3r4bb1t> If they do ask. Saying no will make your life miserable I imagine.
05:38:15 <joepie91> well yes, my use of the 'asking' verb is relative here
05:44:58 <ElectRo`> they can "ask" with a "warrant"
05:45:38 <ElectRo`> i didnt know ddg can search startpage
05:50:39 <cayce> asking can also be "don't get the gov-wide contract for all certs and signing for all IT projects for the next 10 years"
05:55:11 <joepie91> hence my loose usage of the term 'asking' :)
08:44:03 iceTwy (quixotikal@iceTwy.users.cryto) has joined #crytocc
09:04:47 <iceTwy> Hola
09:11:40 <wh1t3r4bb1t> yo
09:14:58 <joepie91> hai
09:14:58 <joepie91> iceTwy
09:15:05 <joepie91>
09:15:16 <iceTwy> watchin'
09:15:17 <joepie91> cc wh1t3r4bb1t, ElectRo`, MK_FG, lysobit, cayce
09:15:22 <joepie91> other interesting people that I forgot to highlight
09:15:23 <joepie91> :p
09:15:26 <joepie91> er
09:15:27 <joepie91> interested*
09:17:13 <iceTwy> o.o
09:19:04 <joepie91> iceTwy: like it? :P
09:19:15 <iceTwy> lol yeah
09:19:24 <iceTwy> did you record all of it?
09:19:33 <joepie91> not quite
09:19:35 <iceTwy> writing the whole parser*
09:19:36 <joepie91> I used a duct tape solution
09:19:41 <iceTwy> ah
09:19:42 <joepie91> what you see
09:19:43 <joepie91> is the entire parser
09:19:45 <joepie91> how I did it:
09:19:54 <joepie91> 1. hold ctrl+z until document empty
09:19:57 <joepie91> 2. turn on xvidcap
09:20:02 <joepie91> 3. hold ctrl+y until stopped
09:20:04 <joepie91> :)
09:20:11 <joepie91> poor mans timelapse
09:20:20 <iceTwy> loooool
09:20:36 <joepie91> it came out quite nicely, though
09:20:39 <iceTwy> that's a nice trick yeah
09:20:59 <joepie91> now
09:21:04 <joepie91> time to continue work on it
09:21:04 <joepie91> :3
09:21:28 <wh1t3r4bb1t> Sweet!
09:23:12 <wh1t3r4bb1t> When I set this cookies for rememberme I can't retrieve it aparently. there is a . in front of the domain. would that be the cause?
09:23:58 <joepie91> 1. why are you still messing about with cookies rather than using PHP sessions?
09:24:11 <joepie91> 2. is there a mismatch between the domain you set the cookie on, and the one you try to retrieve it on?
09:28:31 x has quit (Ping timeout)
09:34:10 <wh1t3r4bb1t> joepie91: The cookie is only for rememberme. The script just actually did retrieve it but not when it was supposed to. I don't see a mismatch in the domain.
09:40:09 <wh1t3r4bb1t> Ok the cookie is being retrieved while the session I set for maintaining login lives.
09:43:10 <wh1t3r4bb1t> Cookie still exists, but it's not being retrieved after browser close and reopen. Isn't the whole point of a cookie that I can retrieve it after the browser reopens to reinstate the logged in session?
09:44:51 <joepie91> this has turned out surprisingly nicely:
09:44:52 <joepie91>         def evaluate(self, message):
09:44:52 <joepie91>                 if self.relation == AND:
09:44:52 <joepie91>                         for element in self.elements:
09:44:52 <joepie91>                                 if element.evaluate() != True:
09:44:52 <joepie91>                                         return False
09:44:52 <joepie91>                         return True
09:44:52 <joepie91>                 elif self.relation == OR:
09:44:52 <joepie91>                         for element in self.elements:
09:44:52 <joepie91>                                 if element.evaluate() == True:
09:44:52 <joepie91>                                         return True
09:44:53 <joepie91>                         return False
09:45:26 <joepie91> wh1t3r4bb1t: your problem is too complex to solve it with the information you've given
09:45:32 <joepie91> also, I see no reason for 'rememberme' having a separate cookie
09:46:27 <wh1t3r4bb1t> Well, I just discovered a potential problem in the logs. brb
10:43:46 <wh1t3r4bb1t> Ok I got it figured out. I was setting the cookie for secure connections only. Switched it to any kind and now it auto logs in then redirects to https
10:52:17 <joepie91> wh1t3r4bb1t: you should really do the login itself over https
11:05:17 <iceTwy> dat feel when your SSH connection is shit
11:05:26 <joepie91> iceTwy: don't remind me :(
11:05:33 <joepie91> lol
11:05:40 <joepie91> also, I'm currently working on boolean parsing logic
11:05:51 <joepie91> somehow, it's harder than the main parsing loop
12:03:26 <wh1t3r4bb1t> jquery features and status posts have to wait till tomorrow. i'm completely tired. gnight all
12:20:45 <iceTwy> night wh1t3r4bb1t
12:20:58 <iceTwy> where's monod btw?
12:21:01 <iceTwy> joepie91: ^
12:21:11 <iceTwy> !seen monod
12:44:12 <joepie91> iceTwy: no idea, probably busy with IRL
12:44:50 <iceTwy> yeah
12:44:52 * iceTwy shrugs
15:44:36 <Zoned> Whats up everyone?
16:12:24 <lysobit> joepie91: I think I figured out why people in #python recommend twisted so much
17:26:40 iceTwy (iceTwy@iceTwy.users.cryto) has joined #crytocc
17:27:20 <iceTwy> back
17:27:21 <iceTwy> so
17:27:24 <iceTwy> I've signed up at the gym
17:27:29 <iceTwy> parents' present
17:27:43 <iceTwy> they think neither my bro, nor me move our asses enough
17:27:49 <iceTwy> (which is actually 110% true)
17:33:08 <cayce> good
17:33:27 <cayce> Go get a bike and ride around the tenements
17:33:40 <cayce> You'll ride pretty fast trying to dodge bullets, it'll be a good workout
17:36:55 mama ( has joined #crytocc
17:38:30 <iceTwy> say what
17:38:31 <iceTwy> lol
17:38:53 <iceTwy> did joepie91 go to sleep?
18:00:20 colombia has quit (Ping timeout)
18:01:50 <cayce> I think I need to ride my bike to the beach
18:05:52 mama has quit (Ping timeout)
18:06:13 <iceTwy> herp
18:06:26 <iceTwy> I'm still trying to find documentation about linking Atheme to Charybdis
18:12:05 mama ( has joined #crytocc
18:32:26 <MK_FG> lysobit, Because it's awesome? ;)
21:03:29 iceTwy (quixotikal@iceTwy.users.cryto) has joined #crytocc
22:14:44 <wh1t3r4bb1t> mornin
22:25:18 <iceTwy> morning wh1t3r4bb1t
