#raspbian IRC Log


IRC Log for 2014-04-08

Timestamps are in GMT/BST.

[1:43] <gnarface> http://it.slashdot.org/story/14/04/07/2354258/openssl-bug-allows-attackers-to-read-memory-in-64k-chunks is the patch for this in rasbpian yet?
[2:15] <gnarface> sorry, i got disconnected there, if anyone responded
[2:16] <gnarface> raspbian patch for the hearbleed openssl vuln?
[5:35] * lupinedk is now known as Lupinedk
[6:43] <stanley> Hi, when will Raspbian have Heartbleed fixes out?
[6:44] <stanley> for openssl
[6:44] <stanley> http://heartbleed.com/ https://www.openssl.org/news/secadv_20140407.txt
[7:01] * joat (~joat@ip70-160-158-40.hr.hr.cox.net) Quit (Read error: Operation timed out)
[7:57] * mythos (~mythos@unaffiliated/mythos) has joined #raspbian
[9:14] <form> hi. is a patched openssl available yet?
[9:14] * oberstet (~quassel@ppp-188-174-153-5.dynamic.mnet-online.de) has joined #raspbian
[9:14] * FR^2 (~frquadrat@farsquare.de) has joined #raspbian
[9:15] <kruemi> form there does not seem an updated package in raspbian right now. If you REALLY need it (have a raspi on an exposed system acting as ssl enabled server) than take a look at the debian repos
[9:20] * gnarface (~gnarface@108-227-52-42.lightspeed.irvnca.sbcglobal.net) has joined #raspbian
[9:20] * raspiguy (c06d32d9@gateway/web/freenode/ip. has joined #raspbian
[9:20] <gnarface> anyone else keep getting disconnected from freenode?
[9:21] * gcSpitfire (~gcSpitfir@ip-176-198-57-143.unitymediagroup.de) has joined #raspbian
[9:23] <Dagger> kruemi: server or client*
[9:23] * Alina-malina (Alina-mali@unaffiliated/alina-malina) Quit (Read error: Connection reset by peer)
[9:24] <kruemi> Dagger: as far as I can see, updates won't help you much if you're a client (but I could be wrong here)
[9:24] * Alina-malina (Alina-mali@unaffiliated/alina-malina) has joined #raspbian
[9:24] <kruemi> Dagger: Bit I think the server can't spy on you while you're connected by ssl.
[9:24] <kruemi> But
[9:24] <gcSpitfire> hi there
[9:25] <Dagger> the server or an MITM can read the client process's memory
[9:26] <gcSpitfire> sorry if i am probably the 1000th who asked but is version 1.0.1e-2+rvt+deb7u4 affected by the openssl-bug?
[9:26] <gcSpitfire> my guess would be no
[9:26] <Dagger> gcSpitfire: https://security-tracker.debian.org/tracker/CVE-2014-0160 says yes
[9:26] <gcSpitfire> ah bollocks
[9:26] <gnarface> Dagger, gcSpitfire but its changelog says no
[9:27] <kruemi> Dagger: you're right. Sorry for the wron information. Client AND Server memory is exposed.
[9:27] * wiiguy (~fake@unaffiliated/wiiguy) has joined #raspbian
[9:28] <gcSpitfire> gnarface: this is exactly why i am asking here :)
[9:28] <Dagger> oh, there's a +rvt+ there. that Debian page *suggests* yes, then
[9:28] <gcSpitfire> so is there any update to be expected soon?
[9:30] <kruemi> gcSpitfire: I'm sure, the maintainers will address this issue with priority. But there is not ETA known until now. If you're in a hurry I'd suggest to build the package from source
[9:32] <gcSpitfire> kruemi: thanks. i'll consider that :)
[9:33] * gnarface (~gnarface@108-227-52-42.lightspeed.irvnca.sbcglobal.net) Quit (Ping timeout: 255 seconds)
[9:50] <kruemi> tedaldi@Laserschrank ~ $ openssl version
[9:50] <kruemi> OpenSSL 1.0.1e 11 Feb 2013
[9:50] * mfa298__ (~mfa298@gateway.yapd.net) has joined #raspbian
[9:50] <kruemi> ok, we're screwed :)
[9:50] <Dagger> for Debian you need +deb7u5
[9:50] <gcSpitfire> OpenSSL 1.0.1e 11 Feb 2013
[9:51] <gcSpitfire> yep, we are, kruemi :)
[10:05] <Roxxor> Hello. About the Openssl bug. I can't find any updates. Somebody knows when it is going to be available? :/
[10:06] <kruemi> Roxxor: I'm sure, the maintainers will address this issue with priority. But there is not ETA known until now. If you're in a hurry I'd suggest to build the package from source
[10:06] <gnarface> Roxxor: you can just disable heartbeats, its pretty easy
[10:06] * pelle2 (~palle@178-132-79-155.cust.azirevpn.net) has joined #raspbian
[10:07] <Roxxor> Hm. Ok. Thank you. Just wanted to know if its maybe also my mistake and the packages are already available. But ok. I just personally use the server. I can wait. Thank you :)
[10:08] <gnarface> Roxxor: no, they're in debian already but there is typically half a day to 2 days delay for propogation into raspbian
[10:09] <Roxxor> A maybe this question: Out of curiosity I enables the debian security repo. Also with it enabled I cant find updates. Does it actually provide armhf packages? Could I run into compatibility issues?
[10:09] <gnarface> you will run into compatibility issues
[10:10] <gnarface> not sure why no packages show up for you but i'm assuming its because its smart enough to know that
[10:10] <gnarface> i thought i'd heard it wasn't but... meh
[10:10] <Roxxor> Ok. Thank you. Going to disable it and drink some tea ;D
[10:10] <Roxxor> Well actually I dont know if its showing packages. Only no updates.
[11:43] <RobCWDudley> hi all. Does raspian have an OpenSSL update to fix Heartbleed yet?
[11:47] <RobCWDudley> ah, just read back through the logs. Can update from source. Apologies for asking the same question as about a million other people!
[11:49] * stanley (~stan@gateway/tor-sasl/stanley) Quit (Remote host closed the connection)
[11:50] * stanley (~stan@gateway/tor-sasl/stanley) has joined #raspbian
[11:51] * msantana (msantana@unaffiliated/darkstar) has joined #raspbian
[11:54] * ascii_ch (~quassel@147-224.197-178.cust.bluewin.ch) Quit (Remote host closed the connection)
[13:46] <gcSpitfire> gnarface: that's my guess aswell
[13:46] <shiftplusone> ioudas, didn't you ask and run that yesterday in #raspberrypi? Can you ping the server and can you browse the repo in your browsser?
[13:47] <shiftplusone> *browser
[13:47] <ioudas> I did
[13:47] <gnarface> Roxxor: i *think* you can also just say "aptitude why libssl1.0.0"
[13:47] <ioudas> sorry didnt see your response.....
[13:48] <gnarface> Roxxor: aptitude is seriously slow though
[13:48] * stackofcats (~stackofca@unaffiliated/stackofcats) Quit (Remote host closed the connection)
[13:48] * nicdev` is now known as nicdev
[13:48] * stanley (~stan@gateway/tor-sasl/stanley) Quit (Remote host closed the connection)
[13:48] <shiftplusone> ioudas, pastebin the whole output when you run the update.
[13:48] <ioudas> can browse the repo, not locally on the pi.... as it doesnt have any browsers un able to ping
[13:49] <ioudas> rgr
[13:49] * stanley (~stan@gateway/tor-sasl/stanley) has joined #raspbian
[13:49] <ioudas> shiftplusone, do you have any wifi experience with deauth packets btw?
[13:49] <shiftplusone> none
[13:49] <Roxxor> I dont have aptitude at all O.o (actually using xbian which is based on raspbian) But the apt-cache works good :)
[13:49] <ioudas> http://pastebin.com/eNMKB2P4
[13:50] <shiftplusone> thanks
[13:50] <shiftplusone> can you ping google?
[13:51] <ioudas> i cannot, but i can reach ntp remotely
[13:51] <shiftplusone> what about the router, can you ping that or the other computers on your network?
[13:51] <kruemi> shiftplusone: can you ping ?
[13:52] * stanley (~stan@gateway/tor-sasl/stanley) Quit (Remote host closed the connection)
[13:52] <ioudas> yes
[13:52] * stanley (~stan@gateway/tor-sasl/stanley) has joined #raspbian
[13:52] <gnarface> Roxxor: aptitude only seems to list one entry anyway. i must be wrong about what that's for.
[13:53] <shiftplusone> strange
[13:53] <shiftplusone> kruemi, I am not the one having issues, heh
[13:53] <kruemi> ioudas: so you can reach the router and stuff? what dies route -n look like?
[13:53] <kruemi> shiftplusone: i've just realized. Sorry!
[13:53] <ioudas> route -n looks like the 4 other pi's that work
[13:53] <ioudas> next to this pi
[13:53] <ioudas> route to its own network
[13:53] <kruemi> ioudas: no ?
[13:53] <ioudas> i can reach internal networks and router
[13:53] <ioudas> root@raspberrypi:/home/pi# route -n
[13:53] <ioudas> Kernel IP routing table
[13:53] <ioudas> Destination Gateway Genmask Flags Metric Ref Use Iface
[13:53] <ioudas> UG 0 0 0 wlan0
[13:53] <ioudas> U 0 0 0 wlan0
[13:54] <kruemi> ok... is your router?
[13:54] <kruemi> ioudas: and ping ?
[13:54] <gnarface> clever not putting it at the end of the range...
[13:54] <ioudas> nothing no icmp.
[13:55] <gnarface> ioudas: what about traceroute -T?
[13:56] <ioudas> root@raspberrypi:/home/pi# traceroute -T
[13:56] <ioudas> traceroute to (, 30 hops max, 60 byte packets
[13:56] <ioudas> 1 wlan-controller.nrfdist.local ( 10.796 ms 10.499 ms 10.343 ms
[13:56] <ioudas> 2 ( 7.395 ms 7.170 ms 15.794 ms
[13:56] <ioudas> 3 google-public-dns-a.google.com ( 19.808 ms 19.557 ms 19.243 ms
[13:56] <gnarface> that's fine... weird
[13:56] <gnarface> almost suspiciously so
[13:56] <kruemi> ioudas: ok. DNS works, UDP as well..
[13:57] <gnarface> wait, so what *doesn't* work?
[13:57] <gnarface> just updates?
[13:57] <gnarface> maybe you got a bad mirror ?
[13:58] <shiftplusone> can you wget stuff?
[13:58] <gnarface> it could be hosted on att...
[13:58] * kruemi (~tedaldi@hifo-intranet.uzh.ch) Quit (Quit: "have a nice evening")
[13:58] <ioudas> i cannot
[13:58] * TheOnionRack (~TheOnionR@ has joined #raspbian
[13:58] <ioudas> apt-get update and install doesnt work
[13:59] <shiftplusone> did you add any fancy iptables rules or does your router have an aggressive firewall of some kind?
[13:59] * heday_ (~heday@2e40bd4a.skybroadband.com) has joined #raspbian
[13:59] * DarylXian (TFyI1rdWR5@bolt.sonic.net) has joined #raspbian
[14:00] <ioudas> it shouldn't 4 other pi's work fine next to this on same network.. no iptables process running
[14:00] <shiftplusone> =/
[14:00] <shiftplusone> well, I give up.
[14:00] <ioudas> yeah
[14:00] <ioudas> its weird
[14:01] <ioudas> im giving up on these pi's anyway ;-) frigging repeating keys, wifi issues. you name it.
[14:01] <shiftplusone> sure your supply isn't terrible?
[14:02] * hyp (818443a7@gateway/web/freenode/ip. has joined #raspbian
[14:02] <ioudas> yeah, weve tried multiple power supplies
[14:02] <ioudas> right now these 5 pi's will also just drop, send a deauth packet
[14:02] <ioudas> and reconnect
[14:03] <ioudas> got a lot of other issues.
[14:03] <gnarface> eh, i suspect that many wifi cards need more power than the usb ports on the pi can provide in order to go into high power mode
[14:03] <ioudas> thats the problem with pi's
[14:03] <ioudas> usb
[14:03] <gnarface> mine won't stay connected to the wifi reliably unless its within about 3 feet of the wifi router
[14:03] <ioudas> yeah
[14:03] <ioudas> exactly
[14:04] <shiftplusone> are you guys using the little 'nano' wifi adapters?
[14:04] <ioudas> i need to find another embedded pc
[14:04] <gnarface> a powered hub for ... each of them... would solve the issue :(
[14:04] * stackofcats (~stackofca@unaffiliated/stackofcats) has joined #raspbian
[14:04] <gnarface> shiftplusone: yea mine cost 9$
[14:04] <ioudas> i have the wifi issues with a powered hub
[14:04] <gnarface> ioudas: really? damn.
[14:04] <ioudas> i actually have an antenna based one rtl8192cu
[14:04] * gnarface was hoping to try the usb hub solution
[14:04] <ioudas> lb link directly from adafruit
[14:04] <shiftplusone> I found those adapters to be terrible all around. Even on the PC.
[14:05] <gnarface> i'm just using that cheap d-link one.
[14:05] <gnarface> can't complain for what i paid
[14:05] <ioudas> im going to deploy two laptops with the lblink
[14:05] <gnarface> mostly i use the ethernet anyway
[14:05] <ioudas> we will see if they drop
[14:05] <ioudas> send deauths
[14:06] <DarylXian> ioudas: re "find another embedded pc", do you have a price point? similar to RPi? or 'just works' ?
[14:06] <ioudas> price point doesnt matter much when it doesnt work.
[14:06] <gnarface> beagleboard black seems to be popular... only 10$ more i think but the video card is limited to 8MB
[14:06] <ioudas> working on that actually today
[14:07] <DarylXian> I switched to these, http://utilite-computer.com/web/utilite-models . a little pricey, but solid as a rock.
[14:07] <ioudas> hmm
[14:07] <ioudas> i dont like that
[14:08] * Jamazia (Jamazia@2604:180::ad4a:14bd) Quit (Changing host)
[14:08] * Jamazia (Jamazia@unaffiliated/jamazia) has joined #raspbian
[18:43] <gotmoreshell> Good evening
[18:44] <gotmoreshell> Anyone know when the fix for CVE-2014-0160 will be released for raspbian.
[18:46] <shiftplusone> plugwash hasn't been on or commented about it elsewhere yet
[18:46] * pda (~pda@ has joined #raspbian
[18:46] <Death_> Plugwash has been eliminated by the NSA, their taget has been the Rasp Pi boards all this time.
[18:46] <Death_> Low-power botnet, have to think ecologically.
[18:47] <shiftplusone> heh
[18:48] <gotmoreshell> So might take a while?
[18:48] <shiftplusone> uknown
[18:48] <shiftplusone> *un
[18:48] <gotmoreshell> :(
[18:51] <DarylXian> What are correct CFLAGS opts for "-mtune", "-march" & "-mcpu" for raspbian's gcc? I'm in a chroot, and adding any/all as 'native', 'armv6l' causes a "cc1: error: unrecognized argument in option '-mcpu=native'" error.
[18:52] <DarylXian> this is for RPi.
[18:52] <shiftplusone> haven't tried multiarch though
[18:52] <paultag> It won't fix this issue
[18:53] <shiftplusone> that just works on arm like it does with x86 and amd64?
[18:53] <paultag> since multiarch enabled packages would put into a special lib
[18:53] <paultag> but basically yes
[18:53] <paultag> lib directory*
[18:53] * gotmoreshell (503893b3@gateway/web/freenode/ip. Quit (Ping timeout: 240 seconds)
[18:53] * [SkG] (~Esqueje@unaffiliated/skg/x-897332) Quit (Remote host closed the connection)
[18:53] <shiftplusone> hm, thanks
[18:53] <stanley> What deb-src line do I need to add in order to get the OpenSSL source?
[18:53] <paultag> so you could install libfoo5:armel and libfoo5:armhf
[18:53] <paultag> stanley: apt-get install devscripts
[18:53] <paultag> dget from Debian
[18:53] <paultag> rebuild
[18:53] <paultag> smile smugly
[18:53] <stanley> paultag: What deb-src line do I need to add?
[18:54] <paultag> you don't if you use dget
[18:54] <stanley> Awesome.
[18:54] <stanley> cheers paultag
[18:54] <Death_> Don't forget the smug smile or it won't work.
[18:54] <paultag> ++
[18:54] <paultag> stanley: dget -x http://ftp.de.debian.org/debian/pool/main/o/openssl/openssl_1.0.1g-1.dsc
[18:54] <paultag> stanley: cd into there and you can do your 'thang
[18:55] * stanley is always impressed by the debian array of tools and scripts
[18:55] <stanley> dscverify: can't find any system keyrings
[18:55] <paultag> We've been doing it a while :)
[18:55] <paultag> stanley: might need a -u since it's raspbian
[18:55] <paultag> (don't check)
[18:55] <paultag> Hurm, also that's out of date
[18:55] <paultag> hold on stanley
[18:55] <paultag> you need -2
[18:56] <paultag> stanley: http://incoming.debian.org/openssl_1.0.1g-2.dsc
[18:56] <paultag> That's not even in Debian yet, but that contains emergency fixes that -1 didn't have
[18:56] <stanley> Which one?
[18:56] <paultag> Checking for services to restart and updating that list
[18:57] <paultag> not code-based
[18:57] <paultag> the code fix is sound
[18:57] <Death_> lsof -n | grep ssl | grep DEL
[18:57] <paultag> :)
[18:58] * fknecht (~chatzilla@port-87-193-155-234.static.qsc.de) has joined #raspbian
[18:58] <stanley> I'd like it to verify
[18:58] <Death_> I'm going to create a mock-up image of an IO board I'd love to put next to my Rasp Pi B.
[18:58] <stanley> maybe I need to find the debian keyring package
[18:58] <paultag> stanley: Yeah, apt-get install debian-keyring
[18:58] <paultag> or get Kurt's key by hand
[19:00] <fknecht> Is anyone working on getting this openssl fix out?
[19:00] <stanley> the guy who can do that here isn't around
[19:00] <paultag> Unknown. That's a plugwash question, I don't have any Raspbian rights, just Debian rights
[19:00] <stanley> so instead you should build your own like I am!
[19:02] <stanley> paultag: debuild -rfakeroot -uc -us <-- this fine?
[19:02] <paultag> yeah, that looks great; I use dpkg-buildpackage -us -uc, but that's identical to that, but dpkg-buildpackage does less
[19:02] <paultag> so, go for it! Nice!
[19:03] <paultag> (I'm outdated cruft)
[19:03] <Death_> http://i.imgur.com/vB25SsJ.png
[19:03] <pda> will it be necessary to (re)build libssl also? or just the openssl package?
[19:03] <Death_> mybodyisready.webm
[19:04] <paultag> pda: the openssl package is the source package name, the source package can build many binary packages
[19:04] <stanley> So we don't need libssl recompiled?..
[19:04] <paultag> pda: in particular, openssl builds libssl-{dev,doc}, libssl1.0.0{,-dbg}
[19:04] <stanley> They seem to be separate packages
[19:04] <paultag> and openssl
[19:04] <stanley> oh ok
[19:05] <paultag> reinstalling the debs you have installed that openssl builds is advised
[19:05] <pda> paultag: good to know, thanks.
[19:05] <paultag> stuff like -dev and -dbg are likely fine to omit, because you likely don't have them installed
[19:05] * yano (~yano@freenode/staff/yano) Quit (Quit: WeeChat, The Better IRC Client -- http://weechat.org/)
[19:05] <paultag> (but basically, debs to source packages is a 1-to-N relation)
[19:06] * lupinedk is now known as Lupinedk
[19:06] <Death_> So what did you guys think of my Rasp Pi new IO mockup for 10 PI CM boards?
[19:06] <paultag> Death_: looks nuts :)
[19:06] <pda> Death_: want. then again, it'd be ~$400, right?
[19:07] * yano (~yano@freenode/staff/yano) has joined #raspbian
[19:08] <fknecht> stanley: ok, let us know when you succeeded and maybe give a short recap?
[19:08] <stanley> Okay :)
[19:08] <Death_> True, but it would be great for a project to really get more out of a small pi cluster. There's no 10/100 ethernet capping the performance.
[19:08] <paultag> stanley: thanks for doing that; nice work pushing through the basics of building a deb :)
[19:08] <paultag> really impressive that you got it so quickly, actually
[19:08] <stanley> it is exciting paultag
[19:08] <paultag> if I can convince you to do some Debian work, let me know when I can start to bribe you :)
[19:09] <pda> Death_: how would they talk? I was thinking the IO board would have an onboard ethernet controller/switch.
[19:09] <stanley> I think it's pretty cool how it's automated and the work that goes into it. I absolutely hate compiling from source and having it spray binaries everywhere
[19:09] <paultag> :)
[19:09] <paultag> It's really nice, aye!
[19:09] <stanley> as for Debian work, I'd be up for it although I don't know what I could offer
[19:09] <Death_> pda I was thinking more in the way that one CM would be the "master" and manages the others or something along those lines
[19:09] <pda> I also hit `Validation FAILED!!` from dget. debian-keyring package installed.
[19:10] * Lupinedk is now known as lupinedk
[19:10] <paultag> You've got packging basics down; starting out doing patches or debianizing something you use a lot would be neat things to do, stanley
[19:10] <paultag> pda: what does dscverify say when you run it over it?
[19:10] <paultag> it should try /usr/share/keyrings/debian-keyring.gpg
[19:10] <paultag> (check to make sure that is there)
[19:11] <pda> oh - maybe I need gpg set up better? ...
[19:11] <paultag> Nah, it should do that for you
[19:11] <pda> dscverify: openssl_1.0.1g-1.dsc failed signature check:
[19:11] <pda> gpg: keyblock resource `/home/pi/.gnupg/secring.gpg': file open error
[19:11] <pda> gpg: Signature made Mon Apr 7 14:34:36 2014 PDT using RSA key ID 1A5522DD
[19:11] <pda> gpg: fatal: /home/pi/.gnupg: directory does not exist!
[19:11] * astrapotro (~mikel@33.85-87-8.dynamic.clientes.euskaltel.es) has joined #raspbian
[19:11] <paultag> try --keyring /usr/share/keyrings/debian-keyring.gpg
[19:12] <pda> `dscverify --keyring /usr/share/keyrings/debian-keyring.gpg openssl_1.0.1g-1.dsc` gives same error, it's trying to open /home/pi/.gnupg/secring.gpg
[19:12] * DarylXian (6E1YvXmRmF@bolt.sonic.net) Quit (Quit: DarylXian)
[19:12] <paultag> --no-default-keyring in there perhaps
[19:13] <paultag> does /usr/share/keyrings/debian-keyring.gpg exist?
[19:13] * orl (~orl@lns-bzn-48f-81-56-240-95.adsl.proxad.net) has joined #raspbian
[19:13] <orl> Hi!
[19:13] <orl> I'm trying to build QLC+ on a RPI with Raspbian installed on it.
[19:13] <pda> paultag: yep `-rw-r--r-- 1 root root 45859871 Apr 21 2013 /usr/share/keyrings/debian-keyring.gpg` exists, and adding --no-default-keyring gives the same error
[19:14] <paultag> try before --keyring
[19:14] <paultag> and what's it's $? # ?
[19:14] <pda> yep it was this: `dscverify --no-default-keyring --keyring /usr/share/keyrings/debian-keyring.gpg openssl_1.0.1g-1.dsc`
[19:14] <pda> paultag: $? = 1
[19:14] <paultag> hurm
[19:14] * paultag tries
[19:15] <pda> I'm afraid debian/ubuntu's package infrastructure works so well normally that I'm lost when it comes to these tools :)
[19:15] <orl> it fails on building due to a problem in linking some libs, seems linked to that problem when the libs are not at the end of the line of gcc, but every lines I've found in the makefiles are at the end. Is there something special about building a soft on a RPI?
[19:15] <paultag> pda: http://paste.debian.net/92528/
[19:15] <paultag> pda: odd!
[19:16] <pda> do you have a ~/.gnupg/ directory?
[19:16] <paultag> yes, but not Kurt's key
[19:16] <Death_> I'm really baffled that something as basic as input length validation was failed to be checked in the package. If only there were more hours in a day I'd spend them reading source-code to find Programming 101 mistakes like the one causing massive issues for a lot of SysAdmins in the world today. Not to mention all the users that go ttheir credentials stolen today. :(
[19:16] <paultag> orl: have logs?
[19:16] <pda> pi@raspbmc:~/heartbleed$ dscverify --no-default-keyring --keyring /usr/share/keyrings/debian-keyring.gpg openssl_1.0.1g-1.dsc ; echo $?
[19:16] <pda> openssl_1.0.1g-1.dsc:
[19:16] <pda> Good signature found
[19:16] <pda> validating openssl_1.0.1g.orig.tar.gz
[19:16] <pda> validating openssl_1.0.1g-1.debian.tar.xz
[19:16] <pda> All files validated successfully.
[19:16] <pda> 0
[19:16] <paultag> Oh, meh. It says good signature. Good enough for Government work
[19:16] <pda> just running `mkdir ~/.gnupg/` fixed it
[19:16] <paultag> ah odd
[19:16] <paultag> funky
[19:16] <paultag> most DDs have a GnuPG home, not shocked
[19:17] <paultag> in the mood to file a bug?
[19:17] <orl> paultag: yep, just wait a bit so that I paste them
[19:17] <pda> paultag: where would I file it? This is a raspbmc install of unknown age ;)
[19:17] <paultag> pda: you can email the BTS with your devscripts version (unless it's changed by Raspbian, in which case, we'll have to dupe on a Debian box)
[19:18] <paultag> most of this are unmodified scripts
[19:18] * ioudas curses meru's and pi's
[19:20] * osxdude|MBP (~osxdude@unaffiliated/osxdude) has joined #raspbian
[19:21] * pizza-dude (~fake@92-108-164-28.dynamic.upc.nl) Quit (Quit: I just broke my connection, but no worries, we can rebuild it. We have the technology.)
[19:22] * v0lt_ (~textual@unaffiliated/v0lt/x-7782577) Quit (Quit: gone)
[19:22] <orl> pauldag: http://paste.debian.net/92533/
[19:22] <Death_> My Debian box was never exposed to this openssl issue, as it has been disconnected from RJ45 and power since 1.5 year.
[19:23] <Death_> Which reminds me, I should connect it again.
[19:23] * Death_ tried to ssh/ping for 2 minutes before checking if power was on
[19:23] * pankid (~pan@c-68-40-250-153.hsd1.mi.comcast.net) Quit (Ping timeout: 250 seconds)
[19:25] * kensanata (~user@fsf/member/kensanata) has joined #raspbian
[19:25] <pda> paultag: FYI that http://incoming.debian.org/openssl_1.0.1g-2.dsc URL 404'd a few times before working.
[19:25] <fknecht> I have 16 boxes affected by this... Half of them raspbian, half debian. Half are fixed now
[19:25] <paultag> It was likely being rebuilt
[19:25] <paultag> That's not for users or developers
[19:25] <paultag> that's there for the Debian buildds to use when doing builds
[19:25] * plugwash (~plugwash@97e03ff4.skybroadband.com) has joined #raspbian
[19:25] * ChanServ sets mode +o plugwash
[19:26] <paultag> it's just that -2 isn't on on the mirror I was checking against at the time
[19:26] <paultag> so you can use that for now
[19:26] <pda> yep I figured it was unstable prerelease style, all good.
[19:26] <shiftplusone> plugwash, there you are.... people have been joining and asking for the heartbleed fix update every few minutes, heh.
[19:27] <plugwash> Yeah, a combination of infrustructure issues and the fact that some manual attention was needed have slowed things down a bit
[19:27] <Death_> Can't blame them, full access to the memory (even at random spots in 64K increments) is a scary thing.
[19:27] <plugwash> it should be out now
[19:28] <plugwash> (the main fix that is, deb7u6 will be a couple more hours)
[19:28] * gotmoreshell (503893b3@gateway/web/freenode/ip. has joined #raspbian
[19:28] <shiftplusone> excellent
[19:28] <pda> might warrant a channel topic?
[19:29] <shiftplusone> plugwash, also, did you modify the raspbian kernel package? I am getting an error when it runs the post-install script. Let me pull up the exact error.
[19:30] <Death_> Get:3 http://mirrordirector.raspbian.org/raspbian/ wheezy/main openssl armhf 1.0.1e-2+rvt+deb7u5 [700 kB]
[19:30] <Death_> confirmed
[19:30] <pda> Candidate: 1.0.1e-2+rvt+deb7u5 <-- is that the fixed one? I'm seeing it from http://archive.raspbian.org now.
[19:31] <Death_> Yeah this is the fixed version
[19:31] <pda> nice
[19:31] <Death_> Don't forget to restart all your services that use openssl.
[19:31] <pda> building 1.0.1f from source anyway l
[19:31] <Death_> lsof -n | grep ssl | grep DEL to get a list
[19:32] <stanley> ditto pda
[19:32] <Defiant> Death_: Don't forget to generate new keys before restarting..
[19:32] <pda> interesting, wifi (wpa_supplicant) is using it. makes sense I guess.
[19:32] <Death_> restart service => generate keys => restart service is what I'm planning
[19:33] * lupinedk is now known as Lupinedk
[19:33] <fknecht> isnt there a U6 that does restart some services?
[19:34] <orl> wow, I miss my ping
[19:34] <orl> @paultag: http://paste.debian.net/92533/
[19:35] <paultag> looks like you're not linking against something you should
[19:35] <paultag> or something
[19:35] * Lupinedk is now known as lupinedk
[19:36] <orl> yes, that's what I think too
[19:36] <gotmoreshell> Mirrors down?
[19:37] <orl> but looking at the makefiles, it's supposed to be OK
[19:37] * pr3d (4e361032@gateway/web/freenode/ip. Quit (Ping timeout: 240 seconds)
[19:37] <orl> this problem is likely to happen when you don't put the libs at the end of you gcc command
[19:37] <orl> and actually, I was able to build it on a debian jessie without any trouble
[19:37] <orl> that's why I wondered
[19:38] * trisi (~trisi@63-140-101-34.dynamic.dsl.acsalaska.net) Quit (Ping timeout: 240 seconds)
[19:39] <Death_> It still looks like some companies don't take this issue very serious.
[19:40] <plugwash> gotmoreshell, not that i'm aware of but I don't closely track all mirrors
[19:40] <plugwash> are you experiancing issues
[19:41] <gotmoreshell> Yes. Let me paste apt-get update
[19:41] <gotmoreshell> Err http://raspberrypi.collabora.com wheezy Release.gpg Temporary failure resolving 'raspberrypi.collabora.com' Err http://archive.raspberrypi.org wheezy Release.gpg Temporary failure resolving 'archive.raspberrypi.org' Err http://mirrordirector.raspbian.org wheezy Release.gpg Tempor
[19:42] <shiftplusone> looks like an issue on your end
[19:42] <shiftplusone> with DNS
[19:42] <gotmoreshell> unchanged but let me check
[19:42] <shiftplusone> since it can't resolve any of the repos, which are unrelated to each other
[19:43] <shiftplusone> can you ping google.com ?
[19:44] <pda> paultag: thanks for the help. plugwash: thanks for pushing the fix, if that's what you did. Heading to lunch while 1.0.1f builds.
[19:45] <gotmoreshell> shiftplusone: works now, apparently reset on reboot :S
[19:45] <gotmoreshell> thanks for the nudge in the correct direction
[19:45] <shiftplusone> np
[19:45] <Death_> whoever helped put the new version on the repo thank you very much for that
[19:46] <pda> +1
[19:48] <Death_> if I don't use any SLL certs, do I need to generate anything else? are server fingerprints potentially compromised?
[19:48] <paultag> SSL*; and the remote servers are the ones that would have the threat against it
[19:49] <paultag> you could in theory dump their private key and then MITM other people with that key
[19:49] <paultag> without an SSL warning
[19:49] * Maxa (~M@unaffiliated/maxa) Quit (Remote host closed the connection)
[19:49] <paultag> so you should enable revocation checking and assume everything on any site with SSL was pwned in the last few days
[19:49] * Fusing (~fusing@ has joined #raspbian
[19:50] <Death_> I'm waiting about a week before resetting all my passwords everywhere. (Next monday) to let all the servers enough time to get updated.
[19:51] * Maxa (~M@unaffiliated/maxa) has joined #raspbian
[19:51] <Death_> As there were a lot of PoCs of userdata being hijacked with the 64K dumps.
[19:51] <paultag> Yep.
[19:52] * plugwash (~plugwash@97e03ff4.skybroadband.com) Quit (Ping timeout: 240 seconds)
[19:53] * plugwash (~plugwash@97e03ff4.skybroadband.com) has joined #raspbian
[19:53] * ChanServ sets mode +o plugwash
[19:54] * Xiguanda (~drtxus@42.Red-81-39-22.dynamicIP.rima-tde.net) has joined #raspbian
[19:57] * foulou (~foulou@gw-tech.lagoon.nc) has joined #raspbian
[20:00] * Fabzgy (~fabzgy@frbg-5f730dd6.pool.mediaWays.net) has joined #raspbian
[20:01] <fknecht> plugwash: thanks for getting this pushed out! I saw that debian pushed out an u6. Only some service restarts though I think
[20:02] * gotmoreshell (503893b3@gateway/web/freenode/ip. Quit (Quit: Page closed)
[20:03] <plugwash> yeah, u6 is on the master server now but I don't like to trigger public repo updates too close together
[20:04] <Death_> People seem to be activly exploiting the bug on un-patched high-profile servers...
[20:04] <plugwash> so i'll just let it go with the next scheduled push
[20:04] * tak30 (~tak30@243.Red-79-158-206.staticIP.rima-tde.net) has joined #raspbian
[20:04] <Death_> Some have reported even getting Credit Card info...
[20:04] <Death_> Scary stuff.
[20:04] * kensanata (~user@fsf/member/kensanata) Quit (Ping timeout: 246 seconds)
[20:04] <plugwash> meanwhile installing u5 and restarting services manually should close up the hole
[20:10] * mpmc[BNC4FREE] is now known as mpmc
[20:10] <fknecht> plugwash: yeah, thats what I'm doing right now. Thanks
[20:10] * ppq (~ppq@unaffiliated/ppq) has joined #raspbian
[20:10] <Death_> Thanks again plugwash. Thanks everyone for the nice talk, have a nice day and maybe talk to you some other time.
[20:11] <Death_> (potentially when the first multi-CM rasp IO boards are announced)
[20:11] * Death_ (5bb6032b@gateway/web/freenode/ip. Quit ()
[20:11] <fknecht> generating 8192bit keys on a raspi takes forever... ;)
[20:11] * drwhom (~drwhom@rrcs-74-218-193-10.central.biz.rr.com) Quit (Quit: Leaving)
[20:11] <stanley> Still compiling atm.
[20:12] <paultag> Entropy is a mess
[20:12] <paultag> ok, bad pun
[20:12] <stanley> use the built in rng? :)
[20:12] <paultag> but yeah, entropy is hard
[20:12] <paultag> I ain't trusting anything I don't have the source or a spec sheet for :)
[20:12] <stanley> the rpi has a hardware rng
[20:12] <stanley> ah, fair enough
[20:12] <paultag> likely nonfree
[20:12] <Fabzgy> The following packages will be upgraded: libssl-dev libssl-doc libssl1.0.0 openssl
[20:12] <Fabzgy> thx for taking care
[20:12] <Darky> <Death_> People seem to be activly exploiting the bug on un-patched high-profile servers...
[20:12] <Darky> someone told me he has nearly 100k working yahoo mail passwords
[20:13] <paultag> ouch
[20:13] <fknecht> yeah, this will haunt us for several months (at least)
[20:14] * mcnoche (~Thunderbi@205-168-220-129.dia.static.qwest.net) Quit (Quit: mcnoche)
[20:14] <fknecht> hopefully people will also upgrade their ssl now and have some better ciphers
[20:17] <shiftplusone> plugwash, any idea what that's about (line 58) http://paste.debian.net/92549/
[20:20] <plugwash> hmm, looks like a hook script is trying to parse a status message
[20:21] * Fusing (~fusing@ Quit (Ping timeout: 246 seconds)
[20:24] * ascii_ch (~quassel@2001:618:ccc:1:f2de:f1ff:fec3:e15e) Quit (Remote host closed the connection)
[20:25] * mcnoche (~Thunderbi@205-168-220-129.dia.static.qwest.net) has joined #raspbian
[20:30] * PasNox (~pasnox@2a01:e35:8b61:9b30:214:d1ff:fee9:bd3a) Quit (Quit: Leaving - Cross platform IDE http://monkeystudio.org)
[20:31] * trisi (~trisi@ has joined #raspbian
[20:35] * bizarro_1 (~bizarro_1@213.Red-88-27-90.staticIP.rima-tde.net) Quit (Quit: Leaving)
[20:37] * Alektos (~Alektos@2-224-104-190.ip170.fastwebnet.it) Quit (Quit: Lingo - http://www.lingoirc.com)
[20:37] * bizarro_1 (~bizarro_1@213.Red-88-27-90.staticIP.rima-tde.net) has joined #raspbian
[20:40] <pda> I wonder how long this openssl-1.0.1g debuild will take.. about an hour and counting so far. Reminds me of compiling linux kernel on 100 MHz systems. (installed the 1.0.1e-2+rvt+deb7u5 binary package in the mean time).
[20:41] <plugwash> any particular reason for building from source?
[20:41] <pda> mostly because the binary wasn't out yet when I started building.
[20:42] <stanley> It's taking a while on this system too :)
[20:42] <stanley> plugwash: we were waiting for you
[20:42] <paultag> :)
[20:42] <plugwash> 49 minuites on a wandboard quad..................
[20:42] * rofl (5ce5fcde@gateway/web/freenode/ip. Quit (Quit: Page closed)
[20:42] <paultag> Hah
[20:43] <stanley> pda: It's been going for an hour and 40 minutes for me.
[20:43] <stanley> (oh and paultag bullied us into using debian tools)
[20:43] * tak30 (~tak30@243.Red-79-158-206.staticIP.rima-tde.net) Quit (Ping timeout: 240 seconds)
[20:43] <paultag> I am a big bully
[20:43] <stanley> I may as well stop tor, perhaps that'll make it go faster. I need to kill the keys anyway.
[20:43] * stanley sad
[20:43] <plugwash> though only 1:04 on a mx53 so it doesn't look like there is all that much paralellism in the build
[20:44] * BManojlovic (~steki@opensuse/member/bmanojlovic) has joined #raspbian
[20:46] <BManojlovic> evening
[20:46] <plugwash> hi
[20:46] <shiftplusone> hey
[20:47] <BManojlovic> is it working for you shiftplusone?
[20:48] <shiftplusone> just testing now
[20:48] <shiftplusone> I got hung up on my own scripts since the raspbian kernel refuses to install.
[21:36] <stanley> pda: I had the test suite run about 20 minuets ago
[21:36] <shiftplusone> blapto, the version in the repo doesn't do much
[21:36] <sjk> Trying to install git and I can only get a 1.7.x version. Is there some "modern" repository I should tap into if I want to avoid ancient stuff?
[21:36] <stanley> Still going!
[21:36] <stanley> keep me updated pda
[21:36] <blapto> shiftplusone: thanks. I'll look elsewhere
[21:36] <stanley> I'll be AFK now for a while but I will inform you too
[21:36] <shiftplusone> hang on
[21:36] <pda> blapto: do you know about http://www.raspbmc.com/ ?
[21:36] <shiftplusone> blapto, I use the version from this repo http://michael.gorven.za.net/raspberrypi/xbmc
