libera/#devuan/ Sunday, 2024-10-27

al1r4dBefore: Upgrading: 743, Installing: 88, Removing: 0, Not Upgrading: 314:29
al1r4dAfter:   Upgrading: 0, Installing: 0, Removing: 0, Not Upgrading: 314:30
al1r4dFeels great :D14:30
NrmlIs @rrq still around? Can he (or anyone here) confirm this is indeed his valid GPG key? https://pastebin.com/HyihWSxQ18:23
Nrml(I'm trying to validade the Devuan Daedalus ISO I just downloaded)18:24
fsmithredNrml, gimme a minute18:27
Nrmlfsmithred: thanks!18:29
fsmithredNrml, sorry, I'm not finding that key. I get a different one.18:42
Nrmlfsmithred: that's what I've been fearing18:44
NrmlPerhaps there are  trojaned ISO images around18:44
Nrmlwhat I did was:18:44
Nrml1) Downloaded https://files.devuan.org/devuan_daedalus.torrent and use it to download just devuan_daedalus/installer-iso/SHA256SUMS.txt, devuan_daedalus/installer-iso/SHA256SUMS.txt.asc, devuan_daedalus/installer-iso/devuan_daedalus_5.0.1_amd64_netinstall.iso18:47
Nrml2) Tried to check SHA256SUMS.txt GPG signature as per the pastebin above.18:47
fsmithredhang on, I'm still working on it.18:48
NrmlOK18:48
NrmlI'm doing some additional checks here18:48
NrmlHummrmrmrmr.... the SHA256SUMS.txt.asc file that I downloaded using the torrent, is *exactly* the same as the one currently at https://files.devuan.org/devuan_daedalus/installer-iso/SHA256SUMS.txt.asc18:50
NrmlSo, either it's not a trojan, or the attacker compromised files.devuan.org too.18:51
debdogdang, removed the torrent a couple of weeks ago (needed the space and it hadn't had any leechers18:51
debdog)18:51
rwpJFTR but my copy of that file that I downloaded "Sep 14 2023" is 722af7905595d9a1417f48f783d43dd40fe7da7a2e1d7998a8ea47df2d26941b18:51
Nrmlrwp: it checks with the ISO I just got via the torrent: devuan_daedalus/installer-iso$ sha256sum *18:52
Nrmlb27e0334d0a9dbfa11eb2e683a2bdd37f5eee21e94f152c3cf91e0ef96791957  README.txt18:52
Nrml868acfcfbe4bbe1f2657eb062edb9c192b1f1fd42f8a171dec5f7e78a858c881  SHA256SUMS.txt18:53
Nrmle911c6a24f9d3fb58283f080dfc022e5eb10af8196cbe187d0998b4bdda1d5a7  SHA256SUMS.txt.asc18:53
Nrml722af7905595d9a1417f48f783d43dd40fe7da7a2e1d7998a8ea47df2d26941b  devuan_daedalus_5.0.1_amd64_netinstall.iso18:53
NrmlBRB18:54
fsmithredI checked the sha256sum in the SHA256SUMS.txt on files.devuan.org matches the checksum on the 5.0.1 amd64 netinstall isos, one I downloaded about six weeks ago and the other last april. And the 5.0.1 i386 netinstall iso I downloaded over a year ago also matches the checksum file.18:58
fsmithredI don't know what's up with his key, and he probably won't be here for a few more hours.18:58
rwpIt looks like it is a key that is not known to the public key servers.  It flummoxes me too.19:02
fsmithredit should be known to me - we should both be in the devuan-keyrings19:03
rwpSo for example here is my current key: https://pgp.surfnet.nl/pks/lookup?op=vindex&fingerprint=on&search=0x421AFA26387F9A8E19:03
Nrmlback19:03
Nrmlfsmithred: thanks for the time and effort to check19:04
rwpBut if I search for 0x680B5A1F661ECDBC that key is not found.19:04
rwpI can download it from the public keyservers but no signatures.19:04
Nrmlfsmithred> it should be known to me - we should both be in the devuan-keyrings -> I confirm that it's not in devuan-keyrings. I manually imported all .gpg files from that package into my personal keyring and did not find the key used in SHA256SUMS.txt.asc19:06
NrmlI think it's probably a false alarm, but let's wait for @rrq to log back in and ask them19:07
NrmlI need to go AFK, will come back in a few hours too. Thanks everyone for your responses.19:07
rwpOf course the problem is one of "alert fatigue" and if we get in the habit of ignoring false alarms then we also ignore positive alarms too. :-(19:08
fsmithredI need to go beat up a horse. rrq will be back in a couple hours. Me too.19:10
rwpNrml, (fsmithred), If we trust keyring.devuan.org as containing authoritative information and not contain false then the key can be downloaded from there and the iso verifies with it: https://paste.debian.net/plain/133362319:16
rwpI will BBIAB19:17
fsmithredwget https://files.devuan.org/devuan-devs.gpg19:53
fsmithredgpg --import devuan-devs.gpg19:53
fsmithredgpg --list-sigs rrq19:54
XenguySurvey says?19:58
fsmithredit's real. One of the sigs on that key (Boian's) was signed by my key.19:58
fsmithredwe all know each other.19:58
fsmithredXenguy, thanks for chiming in. This gpg stuff always kicks my ass.20:01
XenguySo conclusion = crisis averted?20:01
fsmithredyeah20:01
XenguySo mote it be20:01
fsmithredI didn't actually verify the iso, but I see the web of trust on that key.20:01
fsmithred(I'm in it)20:01
XenguyI'm sure rrq can verify if there are any issues also, once he wakes up20:02
fsmithredyup20:02
XenguyGood man fsmithred , thanks for checking20:02
fsmithredyeah, I figured I'd just pull up that key on my computer, but I found a different one.20:03
fsmithredAnd then that extended to searching on four computers.20:03
XenguyPhew20:03
fsmithredyou saved the day.20:03
XenguyJust an all-round average hero  = )20:03
Nrmlback20:14
Nrmlso false alarm after all. But better to spend time chasing down a thousand false alarms, than let a true alarm go by unchecked.20:15
NrmlI'm importing that file and cross-checking here20:16
fsmithredyeah, and I really should have a current version of the devuan-devs keyring since I'm in it.20:16
NrmlSo this is what I see: https://pastebin.com/B0N9RqKe20:21
NrmlIs it good?20:21
XenguyNrml, re: "But better to spend time chasing down a thousand false alarms, than let a true alarm go by unchecked.":  Definitely, yes20:21
XenguyThank you20:21
fsmithredyeah, that's good. If you want to check that further, you can check sigs on Boian's key and you'll see I signed it.20:22
fsmithredso they keys are good.20:22
fsmithredYou can verify the iso. i didn't do that part, but I do know the sha256sum is right.20:23
fsmithredI'm going outside while it's still warm.20:25
fsmithredbbl.20:25
Nrmlfsmithred: devuan_daedalus/installer-iso$ grep devuan_daedalus_5.0.1_amd64_netinstall.iso SHA256SUMS.txt | sha256sum -c -20:29
Nrmldevuan_daedalus_5.0.1_amd64_netinstall.iso: OK20:29
NrmlSo I guess everything is good.20:29
Nrmlthanks again everyone.20:30
NrmlXenguy: \thank *you* and fsmithred and all the great Devuan folks. If it wasn't for you, I would have moved to one of the *BSDs, because systemd is simply unbearable.20:39
XenguyIt really is unbearable, I think we all feel this way20:40
XenguyMy pleasure, just trying to eat my own dog food20:41
XenguyIf people believe in the Devuan project, please consider lending a hand, if you can20:42
XenguyThis is how DIY projects keep on truckin20:42
Nrmlheh :-) I wish I could find food as good as Devuan for my dog when she was alive. Devuan is prime time gourmet food :-)20:42
NrmlBetter than Debian, and that's saying something.20:43
* Xenguy thinks Indian for dinner : -)20:43
rwpYay!  Crisis averted.20:44
Nrmlre: lending a hand, I wish I had the leisure. I can't name any project more worthy than Devuan.20:44
rwpEngineering to save lives here no doubt.  Or at least sanity. :-)20:45
Nrmlrwp: indeed.20:46
NrmlI try and convince my friends to use Devuan, but they are all in denial.20:46
NrmlThe other day, when systemd opened up sshd for remote attack, I talked to one of them about it, and he said, "ah, but that isn't really systemd's fault" WTF?!20:47
XenguyI think maybe technically it was Debian's fault due to their configuration, but still, systemd had a role in that20:49
NrmlAnd the other day the main developer in a project I participate simply said, "systemd isn't the monster you think it is". WTF again...20:49
NrmlXenguy: I think systemd and its policy of incorporating everything in itself was instrumental in that issue.20:50
XenguyIt's a huge attack vector, and it goes against the principles of 'do one thing and do it well'.  I've decided that people either get it or they don't20:50
NrmlExactly! The original Unix designers had very good reasons for their philosophy of separating the OS in many small parts and making every one of them as simple and as interoperable as possible. Systemd just throws all of that out the window.20:51
NrmlSecurity is just one thing to go out the window with that principle.20:52
XenguyYes, a violation of design principles if you will...20:52
XenguyDevil's advocates will reply by saying, yeah but what about ... ?20:52
NrmlThat's "whataboutism" for you20:52
XenguyAnd sure, there are already exceptions before systemd...20:52
XenguyYes20:53
XenguyBut systemd is the most egregious violation of the whole lot, and we're talking about the *init* system here20:53
NrmlWhen people start arguments with "what about", it's the moment I decide I'm wasting my time and move on to some other thing20:53
NrmlMost egregious by quite a few orders of magnitude, we should say.20:54
XenguyI think so, it's akin to the windows'ification of linux, to my mind20:56
Nrmloh man20:56
Nrmlexactly20:56
Nrmlthe joke stating that "Windows is the operating system of the future, because in the future all operating systems will be like Windows" is a sad reality, I think20:57
NrmlI can only hope I'll be long dead by then :-/20:57
XenguyWell as you (or someone) stated, if we can't defend the integrity of Linux, then we'll be forced to retreat to the BSD realm (there is nothing wrong with BSD of course, don't get me wrong, I have the highest respect for it)20:59
XenguyWhile I respect BSD, I *prefer* to run Linux if I can20:59
XenguySo here we are20:59
XenguyContribute or die  : -)21:00
NrmlI love BSD. But Linux is simply better (better supported, better drivers, larger community, etc)21:05
XenguyA quirk of history, involving law suits as I recall21:07
Nrmlyeah AT&T *had* to eff it up with their BSD4.4 lawsuit21:08
NrmlMy first opensource *BSD was 386BSD, and it rocked.21:08
XenguyThe lawsuit drama offered Linux the time and opportunity to get a leg up, IIUC21:09
Nrmlexactly.21:09
NrmlAnyway, here we are21:09
Xenguy"Wherever you go..."21:09
NrmlI just hope you folks can keep Devuan alive for a long time21:09
NrmlLOL "... there you are" ;-)21:10
XenguyWe all die eventually, and need youth to continue; that's the reality of everyone's situation21:10
XenguyThanks for the chat, I'm off hunting for grub21:11
Nrmlyou are more than welcome, Xenguy. Good grub hunting for you, I also have some chores to attend to21:11
* Nrml waves21:11
Xenguyo/21:12
systemdleteapt update is failing with bad certificates.  I am running withOUT the cacher server.23:26
systemdleteI changed the sources back to https: and tried apt update23:26
systemdleteare certs being updated atm?  If so, I can wait until it is done.23:27
systemdlete(oh, and disabled the apt-proxy in the apt config)23:27
rrqonly a few mirror servers support https and you then need to use their exact domain name23:54
rrqthey don't have certificates for the domain "deb.devuan.org" becaus that certificate owner doesn;t want to share their key23:55

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!