Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

equinox

@equinox@chaos.social
mastodon 4.6.9
  • Open on chaos.social

he/him · FRRouting · Junisco & Hp3Com slayer · knows more about IP routing than is healthy · moonlights in bullying electrons around a circuit board

0 Followers
0 Following
40 Posts
Joined November 05, 2022
github:
https://github.com/eqvinox
threema:
95JJFCSA
signal:
equinox.79
pronouns:
he/him
Open post
equinox @equinox@chaos.social
· 4mo ago

So TIL perl has a "flip-flop" operator, ".." (two dots) — if left side is true, it turns on, if the right side is true it turns off.

Yeah, "turns on" and "turns off" means it _remembers state_. Internally.

I don't think I've ever seen such a… cute? no… clever? no… obnoxious and hazard-prone language feature.

Put it in a file-processing function, process multiple files… yeah who needs scope? And a perl non-wiz like me doesn't even notice state being kept.

What a great perl-being-perl example.

10
2
1
0
Open post
equinox @equinox@chaos.social
· 2mo ago
found something while looking through backups… cablingplan-27C3_V2.pdf
3
1
0
0
Open post
equinox @equinox@chaos.social
· 4mo ago

Zelenskyy is starting to dip into his comedy chops again, this can only mean good things 😂 🇺🇦 🎉

(source: TLDR news reporting)

5
0
0
0
Open post
equinox @equinox@chaos.social
· 7mo ago
Replying to
@Jay16K uh, neither the DNS protocol nor general practices or shortcomings around DNS seem to be at fault here. Pretty much any protocol, when implemented by people with insufficient understanding, will suffer bugs like this. I mean, I'm a L3 person, I'll happily shit on DNS all day long… but not without reason?
4
0
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@Tarah@infosec.exchange @letsencrypt@infosec.exchange it's a "compliance" incident https://news.ycombinator.com/item?id=48068096 [= Josh Aas = Executive Director @ ISRG]
news.ycombinator.com

This is a compliance incident, we should be issuing again shortly. Update: Issua... | Hacker News

2
0
1
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@mirabilos@toot.mirbsd.org @dalias@hachyderm.io if you can't block authencesn (e.g. built into kernel), blocking esp4, esp6 and algif_aead is the fallback to cover that indirectly.
2
2
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@dalias@hachyderm.io @mirabilos@toot.mirbsd.org oh I totally agree. My AF_ALG code comes with an equivalent openssl implementation that is bit compatible. It just doesn't support the primary secret being moved into kernel memory (or TPM). (I test my code on FreeBSD, not everything, but anything that may have OS deps. Testing random Linux permutations is a bit much, but if it works on FreeBSD that should cover a lot)
2
2
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago

I don't understand why everyone is picking on algif_aead for copy.fail. It's authencesn that's actually fucking things up.

Sure, you could keep using authencesn for IPsec if you break AF_ALG AEADs. But why? I'd rather break ESN support in IPsec and keep AF_ALG working for AEADs.

It doesn't even break IPsec, it just makes it rotate keys more often in very high bandwidth situations.

2
20
1
0
Open post
equinox @equinox@chaos.social
· 6mo ago
Replying to
@struberg @gnomon it's so bad, even we are migrating away from their shit, and we got it for free on a nonprofit license 😂
2
0
0
0
Open post
equinox @equinox@chaos.social
· 4mo ago
Replying to
@hyc@mastodon.social (the syscall cost for logging was notable, hence the use of sendmmsg. And the issue is tracking down rare issues that happen on "important" routers once in 3 weeks; you don't want to waste a shot because you forgot debug flag XYZ.)
1
0
0
0
Open post
equinox @equinox@chaos.social
· 4mo ago
Replying to
@hyc@mastodon.social I can one-up that 😂 We batch out debug messages (thread-locally) and send them out with sendmmsg() if that's available. And then we have the occasional discussion where people wonder why we don't use , we drag out some numbers and people are about the rates. (For us it's not request rate, it's the sheer number of debug messages, all of which you want because a DFZ router is expensive to restart to hunt things. "Need debug = NEED DEBUG.")
1
1
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@mirabilos@toot.mirbsd.org @dalias@hachyderm.io surprise! the AF_ALG / algif_aead code is essentially "innocent". (=> dirty.frag)
1
2
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@dalias@hachyderm.io @mirabilos@toot.mirbsd.org I/we did ditch Solaris support, because it was fucking painful and Oracle ain't paying zilch, I hope that's ok 🙃
1
0
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@mirabilos@toot.mirbsd.org sure, if that's your choice then that's your choice. I have written code for AF_ALG and I run IPsec. (without ESNs, because that's the default in StrongSwan, and I haven't had reason to worry about rekeying.) I know who @dalias@hachyderm.io is and I greatly respect them for their work on musl. But I'll stick with my opinion until someone claims at least the same experience level as I have. Maybe that's dalias, maybe not, idk their skills on this.
1
6
0
0
Open post
equinox @equinox@chaos.social
· 8mo ago
Replying to
@ariadne@social.treehouse.systems @arclight@oldbytes.space @dalias@hachyderm.io if your IP is categorised as residential, you're still fucked AFAIK.
2
0
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@eloy @q no, because that's not possible. It's for relay<->server and snooper<->server communication. A client simply cannot use it. It actually makes some sense; DHCP snooping is part of first-hop security & SAVI. It's giving me headaches about what TLS library to pull into FRRouting, though. (DHCP relay & snooping is coming in a year or two.)
1
1
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@cmb@cathode.church the load switch should probably have an active output discharge thingy, what with how little power the 1T45s are pulling they might stay on for half a second… (a pair of AO3400+AO3401+resistors would also do the trick, and those are already on the BOM — but I have no idea if optimizing for fewer distinct parts is relevant for this)
1
2
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@cmb@cathode.church I don't think what you're trying to do there will work; DIR still needs to be driven by the FPGA and if you swap the directions the 1T45 will reference that input to Vio… and the FPGA probably won't meet Vil thresholds for the very low voltage ranges (0.315V for Vio=0.9V) and won't meet Vih (3.5V) for 5V either... I would instead create a "+3V3 1T45" net (only one, for all 1T45 chips) and switch that whole net off while the FPGA is not ready.
1
4
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@cmb@cathode.church (to be clear, I'm implying to switch the FPGA back to the A side, which… sorry, that's a little bit annoying with the PCB already started, but, well, better now than later 😅)
1
3
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@cmb@cathode.church ok I grabbed the laptop and it's unchanged from the PDF I don't understand how this⇒ "During reset, DIR pins from the FPGA are high, to prevent all-high outputs in that case, A and B are swapped compared to revC." can be possible at all? Either I'm having a very 🤪 moment or it's seriously fishy.
1
6
0
0
Open post
equinox @equinox@chaos.social
· 8mo ago
Replying to
@cstross@wandering.shop I wish I could enjoy the laugh, but: "Thule AB receives supplies throughout the year on military rotator aircraft and other cargo ships, however, most of the supplies and fuel are provided during Pacer Goose." They're just too cheap to use the other options for bulk stuff.
2
0
1
0
Open post
equinox @equinox@chaos.social
· 6mo ago
Replying to
@zekjur I made the FRR library executable (no I didn't get confused there) just so it can report its version. Sadly, this broke at some point due to some changes in GCC re. assumptions about stack alignment (assumes 0/16, but it's 8/16 on x86_64 now), need to push a fix for that… I invite FRR users to try running libfrr.so, maybe your version still works 😉
1
0
0
0
Open post
equinox @equinox@chaos.social
· 6mo ago
Replying to
@djb this reminds me of the Star Trek episode with Data and the Zakdorn [https://memory-alpha.fandom.com/wiki/Peak_Performance_(episode)] where Data keep losing until he switches his strategy to a draw instead of a win. Only at that point does he not immediately lose, leaving the Zakdorn to quit in frustration. Play for the draw. [P.S.: I have zero fucking clue about cryptography, quantum or regular.]
memory-alpha.fandom.com
1
0
0
0
Open post
equinox @equinox@chaos.social
· 7mo ago
Replying to
@andrewnez I guess it's an unverified assumption but it feels like that's wasting a whole bunch of CPU cycles for no reason 😕
1
0
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@cmb@cathode.church NB: I was looking at the PDF on the phone, I just noticed it is a week old… (could you push a fresh PDF for people like me?)
0
7
0
0
Open post
equinox @equinox@chaos.social
· 4mo ago
Replying to
@duco@norden.social @andrmr@mastodon.social Hausnummern und Hausumringe sind in DE als Open Data von den GIS-Behörden der Länder verfügbar (Katasteramt o.Ä., nach Land unterschiedlich) (Will jetzt nicht ausschließen dass die irgendwo fehlen.) Wenn die Lizenz keinen OSM import hergibt dann (a) braucht das Politikarbeit, und (b) für die Zwischenzeit müsste das direkt bei den Rettungskräften eingebunden werden. Dass die Behörden selber uploaden… ja… das geht halt nicht per Fax…
0
0
0
0
Open post
equinox @equinox@chaos.social
· 3mo ago
https://lantian.pub/en/article/fun/ai-agent-bankrupted-their-operator-scan-dn42lantian.lantian/ https://news.ycombinator.com/item?id=48500012 Seeing what dn42 has become truly warms my heart… especially the bits like this https://news.ycombinator.com/item?id=48501597 :rainbow_heart:
AI Agent Bankrupted Their Operator While Trying to Scan DN42 - Lan Tian @ Blog
Lan Tian @ Blog

AI Agent Bankrupted Their Operator While Trying to Scan DN42 - Lan Tian @ Blog

0
0
1
0
Open post
equinox @equinox@chaos.social
· 2mo ago
@azonenberg@ioc.exchange so @Oskar456@mastodon.social is trying to debug weird behavior with a device's SFP+ ports that is suspected to be misconfig between operating (at 1G) as SGMII or 1000base-X (or some bits in the negotiation pages on either) - do you have any suggestions/ideas how to (cheaply) debug that? Identifying a signal as SGMII vs. 1000base-X would be good, getting the AN pages dumped better…
0
1
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@cmb@cathode.church also how does the A/B swap on the 74AXP1T45 work? DIR is referenced to VccA but A is the pin header? And VccA is 3.3V while VccB is Vio but B goes to FPGA? Am I misreading something?
0
8
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@mirabilos@toot.mirbsd.org hm, I didn't see that, where is that?
0
2
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@whitequark @azonenberg that whole altname concept completely wrecks anything where you configure things per-interface. Imagine I write a config that has 2 different blocks for "wlp59s0" and "wlxccd9ac6b1813".
0
3
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@mirabilos@toot.mirbsd.org there's a "c" missing in authencesn, just to make sure, that's not missing in your config, right?
0
2
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@whitequark @azonenberg also, this invokes the "other" computer science adage — there's only 2 hard things, naming things and cache invalidation.
0
0
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@cmb@cathode.church are the 4 VBUS pins internally connected on that USB-C connector? I'm a bit confused from seeing only one VBUS pin 😅 [edit: 2 each are connected physically, and the pairs then in the kicad part, so it's fine…]
0
2
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@dianea did you mean: superfluikitty? 😸
0
0
0
0
Open post
equinox @equinox@chaos.social
· 5mo ago
Replying to
@mirabilos@toot.mirbsd.org I still don't see mentions of more upcoming shit, but then again I'm tired and it's slop-y text. As for their recommendation: being able to get exploits out of an LLM and understanding what's what in the kernel are not the same skill. Nuking algif_aead "fixes" it. So does nuking authencesn. I see no reason given by them to prefer nuking AF_ALG. I guess it's a user interface? Counterargument: authencesn has network exposure.
0
2
0
0
Open post
equinox @equinox@chaos.social
· 6mo ago
Replying to
@djb from what I've seen, it looks pretty bad, yeah. But at this point the question is whether you want agreement on that or just the document to not get an IETF "stamp of approval". Getting the latter is much easier, at the cost of the former. The IETF is really shit at doing "negatives", i.e. not accepting work. It's a general problem (I'm in the routing area). You can keep pushing to try to get one of those rare "no"s, but it's gonna be incredibly tedious. It's absolutely not worth it IMHO.
0
0
0
0
Open post
equinox @equinox@chaos.social
· 7mo ago
Replying to
@andrewnez does forgejo really fork out to run the git binary? Why would it not just use libgit 😨
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 06:13:33 UTC