HN user

stargrave

7,411 karma

http://www.stargrave.org/

Posts385
Comments37
View on HN
github.com 4mo ago

California results are not authorised to use MidnightBSD

stargrave
7pts0
fireborn.mataroa.blog 4mo ago

The Slow Death of the Power User

stargrave
21pts13
fosdem.org 5mo ago

Terrible economics of package registries and how to fix them [video]

stargrave
1pts0
drewdevault.com 9mo ago

What's Up with FUTO?

stargrave
47pts23
www.rebuildworld.net 9mo ago

Make Rebuildworld

stargrave
2pts0
susam.net 1y ago

SHA-256 0573e7473

stargrave
18pts11
lists.suckless.org 1y ago

Kernel Maintainer Censored on LKML

stargrave
3pts0
git.kernel.org 1y ago

Linux removed 11 maintainers from Russia

stargrave
52pts8
cr.yp.to 1y ago

Don't Publish with IEEE (2005)

stargrave
239pts92
blog.sesse.net 2y ago

Pull Requests via Git Push

stargrave
16pts8
occ.deadnet.se 2y ago

Old Computer Challenge: Year 4

stargrave
3pts0
keymaterial.net 2y ago

Reconstructing Public Keys from Signatures

stargrave
3pts0
blog.cr.yp.to 2y ago

Bibliography keys: It's as easy as [1], [2], [3]

stargrave
64pts27
www.vors.stargrave.org 2y ago

VoRS: Vo(IP) Simple Alternative to Mumble

stargrave
86pts71
xahlee.info 2y ago

Google Crimes

stargrave
24pts12
librepgp.org 2y ago

LibrePGP – Fork of OpenPGP

stargrave
5pts0
www.rfc-editor.org 2y ago

RFC 9498 on the GNU Name System

stargrave
142pts37
dn42.eu 2y ago

Dn42: Big Dynamic VPN with Own IPs, ASNs, BGP, DNS

stargrave
4pts0
wiki.hyperbola.info 2y ago

Hyperbola GNU/Linux-Libre's incompatible packages

stargrave
3pts1
www.retro-exo.com 2y ago

EXoDOS Version 6.0

stargrave
2pts0
unixsheikh.com 2y ago

The Main Differences Between OpenBSD, FreeBSD, NetBSD and DragonFly BSD

stargrave
4pts1
marc.info 2y ago

OpenBSD on Zenbleed

stargrave
71pts60
www.rfc-editor.org 3y ago

RFC 9446: Reflections on Ten Years Past the Snowden Revelations

stargrave
1pts0
lists.freebsd.org 3y ago

In Memoriam: Hans Petter William Sirevåg Selasky

stargrave
118pts6
blog.phnx.im 3y ago

Messaging Layer Security (MLS) – An Overview

stargrave
5pts0
blog.josefsson.org 3y ago

Coping with Non-Free Debian

stargrave
1pts0
groups.google.com 3y ago

Why there may never be a libjpeg-turbo 3.1

stargrave
110pts2
sec.okta.com 3y ago

WebAuthn Is Great and It Sucks (2020)

stargrave
148pts143
www.hyphanet.org 3y ago

Freenet Renamed to Hyphanet

stargrave
45pts24
www.jeffgeerling.com 3y ago

I'm Done with Red Hat (Enterprise Linux)

stargrave
519pts394

My blog (http://blog.stargrave.org/russian/) initially also used Git as a storage, where each commit is a post, and its log message is the content itself. If I add gitweb/cgit, when it will also feature web interface and Atom feed automatically. Later I added my own rendering engine to it: http://www.sgblog.stargrave.org/ for efficiency and automatic transparent gopher/gemini protocols support. Each post also can have some dynamic tags/topics attached, that are stored in git's notes branch. And later I also added ability to leave comments, by sending email message, that is committed in another git-note branch in the form of recfile (https://www.gnu.org/software/recutils/) plain-text comment. Everything is plain text, can be used with Git solely, but has an engine for better rendering and wider protocols support.

My 12+ years old website: http://www.stargrave.org/ Currently it is built as a Texinfo document. Previously I used reStructuted Text (Sphinx), Vimwiki, Gopher-compatible Perl scripts, FTP-viewable READMEs and static HTMLs. Contains much more data than even social networks will ask from people.

And again noone forces you to use multiple files too :-). You can literally have just single default.do file for the whole project. apenwarr/redo somewhere explicitly noted that. Separate .do files are only for convenience and ability to automatically depend on target's build rules independently from others, that Make just do not do at all.

Nobody forces you to use any kind of shell with redo. Its .do files can be anything you want: ELF object files, shell scripts, Perl, Python, whatever, just make it executable and obey trivial simple rules (stdout and three arguments).

FidoNet is still living, however it lacks at least strong authentication and data confidentiality (no crypto used at all). But it shows that people could be capable of creating global networks without unwanted third-parties.

For building store-and-forward networks I created NNCP several years ago and lack of connectivity, censorship (making no connection links) are one of the issues it aims to solve: http://www.nncpgo.org/Use-cases.html

Personally I used Python's tnote program, but, because of Python, it worked pretty slowly. So I rewrite on pure POSIX shell and it serves me for nearly ten years: http://www.git.stargrave.org/?p=t.git;a=blob;f=t

Comparing to author's solution, it gives ability to briefly list notes, use multiple "namespaces", quickly add (without invoking the editor), delete or modify each specified note. Also there is no bashism and it works out of box on *BSD (that lacks bash) and GNU systems.

No, multiple output is not covered. gored passes on all my projects, even containing complicated redo-stamp/redo-always dependencies the same as apenwarr/redo. Not everything is passed in its testsuite, but I did not dig why. In practice it is complete replacement for my needs with the same behaviour.

Dataforge UUCP 7 years ago

I have posted link on HN to Dataforge UUCP because I have been interested in store-and-forward networks for a long years. All my email passing between notebook and my email servers used UUCP-over-SSH for years. But soon I create NNCP (http://www.nncpgo.org/) project and totally moved all my email/files store-and-forward networks to it. Possibly it could be interested to you.

Unfortunately NNTP(like) is the only thing I have never touched at all. I have several years of experience with FidoNet's echomail (this is like NNTP), but today I see that most of discussion is done in mailing lists and I have got no usecases I really could use with something like NNTP (and that is disappointing, because I really like that echomail/news nature).

For example http://www.cypherpunks.ru/pygost/Download.html page contains instructions how to receive the key. You can get it using either maillist, website, DNS, keyservers. And you can use various DNS servers and transport routes via Tor. There is plenty of options. And this key is signed with another one containing many signatures. Of course there is no full guarantees, but at least you have to do it just once and then conveniently do tarballs verifying. With TLS you have to do it everytime, all the time you visit and connect to the server.

Moreover how can you "transfer" the trust to other people? If you proxy/give tarball to someone else, then how can you prove that you did not tamper it? Again, with detached signatures people knowing public key can authenticate it, without connecting to Internet. With TLS there is only single distribution point (TLS website) that can not transfer trust to someone else.

What CA should be used for certificate issuing? Paid one? Not an option if you do not want to support PKI business model (it is business, not security). CAcert.org? Modern browsers and operating systems does not include its certificate too. So anyway you have to get its public key too somehow.

So, TLS has the same problem of getting the public key and is less convenient in use, requiring TLS-aware webserver (instead of cheap providers with static pages hosting), without ability to transfer trust (send signature separately) to someone else. OpenPGP keys (for www.cypherpunks.ru websites), comparing to CA ones, can be received with several (!) keyservers (many of them replicates between themselves), several (!) DNS servers (listed as NS record), through various transports (VPN, proxy, Tor) to one of webservers (listed as A/AAAA record).

But OpenPGP detached signatures, that are isolated and does not depend no transport protocols (TLS), defend you from all that kind of MitM attacks, because they are point-to-point (directly from developer to end-user), without depending on any third-party (like CA issuing TLS certificates, DNSSEC provides, intermediate DNS proxies that must not strip DNSSEC off, and so on).

PKI is a business model. That download page suggests you to verify downloaded tarballs with OpenPGP key, or visit Git repository to look for signed (OpenPGP again) tags there. Of course you have to setup some kind of trust for verifying keys. If your browser shows you such kind of errors, then seems that you do not trust CAcert.org used for certificate creation. You may retrieve OpenPGP keys and find signature you may trust. PKI (HTTPS) is single point of trust, OpenPGP provides much more ones.

syncer works on block level, with raw byte sequences. It knows nothing about file systems. Everything is limited with sequential read/write speeds of your hard drives.

It takes blocksize-size memory block for each CPU in your system. I have got 4 CPUs and work with 2 MiB blocks: program will take 8 MiB of RAM.