Rocksolid Light

News from da outaworlds

mail  files  register  groups  login

Message-ID:  

BOFH excuse #93: Feature not yet implemented


sci / sci.crypt / Re: Memorizing a 128 bit / 256 bit hex key

SubjectAuthor
* Memorizing a 128 bit / 256 bit hex keyStefan Claas
+* Re: Memorizing a 128 bit / 256 bit hex keyRich
|`* Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
| `* Re: Memorizing a 128 bit / 256 bit hex keyRich
|  +* Re: Memorizing a 128 bit / 256 bit hex keyCri-Cri
|  |`* Re: Memorizing a 128 bit / 256 bit hex keyRich
|  | `* Re: Memorizing a 128 bit / 256 bit hex keyCri-Cri
|  |  `* Re: Memorizing a 128 bit / 256 bit hex keyRich
|  |   +* Re: Memorizing a 128 bit / 256 bit hex keyCri-Cri
|  |   |`* Re: Memorizing a 128 bit / 256 bit hex keyRich
|  |   | `* Re: Memorizing a 128 bit / 256 bit hex keyCri-Cri
|  |   |  `* Re: Memorizing a 128 bit / 256 bit hex keyRich
|  |   |   `* Re: Memorizing a 128 bit / 256 bit hex keyCri-Cri
|  |   |    `- Re: Memorizing a 128 bit / 256 bit hex keyRich
|  |   `- Re: Memorizing a 128 bit / 256 bit hex keyPaul Leyland
|  `* Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
|   +* Re: Memorizing a 128 bit / 256 bit hex keyRich
|   |`* Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
|   | +* Re: Memorizing a 128 bit / 256 bit hex keyCri-Cri
|   | |`- Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
|   | `- Re: Memorizing a 128 bit / 256 bit hex keyRich
|   `* Re: Memorizing a 128 bit / 256 bit hex keyCri-Cri
|    `- Re: Memorizing a 128 bit / 256 bit hex keyRich
+* Re: Memorizing a 128 bit / 256 bit hex keyChris M. Thomasson
|`* Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
| +* Re: Memorizing a 128 bit / 256 bit hex keyRich
| |+* Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
| ||`* Re: Memorizing a 128 bit / 256 bit hex keyRich
| || `- Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
| |`- Re: Memorizing a 128 bit / 256 bit hex keyChris M. Thomasson
| `- Re: Memorizing a 128 bit / 256 bit hex keyChris M. Thomasson
+* Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
|+* Re: Memorizing a 128 bit / 256 bit hex keyPeter Fairbrother
||`- Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
|`* Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
| +* Re: Memorizing a 128 bit / 256 bit hex keyPeter Fairbrother
| |`- Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
| `- Re: Memorizing a 128 bit / 256 bit hex keyStefan Claas
+- Re: Memorizing a 128 bit / 256 bit hex keyOscar
`- Re: Memorizing a 128 bit / 256 bit hex keyPeter Fairbrother

Pages:12
Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Peter Fairbrother
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Wed, 19 Jun 2024 19:57 UTC
References: 1 2
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: peter@tsto.co.uk (Peter Fairbrother)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Wed, 19 Jun 2024 20:57:59 +0100
Organization: A noiseless patient Spider
Lines: 27
Message-ID: <v4vd87$249vl$2@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org> <v4s46k$bu48$2@i2pn2.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 19 Jun 2024 21:57:59 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="11e83ddfa5707c6a85053169736b452d";
logging-data="2238453"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18UyoVOUT4tBK7scoODtQzydJ32NrL5f+k="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:AkLTcghxhbel/pueJwJPfjsVZv4=
In-Reply-To: <v4s46k$bu48$2@i2pn2.org>
Content-Language: en-GB
View all headers

On 18/06/2024 15:05, Stefan Claas wrote:
> Stefan Claas wrote:
>
>> You thoughts please, gentlemen.
>>
>> Let's say you travel and do not want to store your secret hex key on your
>> device and recreate it from memory.
>>
>> What do you think about this proposal?
>>
>> $ printf '%x' $(date -u -d '1979-01-01 12:34:56' +%s) $(date ...) 4 or 8 times.
>>
>> One has to remember only the dates (times are optional) and then simply run the
>> one liner.
>
> And use that as a seed for Argon2id key creation.

But Izvestia! Izvestia said: (Russian double-talk) It stinks.

Entropy is considerably lower than 128 bits, probably around 30 bits at
a swag..

Peter Fairbrother

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Peter Fairbrother
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Wed, 19 Jun 2024 20:02 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: peter@tsto.co.uk (Peter Fairbrother)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Wed, 19 Jun 2024 21:02:31 +0100
Organization: A noiseless patient Spider
Lines: 38
Message-ID: <v4vdgn$249vl$3@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org> <v4s46k$bu48$2@i2pn2.org>
<v4s62s$c1if$1@i2pn2.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 19 Jun 2024 22:02:31 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="11e83ddfa5707c6a85053169736b452d";
logging-data="2238453"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+Pqx0poVVBzg4OYvt2ycAkTSiMdNyefUM="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:k63NR9WnuC04mrSVDDyyIO7C/3w=
In-Reply-To: <v4s62s$c1if$1@i2pn2.org>
Content-Language: en-GB
View all headers

On 18/06/2024 15:37, Stefan Claas wrote:
> Stefan Claas wrote:
>
>> Stefan Claas wrote:
>>
>>> You thoughts please, gentlemen.
>>>
>>> Let's say you travel and do not want to store your secret hex key on your
>>> device and recreate it from memory.
>>>
>>> What do you think about this proposal?
>>>
>>> $ printf '%x' $(date -u -d '1979-01-01 12:34:56' +%s) $(date ...) 4 or 8 times.
>>>
>>> One has to remember only the dates (times are optional) and then simply run the
>>> one liner.
>>
>> And use that as a seed for Argon2id key creation.
>>
>>>
>>> The encryption software can be downloaded when one arrives at his destination.

Hmm, from where? Threat analysis?

> I think diceware passwords with Argon2id are the solution, because one can
> recreate the Argon2id hex key with with the memorized diceware passphrase. :-)

Much better.

Both diceware and argon2id can be improved on, but generally that would
mostly work.

Peter Fairbrother

bored, just got out of hospital, and laid up with bad knee

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Chris M. Thomasson
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Wed, 19 Jun 2024 20:05 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: chris.m.thomasson.1@gmail.com (Chris M. Thomasson)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Wed, 19 Jun 2024 13:05:49 -0700
Organization: A noiseless patient Spider
Lines: 73
Message-ID: <v4vdmu$24786$3@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org> <v4vb9v$2478p$1@dont-email.me>
<v4vbth$fvtf$1@i2pn2.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 19 Jun 2024 22:05:50 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="c0855a90345f22abd4db42c5674212bf";
logging-data="2235654"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18X0uPq/KB/IWc1i29XJvcCr4oMxp9hx+g="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:DiFjJ13Eno3NrLiKaUGc4NrGXlc=
Content-Language: en-US
In-Reply-To: <v4vbth$fvtf$1@i2pn2.org>
View all headers

On 6/19/2024 12:35 PM, Stefan Claas wrote:
> Chris M. Thomasson wrote:
>
>> On 6/18/2024 6:55 AM, Stefan Claas wrote:
>>> You thoughts please, gentlemen.
>>>
>>> Let's say you travel and do not want to store your secret hex key on your
>>> device and recreate it from memory.
>>>
>>> What do you think about this proposal?
>>>
>>> $ printf '%x' $(date -u -d '1979-01-01 12:34:56' +%s) $(date ...) 4 or 8 times.
>>>
>>> One has to remember only the dates (times are optional) and then simply run the
>>> one liner.
>>>
>>> The encryption software can be downloaded when one arrives at his destination.
>>>
>>
>> Generate a hex key from a password? It seems like my site can do it:
>>
>> http://fractallife247.com/test/hmac_cipher/ver_0_0_0_1?ct_hmac_cipher=2bf63f8ee90dfed997b115aa711600c45a8212a1e35f4f75ccfa36ee459b3fedd8b5f477ebb8871dd94025e7731f39cf7650f864fd6d5ce6908bb2609f96e81a413ccf40b33380a569155cb79612def387c76dd1ae436bcb4fb8c9b959be255708d020d559e07492ba24aae3705ba700a5d9c857418a0050d9ad5935efbfc36b895329cabeacbc7cefdee04834b4d392e50501c55587361bd6ca7337083fcd16ddf95d50072ea61cf2aaeb45d4d676abf93d39ad0a386399d55f2d0dba6be91521068f1120573e96aa1d81362e62f91bf88f63fe159175c13a1abec4184aae1cadfe2e18be27cac0fbefbae0c57cec531bc71e8a86d0f15a727e98bafe0239c5fd06a250e7f6
>>
>> It encrypts a key using the default password. The key is generated using
>> the same program. This example basically generates a key using the
>> default password, then encrypts said key using a different password.
>>
>> Everybody can decrypt the generated key because the ciphertext in the
>> link uses the default password:
>>
>> https://i.ibb.co/BybrYDw/image.png
>>
>> The plaintext is:
>>
>> A key:
>>
>> f65952b125ba6860e21aef9c55e69e0612b153e5fd2599ac00b67945f9bec7563d5edf8bf9fa0db27aeb78b0c8f40f0a6a69b2cd720d59ecc73a01c1ccad0933cfe9e014dda35db6eaba760c9dbdff0f4ad24c5b702baab8e225189179b8bd
>
> Your site says it does key generation from 64 random bytes. How do you remember the key
> when traveling, with no device? Or how can you trust your site, when your are on annual leave, out of your country, and some bad boy customized your site?
>

Well, yeah. Shit. Sorry what I wrote does not solve your problem. The
problem is on my end for your specific goal. The issue is is that each
time you click encrypt on my site, it will generate a new ciphertext
even if the plaintext is the same. I take it that this is not what you
are looking for! Am I right that you want the same ciphertext generated
for each encryption? A password creates a unique key, in the form of the
generated ciphertext?

Fwiw, my online program needs to use an actual TRNG to follow my rules here:

http://funwithfractals.atspace.cc/ct_cipher/

Using a TRNG for the following function in my code is ideal in:

https://fractallife247.com/test/hmac_cipher/ver_0_0_0_1/ct_main.js
___________
function ct_rand_bytes(n) {
var output = new Array();

for (var i = 0; i < n; ++i) {
var byte = Math.floor(Math.random() * 255);
output.push(byte);
}

return output;
} ___________

That is NOT using a TRNG, ARGH!!!

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Chris M. Thomasson
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Wed, 19 Jun 2024 20:41 UTC
References: 1 2 3 4
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: chris.m.thomasson.1@gmail.com (Chris M. Thomasson)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Wed, 19 Jun 2024 13:41:07 -0700
Organization: A noiseless patient Spider
Lines: 57
Message-ID: <v4vfp4$2554p$1@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org> <v4vb9v$2478p$1@dont-email.me>
<v4vbth$fvtf$1@i2pn2.org> <v4vcm5$24hrj$2@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 19 Jun 2024 22:41:08 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="c0855a90345f22abd4db42c5674212bf";
logging-data="2266265"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX191ybLROG388sloXTHaXp7N/befoclM3sU="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:UcL4KKVugW4+bpfywXjQSer3NZ0=
Content-Language: en-US
In-Reply-To: <v4vcm5$24hrj$2@dont-email.me>
View all headers

On 6/19/2024 12:48 PM, Rich wrote:
> Stefan Claas <pollux@tilde.club> wrote:
>> Chris M. Thomasson wrote:
>>> Generate a hex key from a password? It seems like my site can do it:
>>>
>>> http://fractallife247.com/test/hmac_cipher/ver_0_0_0_1?ct_hmac_cipher=2bf63f8ee90dfed997b115aa711600c45a8212a1e35f4f75ccfa36ee459b3fedd8b5f477ebb8871dd94025e7731f39cf7650f864fd6d5ce6908bb2609f96e81a413ccf40b33380a569155cb79612def387c76dd1ae436bcb4fb8c9b959be255708d020d559e07492ba24aae3705ba700a5d9c857418a0050d9ad5935efbfc36b895329cabeacbc7cefdee04834b4d392e50501c55587361bd6ca7337083fcd16ddf95d50072ea61cf2aaeb45d4d676abf93d39ad0a386399d55f2d0dba6be91521068f1120573e96aa1d81362e62f91bf88f63fe159175c13a1abec4184aae1cadfe2e18be27cac0fbefbae0c57cec531bc71e8a86d0f15a727e98bafe0239c5fd06a250e7f6
>>>
>>> It encrypts a key using the default password. The key is generated
>>> using the same program. This example basically generates a key
>>> using the default password, then encrypts said key using a different
>>> password.
>>>
>>> Everybody can decrypt the generated key because the ciphertext in
>>> the link uses the default password:
>>>
>>> https://i.ibb.co/BybrYDw/image.png
>>>
>>> The plaintext is:
>>>
>>> A key:
>>>
>>> f65952b125ba6860e21aef9c55e69e0612b153e5fd2599ac00b67945f9bec7563d5edf8bf9fa0db27aeb78b0c8f40f0a6a69b2cd720d59ecc73a01c1ccad0933cfe9e014dda35db6eaba760c9dbdff0f4ad24c5b702baab8e225189179b8bd
>>
>> Your site says it does key generation from 64 random bytes. How do
>> you remember the key when traveling, with no device?

Wrt my HMAC cipher as is, you only need to remember the password for a
given ciphertext in order to decrypt it.

However, afaict, this is not what you are looking for wrt key generation
since my code generates a new ciphertext per encryption even if the
plaintext and/or password is the same.

>
>> Or how can you trust your site, when your are on annual leave, out of
>> your country, and some bad boy customized your site?

Well, I guess you can examine the source code of my site. It's client
only, no server side logic.

>
> A valid question -- and one that *also* applies to your argon2id on
> github. How can you be sure that some cracker did not change the
> argon2id present there while you are away on holiday.
>
> Or, how can you trust that a github/microsoft insider with admin level
> access did not swap out your good argon2id with a malicious argon2id.
>
> Or that a three letter agency, having taken interest in you for some
> reason, has not gotten a secret court order to swap the argon2id with a
> cracked one, and included a court ordered gag to prevent
> github/microsoft from informing you of the swap?
>

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Oscar
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Wed, 19 Jun 2024 20:52 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: oxxxxxxxxxxxs@gmail.com (Oscar)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Wed, 19 Jun 2024 22:52:01 +0200
Organization: A noiseless patient Spider
Lines: 29
Message-ID: <v4vgdi$255u4$1@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 19 Jun 2024 22:52:02 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="819341fa8d177646c7aa64a2288e1ebd";
logging-data="2267076"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18M30K0SVAC0ijbyQCjg3NiFIldicRuoo8="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.15.1
Cancel-Lock: sha1:+kk7cvfpst/BN8kC63lIckNSH1o=
In-Reply-To: <v4s3ld$bu48$1@i2pn2.org>
Content-Language: nl
View all headers

Op 18-6-2024 om 15:55 schreef Stefan Claas:
> You thoughts please, gentlemen.
>
> Let's say you travel and do not want to store your secret hex key on your
> device and recreate it from memory.
>
> What do you think about this proposal?
>
> $ printf '%x' $(date -u -d '1979-01-01 12:34:56' +%s) $(date ...) 4 or 8 times.
>
> One has to remember only the dates (times are optional) and then simply run the
> one liner.
>
> The encryption software can be downloaded when one arrives at his destination.
>

Someone already mentioned using python hash functions, but perhaps;
sha1sum <some file on the device>

If you don't want to bring <some file> with you, you can download it later.

Or just make up some lengthy password and translate it manually to "hex
digits" using "man ascii".

Or just try to remember some fun hexdigits literally like deadbeef,
b000b5, caffee etc ..

Cheers,
Oscar

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Stefan Claas
Newsgroups: sci.crypt
Organization: ℭ𝔥𝔦𝔣𝔣𝔯𝔢𝔭𝔲𝔫𝔨𝔰
Date: Wed, 19 Jun 2024 20:53 UTC
References: 1 2 3 4
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.quux.org!news.nk.ca!rocksolid2!i2pn2.org!.POSTED!not-for-mail
From: pollux@tilde.club (Stefan Claas)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Wed, 19 Jun 2024 22:53:57 +0200
Organization: ℭ𝔥𝔦𝔣𝔣𝔯𝔢𝔭𝔲𝔫𝔨
𝔰
Message-ID: <v4vgh6$g5tv$1@i2pn2.org>
References: <v4s3ld$bu48$1@i2pn2.org>
<v4s46k$bu48$2@i2pn2.org>
<v4s62s$c1if$1@i2pn2.org>
<v4vdgn$249vl$3@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 19 Jun 2024 20:53:58 -0000 (UTC)
Injection-Info: i2pn2.org;
logging-data="530367"; mail-complaints-to="usenet@i2pn2.org";
posting-account="Cql5xXq+1B7GYqFCkkYQTE9ttzQmzqt9PRBXcODTV+U";
Finger: tilde.club/~pollux/
X-Spam-Checker-Version: SpamAssassin 4.0.0
View all headers

Peter Fairbrother wrote:

> On 18/06/2024 15:37, Stefan Claas wrote:
> > Stefan Claas wrote:
> >
> >> Stefan Claas wrote:
> >>
> >>> You thoughts please, gentlemen.
> >>>
> >>> Let's say you travel and do not want to store your secret hex key on your
> >>> device and recreate it from memory.
> >>>
> >>> What do you think about this proposal?
> >>>
> >>> $ printf '%x' $(date -u -d '1979-01-01 12:34:56' +%s) $(date ...) 4 or 8 times.
> >>>
> >>> One has to remember only the dates (times are optional) and then simply run the
> >>> one liner.
> >>
> >> And use that as a seed for Argon2id key creation.
> >>
> >>>
> >>> The encryption software can be downloaded when one arrives at his destination.
>
> Hmm, from where? Threat analysis?

Well, for example from GitHub. Prior departure you write down on a piece of paper,
which you carry in your wallet, the shasum and on arrival you download and compare
the shasum.

> > I think diceware passwords with Argon2id are the solution, because one can
> > recreate the Argon2id hex key with with the memorized diceware passphrase. :-)
>
> Much better.
>
> Both diceware and argon2id can be improved on, but generally that would
> mostly work.
>
>
> Peter Fairbrother
>
> bored, just got out of hospital, and laid up with bad knee
>

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Stefan Claas
Newsgroups: sci.crypt
Organization: ℭ𝔥𝔦𝔣𝔣𝔯𝔢𝔭𝔲𝔫𝔨𝔰
Date: Wed, 19 Jun 2024 20:54 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!i2pn.org!i2pn2.org!.POSTED!not-for-mail
From: pollux@tilde.club (Stefan Claas)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Wed, 19 Jun 2024 22:54:44 +0200
Organization: ℭ𝔥𝔦𝔣𝔣𝔯𝔢𝔭𝔲𝔫𝔨
𝔰
Message-ID: <v4vgil$g5tv$2@i2pn2.org>
References: <v4s3ld$bu48$1@i2pn2.org>
<v4s46k$bu48$2@i2pn2.org>
<v4vd87$249vl$2@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 19 Jun 2024 20:54:45 -0000 (UTC)
Injection-Info: i2pn2.org;
logging-data="530367"; mail-complaints-to="usenet@i2pn2.org";
posting-account="Cql5xXq+1B7GYqFCkkYQTE9ttzQmzqt9PRBXcODTV+U";
Finger: tilde.club/~pollux/
X-Spam-Checker-Version: SpamAssassin 4.0.0
View all headers

Peter Fairbrother wrote:

> On 18/06/2024 15:05, Stefan Claas wrote:
> > Stefan Claas wrote:
> >
> >> You thoughts please, gentlemen.
> >>
> >> Let's say you travel and do not want to store your secret hex key on your
> >> device and recreate it from memory.
> >>
> >> What do you think about this proposal?
> >>
> >> $ printf '%x' $(date -u -d '1979-01-01 12:34:56' +%s) $(date ...) 4 or 8 times.
> >>
> >> One has to remember only the dates (times are optional) and then simply run the
> >> one liner.
> >
> > And use that as a seed for Argon2id key creation.
>
> But Izvestia! Izvestia said: (Russian double-talk) It stinks.
>
>
> Entropy is considerably lower than 128 bits, probably around 30 bits at
> a swag..

Thanks for pointing that out.

--
Regards
Stefan

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Stefan Claas
Newsgroups: sci.crypt
Organization: ℭ𝔥𝔦𝔣𝔣𝔯𝔢𝔭𝔲𝔫𝔨𝔰
Date: Wed, 19 Jun 2024 21:03 UTC
References: 1 2 3 4
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!panix!weretis.net!feeder9.news.weretis.net!news.nk.ca!rocksolid2!i2pn2.org!.POSTED!not-for-mail
From: pollux@tilde.club (Stefan Claas)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Wed, 19 Jun 2024 23:03:02 +0200
Organization: ℭ𝔥𝔦𝔣𝔣𝔯𝔢𝔭𝔲𝔫𝔨
𝔰
Message-ID: <v4vh27$g5tv$3@i2pn2.org>
References: <v4s3ld$bu48$1@i2pn2.org>
<v4vb9v$2478p$1@dont-email.me>
<v4vbth$fvtf$1@i2pn2.org>
<v4vcm5$24hrj$2@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 19 Jun 2024 21:03:03 -0000 (UTC)
Injection-Info: i2pn2.org;
logging-data="530367"; mail-complaints-to="usenet@i2pn2.org";
posting-account="Cql5xXq+1B7GYqFCkkYQTE9ttzQmzqt9PRBXcODTV+U";
Finger: tilde.club/~pollux/
X-Spam-Checker-Version: SpamAssassin 4.0.0
View all headers

Rich wrote:

> Stefan Claas <pollux@tilde.club> wrote:
> > Chris M. Thomasson wrote:
> >> Generate a hex key from a password? It seems like my site can do it:
> >>
> >> http://fractallife247.com/test/hmac_cipher/ver_0_0_0_1?ct_hmac_cipher=2bf63f8ee90dfed997b115aa711600c45a8212a1e35f4f75ccfa36ee459b3fedd8b5f477ebb8871dd94025e7731f39cf7650f864fd6d5ce6908bb2609f96e81a413ccf40b33380a569155cb79612def387c76dd1ae436bcb4fb8c9b959be255708d020d559e07492ba24aae3705ba700a5d9c857418a0050d9ad5935efbfc36b895329cabeacbc7cefdee04834b4d392e50501c55587361bd6ca7337083fcd16ddf95d50072ea61cf2aaeb45d4d676abf93d39ad0a386399d55f2d0dba6be91521068f1120573e96aa1d81362e62f91bf88f63fe159175c13a1abec4184aae1cadfe2e18be27cac0fbefbae0c57cec531bc71e8a86d0f15a727e98bafe0239c5fd06a250e7f6
> >>
> >> It encrypts a key using the default password. The key is generated
> >> using the same program. This example basically generates a key
> >> using the default password, then encrypts said key using a different
> >> password.
> >>
> >> Everybody can decrypt the generated key because the ciphertext in
> >> the link uses the default password:
> >>
> >> https://i.ibb.co/BybrYDw/image.png
> >>
> >> The plaintext is:
> >>
> >> A key:
> >>
> >> f65952b125ba6860e21aef9c55e69e0612b153e5fd2599ac00b67945f9bec7563d5edf8bf9fa0db27aeb78b0c8f40f0a6a69b2cd720d59ecc73a01c1ccad0933cfe9e014dda35db6eaba760c9dbdff0f4ad24c5b702baab8e225189179b8bd
> >
> > Your site says it does key generation from 64 random bytes. How do
> > you remember the key when traveling, with no device?
>
> > Or how can you trust your site, when your are on annual leave, out of
> > your country, and some bad boy customized your site?
>
> A valid question -- and one that *also* applies to your argon2id on
> github. How can you be sure that some cracker did not change the
> argon2id present there while you are away on holiday.
>
> Or, how can you trust that a github/microsoft insider with admin level
> access did not swap out your good argon2id with a malicious argon2id.
>
> Or that a three letter agency, having taken interest in you for some
> reason, has not gotten a secret court order to swap the argon2id with a
> cracked one, and included a court ordered gag to prevent
> github/microsoft from informing you of the swap?

Prior upload and departure I can write down on a piece of paper the shasum
and once arrived at my destination I can compare the shasum from the download
with the shasum on paper. Only problem would be IMHO, if the shasum would
no longer match and I have no plan B.

--
Regards
Stefan

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Rich
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Thu, 20 Jun 2024 03:14 UTC
References: 1 2 3 4 5
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: rich@example.invalid (Rich)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Thu, 20 Jun 2024 03:14:45 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 55
Message-ID: <v506r5$2cucm$1@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org> <v4vb9v$2478p$1@dont-email.me> <v4vbth$fvtf$1@i2pn2.org> <v4vcm5$24hrj$2@dont-email.me> <v4vh27$g5tv$3@i2pn2.org>
Injection-Date: Thu, 20 Jun 2024 05:14:46 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="5bdc0c3dfc9fa55cdda166dac217f191";
logging-data="2521494"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18ZqqKU/jmLe/hbP2EO7dHL"
User-Agent: tin/2.6.1-20211226 ("Convalmore") (Linux/5.15.139 (x86_64))
Cancel-Lock: sha1:5BzwDN6dIvW/BMDs73KuqTg0sYw=
View all headers

Stefan Claas <pollux@tilde.club> wrote:
> Rich wrote:
>
>> Stefan Claas <pollux@tilde.club> wrote:
>> > Chris M. Thomasson wrote:
>> >> Generate a hex key from a password? It seems like my site can do it:
>> >>
>> >> http://fractallife247.com/test/hmac_cipher/ver_0_0_0_1?ct_hmac_cipher=2bf63f8ee90dfed997b115aa711600c45a8212a1e35f4f75ccfa36ee459b3fedd8b5f477ebb8871dd94025e7731f39cf7650f864fd6d5ce6908bb2609f96e81a413ccf40b33380a569155cb79612def387c76dd1ae436bcb4fb8c9b959be255708d020d559e07492ba24aae3705ba700a5d9c857418a0050d9ad5935efbfc36b895329cabeacbc7cefdee04834b4d392e50501c55587361bd6ca7337083fcd16ddf95d50072ea61cf2aaeb45d4d676abf93d39ad0a386399d55f2d0dba6be91521068f1120573e96aa1d81362e62f91bf88f63fe159175c13a1abec4184aae1cadfe2e18be27cac0fbefbae0c57cec531bc71e8a86d0f15a727e98bafe0239c5fd06a250e7f6
>> >>
>> >> It encrypts a key using the default password. The key is generated
>> >> using the same program. This example basically generates a key
>> >> using the default password, then encrypts said key using a different
>> >> password.
>> >>
>> >> Everybody can decrypt the generated key because the ciphertext in
>> >> the link uses the default password:
>> >>
>> >> https://i.ibb.co/BybrYDw/image.png
>> >>
>> >> The plaintext is:
>> >>
>> >> A key:
>> >>
>> >> f65952b125ba6860e21aef9c55e69e0612b153e5fd2599ac00b67945f9bec7563d5edf8bf9fa0db27aeb78b0c8f40f0a6a69b2cd720d59ecc73a01c1ccad0933cfe9e014dda35db6eaba760c9dbdff0f4ad24c5b702baab8e225189179b8bd
>> >
>> > Your site says it does key generation from 64 random bytes. How do
>> > you remember the key when traveling, with no device?
>>
>> > Or how can you trust your site, when your are on annual leave, out of
>> > your country, and some bad boy customized your site?
>>
>> A valid question -- and one that *also* applies to your argon2id on
>> github. How can you be sure that some cracker did not change the
>> argon2id present there while you are away on holiday.
>>
>> Or, how can you trust that a github/microsoft insider with admin level
>> access did not swap out your good argon2id with a malicious argon2id.
>>
>> Or that a three letter agency, having taken interest in you for some
>> reason, has not gotten a secret court order to swap the argon2id
>> with a cracked one, and included a court ordered gag to prevent
>> github/microsoft from informing you of the swap?
>
> Prior upload and departure I can write down on a piece of paper the
> shasum and once arrived at my destination I can compare the shasum
> from the download with the shasum on paper.

That would work, presuming the border crossing guards do not question
your shasum paper....

> Only problem would be IMHO, if the shasum would no longer match and I
> have no plan B.

True, but at least you can recognize you've been targeted, and know not
to trust the binary currently on github.

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Cri-Cri
Newsgroups: sci.crypt
Organization: Easynews - www.easynews.com
Date: Thu, 20 Jun 2024 15:26 UTC
References: 1 2 3 4 5 6 7 8 9 10
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.mixmin.net!news.neodome.net!npeer.as286.net!npeer-ng0.as286.net!peer03.ams1!peer.ams1.xlned.com!news.xlned.com!peer02.ams4!peer.am4.highwinds-media.com!news.highwinds-media.com!fx16.ams4.POSTED!not-for-mail
From: cri@cri.cri.invalid (Cri-Cri)
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Newsgroups: sci.crypt
References: <v4s3ld$bu48$1@i2pn2.org> <v4s7nv$1cvio$1@dont-email.me>
<v4sfv1$celq$1@i2pn2.org> <v4snug$1gjt3$1@dont-email.me>
<jFlcO.57814$bHO6.27194@fx06.ams4> <v4spbt$1gttp$2@dont-email.me>
<r7ncO.57940$bHO6.34837@fx06.ams4> <v4th7d$1p20n$1@dont-email.me>
<8tDcO.113085$FND7.27302@fx04.ams4> <v4vccd$24hrj$1@dont-email.me>
MIME-Version: 1.0
x-hc-9: yes
x-no-archive: yes
User-Agent: Pan/0.157 (Mariinka; 7c3c6087)
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Lines: 21
Message-ID: <JSXcO.332465$ujOb.242897@fx16.ams4>
X-Complaints-To: abuse@easynews.com
Organization: Easynews - www.easynews.com
X-Complaints-Info: Please be sure to forward a copy of ALL headers otherwise we will be unable to process your complaint properly.
Date: Thu, 20 Jun 2024 15:26:33 GMT
X-Received-Bytes: 1941
View all headers

On Wed, 19 Jun 2024 19:43:09 -0000 (UTC), Rich wrote:

> And, sadly, it even happens with websites that *should* know better,
> i.e., the traditional newspaper websites far too often have no dates on
> their articles on the web, meanwhile for their legacy paper they date
> each physical paper as of the day it was published.

I suppose one could pester them with questions on a daily basis, until
they learned that it would be easier to put the date on the page already
from day one. :)

Then again, I also see a trend that companies that are represented on the
web, these days seldom provide any means of contacting them. At least not
until you provide something like a DNA sample. Then what will you receive?
SPAM.

When they allowed commercial interests onto the web in the early to mid
1990's, it's been downhill from there.

--
Cri-Cri

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Rich
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Thu, 20 Jun 2024 15:54 UTC
References: 1 2 3 4 5 6 7 8 9 10 11
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: rich@example.invalid (Rich)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Thu, 20 Jun 2024 15:54:30 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 31
Message-ID: <v51jbm$2kvgs$1@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org> <v4s7nv$1cvio$1@dont-email.me> <v4sfv1$celq$1@i2pn2.org> <v4snug$1gjt3$1@dont-email.me> <jFlcO.57814$bHO6.27194@fx06.ams4> <v4spbt$1gttp$2@dont-email.me> <r7ncO.57940$bHO6.34837@fx06.ams4> <v4th7d$1p20n$1@dont-email.me> <8tDcO.113085$FND7.27302@fx04.ams4> <v4vccd$24hrj$1@dont-email.me> <JSXcO.332465$ujOb.242897@fx16.ams4>
Injection-Date: Thu, 20 Jun 2024 17:54:30 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="5bdc0c3dfc9fa55cdda166dac217f191";
logging-data="2784796"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/F1bhMakQ+p0mz0Mq9jYfZ"
User-Agent: tin/2.6.1-20211226 ("Convalmore") (Linux/5.15.139 (x86_64))
Cancel-Lock: sha1:W8Lhr0RZveF2DfxSz4i0DkVQoJo=
View all headers

Cri-Cri <cri@cri.cri.invalid> wrote:
> On Wed, 19 Jun 2024 19:43:09 -0000 (UTC), Rich wrote:
>
>> And, sadly, it even happens with websites that *should* know better,
>> i.e., the traditional newspaper websites far too often have no dates
>> on their articles on the web, meanwhile for their legacy paper they
>> date each physical paper as of the day it was published.
>
> I suppose one could pester them with questions on a daily basis,
> until they learned that it would be easier to put the date on the
> page already from day one. :)

Provided one has a /way/ to pester them....

> Then again, I also see a trend that companies that are represented on
> the web, these days seldom provide any means of contacting them.

Yes, this is indeed the problem. Most want to "broadcast", but never
"receive", any information.

> At least not until you provide something like a DNA sample. Then
> what will you receive? SPAM.

Yup.

> When they allowed commercial interests onto the web in the early to
> mid 1990's, it's been downhill from there.

One could argue that "the web" might not be as big as it is at present
without those ommercial interests. But there has been a lot lost in
pursuit of that growth as well.

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Stefan Claas
Newsgroups: sci.crypt
Organization: ℭ𝔥𝔦𝔣𝔣𝔯𝔢𝔭𝔲𝔫𝔨𝔰
Date: Thu, 20 Jun 2024 18:31 UTC
References: 1 2 3 4 5 6
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!i2pn.org!i2pn2.org!.POSTED!not-for-mail
From: pollux@tilde.club (Stefan Claas)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Thu, 20 Jun 2024 20:31:22 +0200
Organization: ℭ𝔥𝔦𝔣𝔣𝔯𝔢𝔭𝔲𝔫𝔨
𝔰
Message-ID: <v51shs$j1t2$1@i2pn2.org>
References: <v4s3ld$bu48$1@i2pn2.org>
<v4vb9v$2478p$1@dont-email.me>
<v4vbth$fvtf$1@i2pn2.org>
<v4vcm5$24hrj$2@dont-email.me>
<v4vh27$g5tv$3@i2pn2.org>
<v506r5$2cucm$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Thu, 20 Jun 2024 18:31:24 -0000 (UTC)
Injection-Info: i2pn2.org;
logging-data="624546"; mail-complaints-to="usenet@i2pn2.org";
posting-account="uWi4uQdALkj7ETOfPbhNXfz0+Ra/gM5z6/Fa40dJi9U";
X-Spam-Checker-Version: SpamAssassin 4.0.0
Finger: tilde.club/~pollux/
View all headers

Rich wrote:

> Stefan Claas <pollux@tilde.club> wrote:

> > Prior upload and departure I can write down on a piece of paper the
> > shasum and once arrived at my destination I can compare the shasum
> > from the download with the shasum on paper.
>
> That would work, presuming the border crossing guards do not question
> your shasum paper....
>
> > Only problem would be IMHO, if the shasum would no longer match and I
> > have no plan B.
>
> True, but at least you can recognize you've been targeted, and know not
> to trust the binary currently on github.

And to notify, for example, people on Usenet I can then download
GnuPG 1.4 Windows from my GitHub repository and use that to post,
without nntp credentials, to Usenet, via an additional Gmail account.

In that case it doesn't matter if this repository would be compromised
as well, or a key logger is installed in an Internet Café.

--
Regards
Stefan

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Cri-Cri
Newsgroups: sci.crypt
Organization: Easynews - www.easynews.com
Date: Fri, 21 Jun 2024 01:22 UTC
References: 1 2 3 4 5 6 7 8 9 10 11 12
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!panix!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!peer03.ams4!peer.am4.highwinds-media.com!news.highwinds-media.com!fx05.ams4.POSTED!not-for-mail
From: cri@cri.cri.invalid (Cri-Cri)
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Newsgroups: sci.crypt
References: <v4s3ld$bu48$1@i2pn2.org> <v4s7nv$1cvio$1@dont-email.me>
<v4sfv1$celq$1@i2pn2.org> <v4snug$1gjt3$1@dont-email.me>
<jFlcO.57814$bHO6.27194@fx06.ams4> <v4spbt$1gttp$2@dont-email.me>
<r7ncO.57940$bHO6.34837@fx06.ams4> <v4th7d$1p20n$1@dont-email.me>
<8tDcO.113085$FND7.27302@fx04.ams4> <v4vccd$24hrj$1@dont-email.me>
<JSXcO.332465$ujOb.242897@fx16.ams4> <v51jbm$2kvgs$1@dont-email.me>
MIME-Version: 1.0
x-hc-9: yes
x-no-archive: yes
User-Agent: Pan/0.157 (Mariinka; 7c3c6087)
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Lines: 41
Message-ID: <RB4dO.139760$2RJ6.66618@fx05.ams4>
X-Complaints-To: abuse@easynews.com
Organization: Easynews - www.easynews.com
X-Complaints-Info: Please be sure to forward a copy of ALL headers otherwise we will be unable to process your complaint properly.
Date: Fri, 21 Jun 2024 01:22:57 GMT
X-Received-Bytes: 2926
View all headers

On Thu, 20 Jun 2024 15:54:30 -0000 (UTC), Rich wrote:

>> the web, these days seldom provide any means of contacting them.
>
> Yes, this is indeed the problem. Most want to "broadcast", but never
> "receive", any information.

With email there used to be this required recipient mailbox "postmaster"
on email servers, through which the email admin received, e.g., complaints
about misuse of resources, or other things deemed "illegal", from an email
and a general online conduct perspective.

Although it may still be required, I don't think this mailbox is monitored
by many admins these days. Or you need to be in on some secret usage of
vocabulary to circumvent heavy filtering.

I see the same trend in the whois protocol. Information is stripped for
"integrity" and "protection" reasons, but it can't be "personal integrity"
or "protection of the individual", since we are dealing with the majority
being companies that own the domains which are registered with the whois
protocol.

Same trend on Usenet. One can no longer see the path to servers (at least
not on my server). Now it just says "Path: not-for-mail." When I asked
about it, they, of course, said "for security reasons." They are now
protecting spammers and header fakers and they are in breach of the RFC
"rule book." I pointed that out to them. Result? Silence.

So, who's to blame? SPAM and script kiddies and probably what you said:
they only want to broadcast, not receive.

The whole damn thing is turning into old time radio!

> One could argue that "the web" might not be as big as it is at present
> without those ommercial interests. But there has been a lot lost in
> pursuit of that growth as well.

"Money makes the world go around."

--
Cri-Cri

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Rich
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Fri, 21 Jun 2024 03:06 UTC
References: 1 2 3 4 5 6 7 8 9 10 11 12 13
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: rich@example.invalid (Rich)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Fri, 21 Jun 2024 03:06:21 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 40
Message-ID: <v52qnd$2vm44$2@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org> <v4s7nv$1cvio$1@dont-email.me> <v4sfv1$celq$1@i2pn2.org> <v4snug$1gjt3$1@dont-email.me> <jFlcO.57814$bHO6.27194@fx06.ams4> <v4spbt$1gttp$2@dont-email.me> <r7ncO.57940$bHO6.34837@fx06.ams4> <v4th7d$1p20n$1@dont-email.me> <8tDcO.113085$FND7.27302@fx04.ams4> <v4vccd$24hrj$1@dont-email.me> <JSXcO.332465$ujOb.242897@fx16.ams4> <v51jbm$2kvgs$1@dont-email.me> <RB4dO.139760$2RJ6.66618@fx05.ams4>
Injection-Date: Fri, 21 Jun 2024 05:06:21 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="c1822e671ded941375ba81f7b10eb360";
logging-data="3135620"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/BnJg7X6QQIMavgO+3+dAD"
User-Agent: tin/2.6.1-20211226 ("Convalmore") (Linux/5.15.139 (x86_64))
Cancel-Lock: sha1:YzQhSQ+bNNHwlm+WXav5Bj/lyYs=
View all headers

Cri-Cri <cri@cri.cri.invalid> wrote:
> On Thu, 20 Jun 2024 15:54:30 -0000 (UTC), Rich wrote:
>
>>> the web, these days seldom provide any means of contacting them.
>>
>> Yes, this is indeed the problem. Most want to "broadcast", but never
>> "receive", any information.
>
> With email there used to be this required recipient mailbox "postmaster"
> on email servers, through which the email admin received, e.g., complaints
> about misuse of resources, or other things deemed "illegal", from an email
> and a general online conduct perspective.
>
> Although it may still be required, I don't think this mailbox is monitored
> by many admins these days. Or you need to be in on some secret usage of
> vocabulary to circumvent heavy filtering.

Yeah, I feel like email to postmaster@bigsite.com just about anywhere
will either bounce (at least you know it went nowhere) or go into an
email black hole never to be seen nor heard from again.

> Same trend on Usenet. One can no longer see the path to servers (at least
> not on my server). Now it just says "Path: not-for-mail."

Works fine here:

Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!panix!usenet.blueworldhosting.com!diab
lo1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!peer03.ams4!peer.am4.highwinds-media.com!news.highwi
nds-media.com!fx05.ams4.POSTED!not-for-mail

That's your path header from the article this is a reply to.

So either Pan is not showing you the full header, or something real
funky is happening with easynews's nntp feed.

> When I asked about it, they, of course, said "for security reasons."

That's often the "we don't know, we don't care, we just want you to go
away" answer -- and for many it does cause them to "just go away".

Subject: Re: Memorizing a 128 bit / 256 bit hex key
From: Paul Leyland
Newsgroups: sci.crypt
Organization: A noiseless patient Spider
Date: Tue, 16 Jul 2024 09:39 UTC
References: 1 2 3 4 5 6 7 8
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: paul.leyland@gmail.com (Paul Leyland)
Newsgroups: sci.crypt
Subject: Re: Memorizing a 128 bit / 256 bit hex key
Date: Tue, 16 Jul 2024 10:39:19 +0100
Organization: A noiseless patient Spider
Lines: 26
Message-ID: <v75f47$173cm$1@dont-email.me>
References: <v4s3ld$bu48$1@i2pn2.org> <v4s7nv$1cvio$1@dont-email.me>
<v4sfv1$celq$1@i2pn2.org> <v4snug$1gjt3$1@dont-email.me>
<jFlcO.57814$bHO6.27194@fx06.ams4> <v4spbt$1gttp$2@dont-email.me>
<r7ncO.57940$bHO6.34837@fx06.ams4> <v4th7d$1p20n$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 16 Jul 2024 11:39:20 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="b182b4476ddb767cb677e54e38eda4ea";
logging-data="1281430"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18BpjaXHUGhnhoN+I/hKoFx"
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:292uK41Q0wJ1QkDrTnlwDewXXIw=
Content-Language: en-GB
In-Reply-To: <v4th7d$1p20n$1@dont-email.me>
View all headers

On 19/06/2024 03:53, Rich wrote:
> Cri-Cri <cri@cri.cri.invalid> wrote:
>> it's like English speaking people who own web sites have some general
>> allergy towards mentioning a date
>
> It's not just "english speaking people". This mentality seems to
> perfuse across the entire web ecosystem. Something about the relative
> /ease/ of putting up a web page causes by far too many of those people
> to omit publication dates from anywhere on their page(s).

I prefer not to put the last-modified date on the visible page. Anyone
who really wants to know can look at the HTML. For instance, from
www.astropalma.com

<head>
<title>Tacande Observatory, La Palma</title>
<link type="text/css" rel="stylesheet" href="de.css">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
<meta name="author" content="Paul Leyland"/>
<meta name="generator" content="GNU Emacs 26.3"/>
<meta name="revised" content="20210819T1136"/>
<meta name="X-Clacks-Overhead" content="GNU Terry Pratchet"/>
</head>

Perhaps others do much the same.

Pages:12

rocksolid light 0.9.8
clearnet tor