Damus
ティージェーグレェ profile picture
ティージェーグレェ
@ティージェーグレェ

It's teajaygrey on snac.BSD.cafe!

I would probably write something else, but that rhymes, what can I say?

Previously: @[email protected], @[email protected], @[email protected], @[email protected], @[email protected]
@[email protected]

Elsewhere, semi personal: http://www.artkiver.com
Editor since 2004: https://undeadly.org
libre/free open source maintainer glimpse: https://repology.org/maintainers/?search=artkiver
Partial career history: http://www.artkiver.com/partialcareer.html
Pre-career/amateur/personal history and some musical highlights: http://www.artkiver.com/noncommercialandmusical.html

Relays (1)
  • wss://relay.ditto.pub – read & write

Recent Notes

ティージェーグレェ · 1w
I submitted a Pull Request to update MacPorts' LibreSSL to 4.3.1 here: https://github.com/macports/macports-ports/pull/32313 GitHub Continuous Integration checks are queued. Hopefully they will comp...
ティージェーグレェ profile picture
Relatedly, I submitted a Pull Request to update MacPorts' libressl-devel to 4.3.1 here:

https://github.com/macports/macports-ports/pull/32314

GitHub Continuous Integration checks are queued. Hopefully they will complete without issues?

Regardless, it's up to someone else with commit access to merge it!

#LibreSSL #MacPorts #TLS #TransportLayerSecurity #SSL #SecureSocketsLayer #Encryption #OpenSource
IrishMASMS · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0q2wkcw49x5vpxsp4y8usuz0jx64tv2rvnfxpy54wrqcsvkuywcqncnhxp oh man suicide commando 😔
ティージェーグレェ profile picture
It was a good show!

Admittedly, I probably had more fun chatting and catching up with an old friend who met me there, since the set was almost identical to the AMP Festival Suicide Commando set, though he added "Die Motherfucker Die" at the end of the encore. Otherwise, even the song orders were the same and the AMP Festival crowd was more my speed and the sound was more to my liking too.

Though, I did get Johan to autograph a couple of CDs for me. ^_^
ティージェーグレェ profile picture
I submitted a Pull Request to update MacPorts' LibreSSL to 4.3.1 here:

https://github.com/macports/macports-ports/pull/32313

GitHub Continuous Integration checks are queued. Hopefully they will complete without issues?

Regardless, it's up to someone else with commit access to merge it!

I should do something similar with libressl-devel next.

#LibreSSL #MacPorts #TLS #TransportLayerSecurity #SSL #SecureSocketsLayer #Encryption #OpenSource
1
ティージェーグレェ · 1w
Relatedly, I submitted a Pull Request to update MacPorts' libressl-devel to 4.3.1 here: https://github.com/macports/macports-ports/pull/32314 GitHub Continuous Integration checks are queued. Hopefully they will complete without issues? Regardless, it's up to someone else with commit access to mer...
ティージェーグレェ profile picture
I've submitted a Pull Request to update MacPorts' rpki-client to 9.8 here:

https://github.com/macports/macports-ports/pull/32251

GitHub Continuous Integration checks passed OK!

It's up to someone else to merge it.

I couldn't help but notice the most recent OpenBGPD release announcement mentioned something about a -portable branch? Admittedly, it has been a very long time since I looked at building OpenBGPD on macOS, but maybe it is worth looking at again? I still think it is probably ill advised to use macOS for something as critical as routing insomuch as it sleeps, with abandon, unless /usr/bin/caffeinate is invoked.

#RPKI #MacPorts #rpkiーclient #RPKIclient #OpenSource #BGP #Routing
ティージェーグレェ profile picture
Meanwhile: tomorrow is "Tax Day" in the USA?

I submitted the tax preparation packet to my CPA last month. Sent him an email, he replied. Got my bankers to forward my CPA's office some stuff. Sent an email last week, no reply.

I mean, this is par for the course tbh, my CPA tends to automatically file extensions and often we end up filing way after the April 15th deadline, so I am guessing that is what is going on again this year?

Probably my fault anyway for mailing that the day before his office had marked it as due and postal system delays, but whatever, even when I have been more proactive and ahead of the curve, these things tend to drag on much longer than I ever think necessary.

sigh

Years ago, I remember speaking with a friend's husband who I guess uses a tax attorney (geeze, it's bad enough that I was audited and started relying on a CPA, I don't even want to think about what a tax attorney costs) and he claimed that he basically files taxes at the first of the year.

My employers? Typically don't even provide W2s or whatever, until late January. I have no idea how that guy's tax attorney could file so early. Sounded extremely sus.

But I guess if you have the money to bribe^w pay off the right people? Sus things are just "normal"?
ティージェーグレェ profile picture
That Claude $20,000 in LLM time burnt to find a bug in OpenBSD?

Kinda reminds me of that CCC talk on OpenBSD by that person who was like, super critical of OpenBSD, one of the security features (I don't remember which one and I really don't feel like re-watching that video on this slow WiFi just to be more precise with citations) he sort of hand waved away with something along the lines of: "maybe this is useful for some CTF competition, but not in the real world."

I mean, I dunno much about CTF competitions everywhere. At ToorCon 8, I sorta stood over jose's shoulder while he helped their CTF team get something to compile and for some reason, I ended up on that year's t-shirt, twice, as a result! ;) I also know some of the old DefCon CTF folks. obecian, of the Ghetto Hackers? Was an OpenBSD developer. Ghetto Hackers, having won CTFs in the past, I guess got to organize future CTFs or something?

OpenBSD was banned from CTFs IIRC, because it set the bar too high. In a Capture The Flag competition, you need hosts which are actually able to be exploited.

So, no, I don't think OpenBSD developers make security features, for CTF competitions, because at least, the last time I paid any attention to such things? OpenBSD was prohibited from being used in such things. That would be a lot of wasted development effort, for something from which no one would benefit.

As an aside, one of the two times (the first time I think? 2005?) that I ever ended up attending DefCon, I learned from Caezar how obecian got ingratiated into their group. Pretty hilarious story, but I would be retelling it with about 20 years in between when I heard it and now, and doubtlessly would get some details incorrect. Not the thing to write about online so much as share in person anyway. ^_^

As an aside, didja see the Call For Papers for ToorCamp 2026?

https://talks.toorcon.net/toorcamp-2026/cfp

I dunno if I will have my life together enough to attend (it's late June, seems, dubious) but having attended ToorCamp in 2009 and having heard nothing but good things about it improving over the ensuring years? I am guessing it will be a good time!

#CTF #OpenBSD #ToorCamp #GhettoHackers
ティージェーグレェ profile picture
So that job to which I applied last week?

Yesterday I had an in person interview.

Before 19:00 local time? There was a voicemail claiming they want to move forward with the security background check part of the hiring process, which is a good sign?

Anyway, too soon to count any of those eggs as hatched, but perhaps, soonish, within the next several weeks to a month or so: maybe I will have TWO jobs!

And, presumably, still be below the poverty line and homeless and thousands in debt.

But y'know? Every little cent probably helps?

Tomorrow: I am checking out of the hostel which has been, cheap, but as with anything with shared bunk beds, kind of unfortunately reminiscent of being incarcerated. I'll then be renting a car, stopping by my mailbox for the first time in like a month, getting a haircut for the first time in maybe two months and, well other things too, before work on Thursday.

There's been a lot of other stuff going on personally. Not a whole lot exciting (other than having now taken 3 weeks of Introduction to Irish with 4th looming on Saturday) but I'll be driving to SoCal to see Suicide Commando on Saturday for what will, supposedly, be his last US tour! I'm definitely looking forward to that (the drive down and back before work Sunday morning? Less so, but music is at least something worthwhile in my existence.)
2
feld · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0q2wkcw49x5vpxsp4y8usuz0jx64tv2rvnfxpy54wrqcsvkuywcqncnhxp that's great news, good luck!!
IrishMASMS · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0q2wkcw49x5vpxsp4y8usuz0jx64tv2rvnfxpy54wrqcsvkuywcqncnhxp oh man suicide commando 😔
Christine Lemmer-Webber · 3w
You can use these tools for red teaming (caveat: you will get a lot of false positives also). You can sort of use them for prototyping (though a lot of the value of understanding building through the ...
ティージェーグレェ profile picture
The red teaming idea is maybe complementary insomuch as fuzzer and LLMs seem to have some overlapping problem spaces.

However, the backlash is not insignificant, e.g. HackerOne (a bug bounty program) has gone on hiatus after a lot of genA"I" submissions: "Internet Bug Bounty is taking a break and is not accepting new submissions." (https://hackerone.com/ibb?type=team the diff specifically: https://hackerone.com/ibb/policy_versions?change=3771829)

I have always thought that bug bounties, create perverse incentives and I was never a strong proponent of them despite knowing, perhaps too personally, some of the advocates and creators of such things.

Having written as much, I didn't really foresee the pause of such programs due to this.
✧✦Catherine✦✧ · 3w
chat, please rate my NVIDIA BlueField-3 DPU power, cooling, and communications solution yes, that's a hairdryer. yes, it is very loud. yes, it reduces the temperature from "96C and after 10 minutes t...
ティージェーグレェ profile picture
I rate it a: yikes.

A hair dryer?!

Admittedly, I guess a NVIDIA BlueField-3 DPU is a 400Gbps interconnect (presumably what the previously known as Mellanox folks are working on since they were acquired?) and that seems nifty! I don't have any experience with anything like that.

I am also weird insomuch as one of my past employers had Prop 65 Warnings everywhere (basically a California hazardous sign that dust particulates in the area may cause cancer) and really got into fanless design discipline decades ago (and even used such experiences when helping collaborate on some giant interactive fire art sculpture stuff at some Burning Man iterations, long ago). But, I also know too darned well how few GPU (and related DPUs or whatever I guess these days) are fanless in nature. ;(

Heck, even PSUs being fanless are a pain. I can find hot swappable PSUs (like, duh) and fanless PSUs (also duh) but PSUs that are hot swappable and fanless!? I cannot find them, anywhere and I have searched, repeatedly, over the years. In theory, I guess I can build such things? I really do not want to focus on that as a goal at the moment.

The hair dryer is presumably at least: budget friendly? The whole thing presumably is, well, for the throughput it can, in theory, provide. Hopefully the benchmarks are up to snuff as far as expected pushed packets or whatever!
1
✧✦Catherine✦✧ · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0q2wkcw49x5vpxsp4y8usuz0jx64tv2rvnfxpy54wrqcsvkuywcqncnhxp it's fanless in that it doesn't have a fan. it is very much not fanless in that it expects a fan, and a pretty big one at that. without cooling it overheats to the point of the NVMe dri...
Michael Knudsen · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpql5h4cecadr8nd4vunarr2cspyqg8tnz2zclep65zevj735y9rmasl3mp0w small nit: "sprint 2014" -> spring?
ティージェーグレェ profile picture
That reminds me, as I have read these I have observed occasional typos and had considered whether to submit a diff or something?

Admittedly, some of them are within historic email archives included, and those would remain untouched. Others, are maybe kind of a personal nuance and maybe not worth harping over either?

Yet I had wondered if such editorial suggestions would be welcomed and if so, how to go about doing so, but I hadn't done more than think about such things, until now.

CC: @Miod Vallat