libera/#maemo/ Monday, 2020-11-16

untakenstupidnicis there a way to install stuff on home? n900 bootloops often and i keep losing the programs. you can't make a backup every second.01:01
xmnThere is a home.plugins file I've backup for such situations. /home/user/.config/hildon-desktop01:03
xmnlets me instantly restore my desktop widgets01:03
xmnif thats what you were talking about01:03
untakenstupidnicit keeps stuck on boot spontaneously, and it would often be fixed by re-plugging the battery (suggesting it is a non-fatal, mundane problem) but no one seems to know why it happens, so i have to flash it again and again and again and i'm tired of reinstalling all the stuff for some crazy problem in a random system file.01:09
xmndoes it happen on a fresh flash?01:15
HtheBGuys, is tmo down?01:51
HtheBit gives a database error01:52
xmnconfirmed. Everything else seems to still be fine01:59
KotCzarnywell, thats new on tmo:06:17
KotCzarnyContent Encoding Error06:17
KotCzarnyThe page you are trying to view cannot be shown because it uses an invalid or unsupported form of compression.06:17
KotCzarnyPlease contact the website owners to inform them of this problem.06:17
KotCzarnyxes?06:18
Maxdamantus> MySQL Error   : The table 'vb3_session' is full06:48
MaxdamantusThough I'm interested in why Firefox gets that content encoding error.06:48
MaxdamantusOh, I see.06:53
MaxdamantusContent-Encoding: gzip^M06:53
Maxdamantusbut the response is not gzip.06:53
MaxdamantusAnnoying how Firefox's developer tools behaves with such errors; it just says "No headers for this request", so can't see the request or response headers.06:55
xesKotCzarny: hi! tmo is up again09:44
xmnsweet09:56
KotCzarnythanks!10:10
KotCzarny:)10:10
untakenstupidnicwhat caused the problem?10:15
sixwheeledbeasti am getting "too busy" on tmo10:30
sixwheeledbeastare you sure this bootloop isn't a faulty battery. I mean unless your doing silly things to root I wouldn't expect bootloops to occur. Maybe there is some unusual hardware fault.10:32
sixwheeledbeast~bootloop10:32
infoboti guess bootloop is when your device has broken rootfilesystem, so during reboot it fails on some service startup or kernel module load and thus reboots. This *drains* battery! And you can't reflash to stop bootloop when battery is drained. Recharge your battery by other means before reflashing. E.g. using ~rescueOS. Or external charger or BL-5J compatible other device.10:32
xesnotice: tmo web service has been stopped while monitoring the storm in progress11:05
sixwheeledbeastddos?11:19
sixwheeledbeastoh maybe broken db? from posts above11:20
xesnope. storm of requests. At the moment is again active only with https11:27
KotCzarnyhttps://sneak.berlin/20201112/your-computer-isnt-yours/11:45
KotCzarnynice11:45
bencoh"Dear Frog, This Water Is Now Boiling" <311:49
warfareKotCzarny: sneak.berlin doesn't understand OCSP. https://blog.jacopo.io/en/post/apple-ocsp/ has a more detailed writeup.12:10
KotCzarnywarfare: idea is its not about ocsp, its about sending it unencrypted, which allows spying by 3rd parties12:11
warfareocsp has to be unencrypted because using a tls connection would require another ocsp request.12:12
KotCzarnywhich essentially makes it privacy hole12:12
warfareWell, you could add some fake ocsp requests, but all in all, you have to start somewhere ;)12:15
MaxdamantusPresumably you could just expect the OCSP server to include a stapled OCSP response.12:27
MaxdamantusI suspect it's not encrypted because there are plenty of other ways of finding that information.12:28
Maxdamantuseg, most obviously SNI, but afaik the server certificate itself is sent unencrypted when establishing a TLS connection.12:29
MaxdamantusI can confirm that at least by default by looking at `strace openssl s_client -connect google.com:443`12:32
bencohI'm not certain OCSP here refers only to OCSP as we know it in the ssl/tls context12:42
bencohas in, they use it to check dev/app certs/sigs as well12:43
bencohthere is basically no reason to send those requests as plaintext12:43
warfareThere is. TLS overhead time- and cpuwise. And actually I don't care if my os checks every now and then (because the result is cached) if certain developer certificates are still valid.13:11
warfareAlso, you can't use existing OCSP implementations and would have to roll your own. And thats always a bad idea with anything crypto related.13:12
bencohfor this part they probably 1. implemented by themselves already 2. probably just relay the http(s) request to another layer13:38
peterleinchenxes, thanks for fixing TMO22:51
peterleinchen(once more)22:51

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!