#raspbian IRC Log


IRC Log for 2014-04-08

Timestamps are in GMT/BST.

[1:43] <gnarface> http://it.slashdot.org/story/14/04/07/2354258/openssl-bug-allows-attackers-to-read-memory-in-64k-chunks is the patch for this in rasbpian yet?
[7:30] * FlummN is now known as FlummN_away
[8:25] <Pheimors> hello
[8:25] <Pheimors> is there any way to upgrade openssl to avoid the HearBleed bug ?
[8:29] * mythos (~mythos@unaffiliated/mythos) has joined #raspbian
[8:33] <archangel-amael> Pheimors: Take a look at https://security-tracker.debian.org/tracker/CVE-2014-0160
[8:33] <Pheimors> ok, thanks
[8:34] <archangel-amael> Also https://www.openssl.org/news/secadv_20140407.txt
[9:13] * jameswatling (~jameswatl@122-59-246-95.jetstream.xtra.co.nz) Quit (Remote host closed the connection)
[9:13] * form (form@ has joined #raspbian
[9:14] <form> hi. is a patched openssl available yet?
[9:14] * oberstet (~quassel@ppp-188-174-153-5.dynamic.mnet-online.de) has joined #raspbian
[9:14] * FR^2 (~frquadrat@farsquare.de) has joined #raspbian
[9:15] <kruemi> form there does not seem an updated package in raspbian right now. If you REALLY need it (have a raspi on an exposed system acting as ssl enabled server) than take a look at the debian repos
[9:20] * gnarface (~gnarface@108-227-52-42.lightspeed.irvnca.sbcglobal.net) has joined #raspbian
[9:20] * raspiguy (c06d32d9@gateway/web/freenode/ip. has joined #raspbian
[9:20] <gnarface> anyone else keep getting disconnected from freenode?
[9:21] * gcSpitfire (~gcSpitfir@ip-176-198-57-143.unitymediagroup.de) has joined #raspbian
[9:23] <Dagger> kruemi: server or client*
[9:23] * Alina-malina (Alina-mali@unaffiliated/alina-malina) Quit (Read error: Connection reset by peer)
[9:24] <kruemi> Dagger: as far as I can see, updates won't help you much if you're a client (but I could be wrong here)
[9:24] * Alina-malina (Alina-mali@unaffiliated/alina-malina) has joined #raspbian
[9:24] <kruemi> Dagger: Bit I think the server can't spy on you while you're connected by ssl.
[9:24] <kruemi> But
[9:24] <gcSpitfire> hi there
[9:25] <Dagger> the server or an MITM can read the client process's memory
[9:26] <gcSpitfire> sorry if i am probably the 1000th who asked but is version 1.0.1e-2+rvt+deb7u4 affected by the openssl-bug?
[9:26] <gcSpitfire> my guess would be no
[9:26] <Dagger> gcSpitfire: https://security-tracker.debian.org/tracker/CVE-2014-0160 says yes
[9:26] <gcSpitfire> ah bollocks
[9:26] <gnarface> Dagger, gcSpitfire but its changelog says no
[9:27] <kruemi> Dagger: you're right. Sorry for the wron information. Client AND Server memory is exposed.
[9:27] * wiiguy (~fake@unaffiliated/wiiguy) has joined #raspbian
[9:28] <gcSpitfire> gnarface: this is exactly why i am asking here :)
[9:28] <Dagger> oh, there's a +rvt+ there. that Debian page *suggests* yes, then
[9:28] <gcSpitfire> so is there any update to be expected soon?
[9:30] <kruemi> gcSpitfire: I'm sure, the maintainers will address this issue with priority. But there is not ETA known until now. If you're in a hurry I'd suggest to build the package from source
[9:32] <gcSpitfire> kruemi: thanks. i'll consider that :)
[9:33] * gnarface (~gnarface@108-227-52-42.lightspeed.irvnca.sbcglobal.net) Quit (Ping timeout: 255 seconds)
[9:46] * babel (~quassel@2001:41d0:a:25b0::1) has joined #raspbian
[10:01] * pbn (pbn@wopr.geekshells.org) Quit (Ping timeout: 264 seconds)
[10:04] * PeterSilie (~quassel@2605:8900:5000:1001:8:0:6d:2) has joined #raspbian
[10:04] * Sorcier_FXK (~Sorcier_F@unaffiliated/sorcierfxk) has joined #raspbian
[10:04] * ciborg (sid5739@gateway/web/irccloud.com/x-unsnzljexgphearn) has joined #raspbian
[10:04] * Roxxor (57e24bba@gateway/web/freenode/ip. has joined #raspbian
[10:05] * MacArony (~macarony@ca.tdct.org) has joined #raspbian
[10:05] <Roxxor> Hello. About the Openssl bug. I can't find any updates. Somebody knows when it is going to be available? :/
[10:06] <kruemi> Roxxor: I'm sure, the maintainers will address this issue with priority. But there is not ETA known until now. If you're in a hurry I'd suggest to build the package from source
[10:06] <gnarface> Roxxor: you can just disable heartbeats, its pretty easy
[10:06] * pelle2 (~palle@178-132-79-155.cust.azirevpn.net) has joined #raspbian
[10:07] <Roxxor> Hm. Ok. Thank you. Just wanted to know if its maybe also my mistake and the packages are already available. But ok. I just personally use the server. I can wait. Thank you :)
[10:08] <gnarface> Roxxor: no, they're in debian already but there is typically half a day to 2 days delay for propogation into raspbian
[10:09] <Roxxor> A maybe this question: Out of curiosity I enables the debian security repo. Also with it enabled I cant find updates. Does it actually provide armhf packages? Could I run into compatibility issues?
[10:09] <gnarface> you will run into compatibility issues
[10:10] <gnarface> not sure why no packages show up for you but i'm assuming its because its smart enough to know that
[10:10] <gnarface> i thought i'd heard it wasn't but... meh
[10:10] <Roxxor> Ok. Thank you. Going to disable it and drink some tea ;D
[10:10] <Roxxor> Well actually I dont know if its showing packages. Only no updates.
[10:26] * TheOnionRack (~TheOnionR@ Quit (*.net *.split)
[10:26] * Bercik (~Yotsuba@unaffiliated/bercik) Quit (*.net *.split)
[10:26] * kenny (~kenny@rm-rf.ca) Quit (*.net *.split)
[10:32] * djukon (~djukon@50708181.static.ziggozakelijk.nl) has joined #raspbian
[10:33] * gnarface (~gnarface@108-227-52-42.lightspeed.irvnca.sbcglobal.net) Quit (Ping timeout: 240 seconds)
[10:36] <Halberd1> Hello. I'm having troubles instaling the latest dosfstools (3.0.26). I have downloaded a source from Git, but compiling it throws an error "stdio.h": No such file or directory found.
[10:38] * Lupinedk is now known as lupinedk
[10:38] <kruemi> Halberd1: you might have to install the package clang
[11:03] <gordonDrogon> ssh isn't affected by this anyway.
[11:42] * RobCWDudley (robdudley@gateway/shell/blinkenshell.org/x-xnldbrtbcjhjtugb) has joined #raspbian
[11:43] <RobCWDudley> hi all. Does raspian have an OpenSSL update to fix Heartbleed yet?
[11:47] <RobCWDudley> ah, just read back through the logs. Can update from source. Apologies for asking the same question as about a million other people!
[11:49] * stanley (~stan@gateway/tor-sasl/stanley) Quit (Remote host closed the connection)
[11:50] * stanley (~stan@gateway/tor-sasl/stanley) has joined #raspbian
[11:51] * msantana (msantana@unaffiliated/darkstar) has joined #raspbian
[11:54] * ascii_ch (~quassel@147-224.197-178.cust.bluewin.ch) Quit (Remote host closed the connection)
[12:13] * Sorcier_FXK (~Sorcier_F@unaffiliated/sorcierfxk) Quit (Quit: Impossible isn't possible)
[12:16] * Sorcier_FXK (~Sorcier_F@unaffiliated/sorcierfxk) has joined #raspbian
[12:34] * sqrrl (~mj@unaffiliated/squirrel) Quit (Quit:  )
[12:54] * UniOn (~UniOn4@5419C81A.cm-5-2d.dynamic.ziggo.nl) has joined #raspbian
[13:39] * hyp (818443a7@gateway/web/freenode/ip. Quit (Client Quit)
[13:39] <shiftplusone> gnarface, no option to make them call you back instead of waiting on hold?
[13:39] <gnarface> heh, nope
[13:40] <shiftplusone> and no page showing known problems either? =S
[13:40] <Roxxor> gcSpitfire: yeah works. but now I see that it is not complete as openssl is likely no dependency of nginx, but optional. well ok then lets hope that I will remember everything :D thank you :)
[13:40] <gnarface> shiftplusone: oh they got one of those, but the page says there's no problems
[13:40] <shiftplusone> ah
[13:40] <gnarface> i miss speakeasy. they'd send emails
[13:41] <gcSpitfire> Roxxor: maybe you should try and see what depends on "libssl1.0.0" instead
[13:41] <shiftplusone> my local exchange decided to connect me to another port, which failed horribly and I was left without the internet for 4 days. Although my ISP was terrible about communicating the issue, they gave me the next month for free, so I can't complain.
[13:43] <Roxxor> gcSpitfire: ui. long list. Thank you :) that should be complete
[13:43] <gcSpitfire> Roxxor: grep's your friend :)
[13:44] <Roxxor> gcSpitfire: I know, but its just to scroll over if I maybe forgot a server :D if I know what to grep then I also know that I ahve to change the keys :D
[13:44] <gcSpitfire> anyway folks. you don't need to set up an entire new CA after that, do you?
[13:45] <BManojlovic> shiftplusone: it is inside of script which mirror it uses :)
[13:45] <gcSpitfire> i tend to do it anyway though because i am paranoid
[13:46] <Roxxor> Im also paranoid, and from a technical point you should do a new one. I also do it :D
[13:46] <shiftplusone> BManojlovic, heh
[13:46] * ioudas wonders why his pi wont apt update
[13:46] <gnarface> gcSpitfire: i'm not sure, but i think the damage would in theory be limited to private keys that were in memory at the time of any snooping happening, that might be naive though...
[13:58] * TheOnionRack (~TheOnionR@ has joined #raspbian
[13:58] <ioudas> apt-get update and install doesnt work
[13:59] <shiftplusone> did you add any fancy iptables rules or does your router have an aggressive firewall of some kind?
[13:59] * heday_ (~heday@2e40bd4a.skybroadband.com) has joined #raspbian
[13:59] * DarylXian (TFyI1rdWR5@bolt.sonic.net) has joined #raspbian
[14:00] <ioudas> it shouldn't 4 other pi's work fine next to this on same network.. no iptables process running
[14:00] <shiftplusone> =/
[14:00] <shiftplusone> well, I give up.
[14:00] <ioudas> yeah
[14:00] <ioudas> its weird
[14:01] <ioudas> im giving up on these pi's anyway ;-) frigging repeating keys, wifi issues. you name it.
[14:01] <shiftplusone> sure your supply isn't terrible?
[14:31] * messenjah_ is now known as messenjah
[14:49] * XpineX (~XpineX@93-160-241-126-dynamic.dk.customer.tdc.net) has joined #raspbian
[14:49] * diego_ (~diego@248.Red-81-47-179.staticIP.rima-tde.net) has joined #raspbian
[15:36] * DarylXian (TFyI1rdWR5@bolt.sonic.net) Quit (Quit: DarylXian)
[15:36] <sfasdf> sorry connection died
[15:36] <shiftplusone> you didn't miss anything
[15:36] <sfasdf> ha ok
[15:37] <sfasdf> so no idea why openvpn is only using 50% cpu?
[15:38] * mr-jack (~mr-jack@unaffiliated/mr-jack) has joined #raspbian
[15:41] * dougiel (~doug@S0106744401495b56.wp.shawcable.net) has joined #raspbian
[15:41] * Fogest (Fogest@2604:180::1458:e4e6) has joined #raspbian
[15:42] <Darky> nope, maybe you should ask the openvpn guys ( #openvpn on freenode)
[15:48] * DarylXian (8vSPeZODCn@bolt.sonic.net) has joined #raspbian
[15:48] <sfasdf> ok ill try my luck there thanks.
[15:52] <sfasdf> it says I'm banned. WTF??
[15:52] <sfasdf> #openvpn Cannot join channel (+b) - you are banned
[15:52] <sfasdf> do i need to be a registered user to login to #openvpn?
[15:53] <shiftplusone> they blocked the webchat thing you're using
[15:54] <sfasdf> freenode? so i need a client? is there any other webchat they allow?
[15:54] <shiftplusone> just save yourself the trouble and use a client.
[15:55] * user (599ccc1b@gateway/web/freenode/ip. has joined #raspbian
[15:57] * pankid (~pan@c-68-40-250-153.hsd1.mi.comcast.net) has joined #raspbian
[15:58] * sfasdf (6dc99a9c@gateway/web/freenode/ip. has left #raspbian
[15:59] * Fusing (~fusing@ has joined #raspbian
[16:00] * mpmc[BNC4FREE] is now known as mpmc
[16:01] * mike_t (~mike@ Quit (Ping timeout: 240 seconds)
[16:01] * _yoy_ (~YoY@ Quit (Quit: Leaving...)
[16:01] * zGrr (~G@ Quit (Remote host closed the connection)
[16:02] * _yoy_ (~YoY@ has joined #raspbian
[16:03] * hyp (818443a7@gateway/web/freenode/ip. Quit (Quit: Page closed)
[16:04] * mike_t (~mike@ has joined #raspbian
[16:09] * user (599ccc1b@gateway/web/freenode/ip. Quit (Quit: Page closed)
[16:10] * gcSpitfire (~gcSpitfir@ip-176-198-57-143.unitymediagroup.de) Quit (Remote host closed the connection)
[16:11] * dicknutz (cdaaf421@gateway/web/freenode/ip. has joined #raspbian
[16:57] <komodo> k... lemme try
[16:57] <Death_> I'm not 100% sure on the exact numbers, but as far as I remember USB for data will not provide the amount of current the Pie needs to operate well with periphirals and all connected.
[16:58] * rela (~x@pdpc/supporter/active/rela) Quit (Read error: Connection reset by peer)
[16:59] * stationweb (~narsene@ Quit (Quit: stationweb)
[16:59] * Bane^ (~Bane@fsf/member/bane) Quit (Quit: ZNC - http://znc.in)
[16:59] <Darky> a usb connector should give 0.5 - 0.9 A of power, the pi needs 0.7 A to function, more if you use a keyboard, mouse, etc
[17:00] * Bane^ (~Bane@fsf/member/bane) has joined #raspbian
[17:00] <shiftplusone> more importantly, it needs to give 5v at the pi's input over the whole range.
[17:00] <komodo> darky: thank you for that info!!!!
[17:01] <shiftplusone> though 0.7A to function + more for usb comment is nonsense. 0.7A is already taking low power USB devices into account.
[17:01] <komodo> Darky: works perfectly now! Thank you so much
[17:01] <Death_> Isn't USB only 100mA by default Darky?
[17:02] <komodo> wow... seems like a lot of people are upset by what you said Darky :(
[17:02] <shiftplusone> By the specs, a USB port needs to provide 100mA normally, and a minimum of 500mA in high power mode.
[17:02] <Death_> Usb 2.0 is 500mA though. But 1.0 isn't.
[17:02] <Darky> no one uses 1.0 these days
[17:03] * mike_t (~mike@ Quit (Remote host closed the connection)
[17:03] <komodo> well plugging into wall rather than into my usb port on my pc did the trick. stable power now
[17:03] <Death_> You can't assume that when it comes to somebody messing around with a Pi =) Their testing environment/setup could be outdated.
[17:03] <shiftplusone> komodo, 'upset' is a bit strong, heh.
[17:03] <komodo> :)
[17:04] <shiftplusone> lol, you were powering from the PC's USB port AND you had a fan going earlier? D=
[17:04] <komodo> ok... now i am down to my last question for you fine ladies adn gents
[17:04] <komodo> yeah :)
[17:04] <Darky> komodo: correcting or disagreeing with someone isn't a problem
[17:04] <shiftplusone> ouch
[17:04] <Darky> wouldn't say anyone here is upset really
[17:05] <Death_> I'm upset, but that is because I had to deal with the OpenSSL issue all day at work, and now at home for my private servers and labo. :(
[17:05] * shiftplusone hides the pitchfork >.>
[17:05] <komodo> so, i got the Kali linux release for raspberry pi and imaged it to my sd card. it loads up fine, but i notice it doesn't have any of the Kali linux tools installed - lol. Does anyone have any experience with Kali linux or the Kali release for raspberry?
[17:06] <shiftplusone> don't they have a channel?
[17:06] <Death_> I'm a Raspbian guy, sorry.
[17:06] <komodo> hmm.. didn't know they had a channel
[17:08] * stanley (~stan@gateway/tor-sasl/stanley) Quit (Remote host closed the connection)
[17:09] <Darky> after a bit of searching, it looks like the 0.1 A limit applies to the Pi itself, as in you shouldn't draw more than 100 mA from the Pi's usb ports
[17:10] <shiftplusone> without asking
[17:12] <Darky> was referring to <Deat__> Isn't USB only 100mA by default Darky?
[17:14] <shiftplusone> Yeah, I was just adding that a device that draws more should identify itself as such and the host can reject it.
[17:14] * nitdega (nitdega@2602:306:2423:3b71:6c4d:ea56:38a:833f) Quit (Quit: Leaving)
[17:15] * lvispy (~luiz@179-125-129-2.desktop.com.br) has joined #raspbian
[18:07] * spacedentist (~quassel@spacedentist.net) Quit (Remote host closed the connection)
[18:43] <gotmoreshell> Good evening
[18:44] <gotmoreshell> Anyone know when the fix for CVE-2014-0160 will be released for raspbian.
[18:46] <shiftplusone> plugwash hasn't been on or commented about it elsewhere yet
[18:46] * pda (~pda@ has joined #raspbian
[18:46] <Death_> Plugwash has been eliminated by the NSA, their taget has been the Rasp Pi boards all this time.
[18:46] <Death_> Low-power botnet, have to think ecologically.
[18:47] <shiftplusone> heh
[18:48] <gotmoreshell> So might take a while?
[18:48] <shiftplusone> uknown
[18:48] <shiftplusone> *un
[18:48] <gotmoreshell> :(
[18:51] <DarylXian> What are correct CFLAGS opts for "-mtune", "-march" & "-mcpu" for raspbian's gcc? I'm in a chroot, and adding any/all as 'native', 'armv6l' causes a "cc1: error: unrecognized argument in option '-mcpu=native'" error.
[18:52] <DarylXian> this is for RPi.
[18:52] <shiftplusone> haven't tried multiarch though
[18:52] <paultag> It won't fix this issue
[18:53] <shiftplusone> that just works on arm like it does with x86 and amd64?
[18:53] <paultag> since multiarch enabled packages would put into a special lib
[18:53] <paultag> but basically yes
[18:53] <paultag> lib directory*
[18:53] * gotmoreshell (503893b3@gateway/web/freenode/ip. Quit (Ping timeout: 240 seconds)
[18:53] * [SkG] (~Esqueje@unaffiliated/skg/x-897332) Quit (Remote host closed the connection)
[18:53] <shiftplusone> hm, thanks
[18:53] <stanley> What deb-src line do I need to add in order to get the OpenSSL source?
[18:53] <paultag> so you could install libfoo5:armel and libfoo5:armhf
[18:53] <paultag> stanley: apt-get install devscripts
[18:53] <paultag> dget from Debian
[18:53] <paultag> rebuild
[18:53] <paultag> smile smugly
[18:53] <stanley> paultag: What deb-src line do I need to add?
[18:54] <paultag> you don't if you use dget
[18:54] <stanley> Awesome.
[18:54] <stanley> cheers paultag
[18:54] <Death_> Don't forget the smug smile or it won't work.
[18:54] <paultag> ++
[18:54] <paultag> stanley: dget -x http://ftp.de.debian.org/debian/pool/main/o/openssl/openssl_1.0.1g-1.dsc
[18:54] <paultag> stanley: cd into there and you can do your 'thang
[18:55] * stanley is always impressed by the debian array of tools and scripts
[18:55] <stanley> dscverify: can't find any system keyrings
[18:55] <paultag> We've been doing it a while :)
[18:55] <paultag> stanley: might need a -u since it's raspbian
[18:55] <paultag> (don't check)
[18:55] <paultag> Hurm, also that's out of date
[18:55] <paultag> hold on stanley
[18:55] <paultag> you need -2
[18:56] <paultag> stanley: http://incoming.debian.org/openssl_1.0.1g-2.dsc
[18:56] <paultag> That's not even in Debian yet, but that contains emergency fixes that -1 didn't have
[18:56] <stanley> Which one?
[18:56] <paultag> Checking for services to restart and updating that list
[18:57] <paultag> not code-based
[18:57] <paultag> the code fix is sound
[18:57] <Death_> lsof -n | grep ssl | grep DEL
[18:57] <paultag> :)
[18:58] * fknecht (~chatzilla@port-87-193-155-234.static.qsc.de) has joined #raspbian
[18:58] <stanley> I'd like it to verify
[18:58] <Death_> I'm going to create a mock-up image of an IO board I'd love to put next to my Rasp Pi B.
[18:58] <stanley> maybe I need to find the debian keyring package
[18:58] <paultag> stanley: Yeah, apt-get install debian-keyring
[18:58] <paultag> or get Kurt's key by hand
[19:00] <fknecht> Is anyone working on getting this openssl fix out?
[19:00] <stanley> the guy who can do that here isn't around
[19:00] <paultag> Unknown. That's a plugwash question, I don't have any Raspbian rights, just Debian rights
[19:00] <stanley> so instead you should build your own like I am!
[19:02] <stanley> paultag: debuild -rfakeroot -uc -us <-- this fine?
[19:02] <paultag> yeah, that looks great; I use dpkg-buildpackage -us -uc, but that's identical to that, but dpkg-buildpackage does less
[19:02] <paultag> so, go for it! Nice!
[19:03] <paultag> (I'm outdated cruft)
[19:03] <Death_> http://i.imgur.com/vB25SsJ.png
[19:03] <pda> will it be necessary to (re)build libssl also? or just the openssl package?
[19:03] <Death_> mybodyisready.webm
[19:04] <paultag> pda: the openssl package is the source package name, the source package can build many binary packages
[19:04] <stanley> So we don't need libssl recompiled?..
[19:04] <paultag> pda: in particular, openssl builds libssl-{dev,doc}, libssl1.0.0{,-dbg}
[19:15] <orl> it fails on building due to a problem in linking some libs, seems linked to that problem when the libs are not at the end of the line of gcc, but every lines I've found in the makefiles are at the end. Is there something special about building a soft on a RPI?
[19:15] <paultag> pda: http://paste.debian.net/92528/
[19:15] <paultag> pda: odd!
[19:16] <pda> do you have a ~/.gnupg/ directory?
[19:16] <paultag> yes, but not Kurt's key
[19:16] <Death_> I'm really baffled that something as basic as input length validation was failed to be checked in the package. If only there were more hours in a day I'd spend them reading source-code to find Programming 101 mistakes like the one causing massive issues for a lot of SysAdmins in the world today. Not to mention all the users that go ttheir credentials stolen today. :(
[19:16] <paultag> orl: have logs?
[19:16] <pda> pi@raspbmc:~/heartbleed$ dscverify --no-default-keyring --keyring /usr/share/keyrings/debian-keyring.gpg openssl_1.0.1g-1.dsc ; echo $?
[19:16] <pda> openssl_1.0.1g-1.dsc:
[19:16] <pda> Good signature found
[19:16] <pda> validating openssl_1.0.1g.orig.tar.gz
[19:16] <pda> validating openssl_1.0.1g-1.debian.tar.xz
[19:16] <pda> All files validated successfully.
[19:16] <pda> 0
[19:16] <paultag> Oh, meh. It says good signature. Good enough for Government work
[19:16] <pda> just running `mkdir ~/.gnupg/` fixed it
[19:16] <paultag> ah odd
[19:16] <paultag> funky
[19:16] <paultag> most DDs have a GnuPG home, not shocked
[19:17] <paultag> in the mood to file a bug?
[19:17] <orl> paultag: yep, just wait a bit so that I paste them
[19:17] <pda> paultag: where would I file it? This is a raspbmc install of unknown age ;)
[19:17] <paultag> pda: you can email the BTS with your devscripts version (unless it's changed by Raspbian, in which case, we'll have to dupe on a Debian box)
[19:18] <paultag> most of this are unmodified scripts
[19:18] * ioudas curses meru's and pi's
[19:26] <pda> yep I figured it was unstable prerelease style, all good.
[19:26] <shiftplusone> plugwash, there you are.... people have been joining and asking for the heartbleed fix update every few minutes, heh.
[19:27] <plugwash> Yeah, a combination of infrustructure issues and the fact that some manual attention was needed have slowed things down a bit
[19:27] <Death_> Can't blame them, full access to the memory (even at random spots in 64K increments) is a scary thing.
[19:27] <plugwash> it should be out now
[19:28] <plugwash> (the main fix that is, deb7u6 will be a couple more hours)
[19:28] * gotmoreshell (503893b3@gateway/web/freenode/ip. has joined #raspbian
[19:28] <shiftplusone> excellent
[19:28] <pda> might warrant a channel topic?
[19:29] <shiftplusone> plugwash, also, did you modify the raspbian kernel package? I am getting an error when it runs the post-install script. Let me pull up the exact error.
[19:30] <Death_> Get:3 http://mirrordirector.raspbian.org/raspbian/ wheezy/main openssl armhf 1.0.1e-2+rvt+deb7u5 [700 kB]
[19:30] <Death_> confirmed
[19:30] <pda> Candidate: 1.0.1e-2+rvt+deb7u5 <-- is that the fixed one? I'm seeing it from http://archive.raspbian.org now.
[19:31] <Death_> Yeah this is the fixed version
[19:31] <pda> nice
[19:31] <Death_> Don't forget to restart all your services that use openssl.
[19:31] <pda> building 1.0.1f from source anyway l
[19:31] <Death_> lsof -n | grep ssl | grep DEL to get a list
[19:32] <stanley> ditto pda
[19:48] <paultag> SSL*; and the remote servers are the ones that would have the threat against it
[19:49] <paultag> you could in theory dump their private key and then MITM other people with that key
[19:49] <paultag> without an SSL warning
[19:49] * Maxa (~M@unaffiliated/maxa) Quit (Remote host closed the connection)
[19:49] <paultag> so you should enable revocation checking and assume everything on any site with SSL was pwned in the last few days
[19:49] * Fusing (~fusing@ has joined #raspbian
[19:50] <Death_> I'm waiting about a week before resetting all my passwords everywhere. (Next monday) to let all the servers enough time to get updated.
[19:51] * Maxa (~M@unaffiliated/maxa) has joined #raspbian
[19:51] <Death_> As there were a lot of PoCs of userdata being hijacked with the 64K dumps.
[19:51] <paultag> Yep.
[19:52] * plugwash (~plugwash@97e03ff4.skybroadband.com) Quit (Ping timeout: 240 seconds)
[19:53] * plugwash (~plugwash@97e03ff4.skybroadband.com) has joined #raspbian
[19:53] * ChanServ sets mode +o plugwash
[19:54] * Xiguanda (~drtxus@42.Red-81-39-22.dynamicIP.rima-tde.net) has joined #raspbian
[19:57] * foulou (~foulou@gw-tech.lagoon.nc) has joined #raspbian
[20:00] * Fabzgy (~fabzgy@frbg-5f730dd6.pool.mediaWays.net) has joined #raspbian
[20:01] <fknecht> plugwash: thanks for getting this pushed out! I saw that debian pushed out an u6. Only some service restarts though I think
[20:02] * gotmoreshell (503893b3@gateway/web/freenode/ip. Quit (Quit: Page closed)
[20:03] <plugwash> yeah, u6 is on the master server now but I don't like to trigger public repo updates too close together
[20:04] <Death_> People seem to be activly exploiting the bug on un-patched high-profile servers...
[20:04] <plugwash> so i'll just let it go with the next scheduled push
[20:04] * tak30 (~tak30@243.Red-79-158-206.staticIP.rima-tde.net) has joined #raspbian
[20:04] <Death_> Some have reported even getting Credit Card info...
[20:04] <Death_> Scary stuff.
[20:11] <fknecht> generating 8192bit keys on a raspi takes forever... ;)
[20:11] * drwhom (~drwhom@rrcs-74-218-193-10.central.biz.rr.com) Quit (Quit: Leaving)
[21:12] * Marchal (sammy@shell.franken.de) Quit (Ping timeout: 240 seconds)
[21:19] <shiftplusone> BManojlovic, looks good so far. bootstrapped and chrooted without any intervention.
[21:21] <BManojlovic> nice to hear :)
[21:21] <BManojlovic> tested on wheezy so it should work
[21:21] <shiftplusone> I'll see how I go with making it use another toolchain.
[21:31] <pda> stanley: making progress? two hours in, looks like debuild openssl-1.0.1g is running the openssl test suite.
[21:43] <pda> cool
[21:43] * Darky (~Darky@2001:41d0:52:100::407) has joined #raspbian
[21:43] * Darky (~Darky@2001:41d0:52:100::407) Quit (Changing host)
[21:43] * Darky (~Darky@unaffiliated/darky) has joined #raspbian
[21:43] <blapto> This is an amazing bit of kit. Very impressed
[21:46] * lupinedk is now known as Lupinedk
[21:52] * simonnn (~simon@gola.grd.sgsnet.se) has joined #raspbian
[21:56] * osxdude|MBP (~osxdude@unaffiliated/osxdude) has joined #raspbian
These logs were automatically created by RaspbianLogBot on irc.freenode.net using the Java IRC LogBot.