zamn900nevermind if you dont know00:00
zamn900better dont know00:00
Ori_88i added some repositories addresses getting the link from some random page before it detected i had to upgrade and it eventually died, is that what you meant zamn900?00:01
zamn900nope dist-upgrade is a command to over upgrade00:02
zamn900it's like updating win00:02
zamn900but with shrink to new win version00:02
zamn900that's dist-upgrade00:02
zamn900what you did is not properly reccomended anyway00:03
zamn900especially if you don't know very well what you are doing00:03
zamn900normal repository are ok00:03
zamn900or just ask us00:03
zamn900about more00:04
zamn900such as before faari suggested skeiron00:04
zamn900as source00:04
zamn900and DocScrutinizer05 is the devil god master here00:05
zamn900but now he seems finally sleepy00:05
zamn900but sometimes he is not00:06
zamn900actually is always awake00:06
Ori_88does that mean that i don't need to update repositories addresses in my new phone?00:09
paranoikHi guys. I have an old N900 with damaged mainboard(gsm, gps chips and usb port broken, vibrator damaged) and I would like to sacrifice its parts for Neo90010:31
*** jon_y_ has joined #maemo10:31
zamn900you... dirty... tell me.. did ya use it as sex toy?10:32
paranoikit was amazing10:32
zamn900why vibrator damaged and acid damaged10:32
paranoikI bought it with these components damaged10:33
zamn900oh... i am deeply sorry10:33
paranoikI guess that at least the display connector could be used for Neo10:34
zamn900go in #neo90010:35
*** triggerhappy has joined #maemo10:35
zamn900I just awaked now from an erotic dream10:35
paranoikwhen I saw your first reply I understood that it is the wrong channel :)10:35
zamn900i am rolling at floor10:38
* jaska hits faari with a rotten baltic herring.10:39
grrmoin :)11:31
DocScrutinizer05damn, he left11:53
DocScrutinizer05>> j_o_l_l_a \n coming doon! \n your Limited Edition The Other Half will be shipped in the next few weeks. \n We'll send an email confirmation with shipping details<<14:12
DocScrutinizer05nice surprise in that parcel that arrived today14:12
zGrrI've read on the other day, that jolla is planning to release new model with hw keyboard (N810 style) and larger 1080p display.14:19
DocScrutinizer05and WTF?! tmo down?14:21
zGrrThat would be cool.14:21
zGrrIf they don't screw up the system software.14:21
zGrrLike N914:22
*** Hurrian has joined #maemo14:28
WizzupzGrr: source on this? :)14:28
zGrrWizzup:  I don't remember.  I'll go through my bookmarks.14:29
DocScrutinizer05could somebody please test14:37
DocScrutinizer05host -a
DocScrutinizer05for me?14:37
DocScrutinizer05THREE dns servers are down for me, giving me headache doing anything on internet14:38
DocScrutinizer058.8.8.8 works great though14:38
Hakki_no answer14:38
wnd;; connection timed out; no servers could be reached14:38
DocScrutinizer05so it's not me but germany down on DNS :-o14:39
zGrrWizzup:  it was that page, I saw on the other day:
DocScrutinizer05Hakki_: wnd: thanks!14:41
Wizzupah, that is .. totally comprehensible14:42
* Wizzup gtranslates14:42
WizzupIt does say fan-concept14:43
wndit does14:43
zGrrIC. Too beautiful to be true.14:43
zGrrThey probably can't afford another launch anyway.14:44
wndalso, I don't get idea of phones large enough to be chopping boards14:44
zGrrAll so called phones, are too large anyway.14:45
zGrrI actually liked the size of N810.14:46
*** orsoniasty has joined #maemo14:46
wndit's fine as a pda14:46
*** Hakki_ is now known as Hakki14:46
zGrrN900 was bit smallish, though it had better, more comfortable keyboard.14:47
zGrrOr IS smallish, since I still use it every day.14:47
wndI wouldn't mind if my n900 was slightly smaller14:48
wndbut then again there are occasions when the opposite would also be true14:49
ampharosi'd be ok with N800 form factor if it didn't have the hump14:49
ampharosi never touched N810 so dunno14:49
zGrrBattery life is always an issue. You just can't have small smartphone with decent battery life.14:50
wndbut yeah, I think I prefer n810's overall shape, or relative dimensions14:50
zGrrSemi-smart, could be done, but who wants a semi-smart phone these days anyway?14:51
wndwe have an android phone as a "support line" at work. it's samsungs's candy bar phone using 3G network, it automagically updates emails and such, and the battery lasts for over a week.14:51
wndof course it doesn't have active users as is14:52
zGrrNever had Samsung. Some friends told me, it has good battery life but I never had any chance touch it.14:53
wndI don't really know which model it is, but it's considerably smaller than n900, and I believe it was one of the cheapest available14:53
zGrrI think of buying nice, small feature phone to replace my annoying N9.14:57
*** tg has quit IRC14:59
*** Kabouik has joined #maemo15:21
*** brolin_empey_ is now known as brolin_empey15:25
*** eMHa_ has joined #maemo15:39
*** zamn900 has joined #maemo15:42
DocScrutinizer05there are instances where I could shoot down KDE with a MTHEL. One such instance is when kio_http hogs all 4096 nat sessions of my router, to talk to the router HTTP15:42
DocScrutinizer05which conveniently brings down everything incl DNS lookup on public DNS servers15:43
DocScrutinizer05ok, actually my primary DNS server has an "issue", so I switched to for now (OUCH!), but the kio_idiots were busy to try and find out about dunnowhat and kio_fubar doesn't terminate when you close the app that invoked it15:51
DocScrutinizer05it goes on and on and on15:51
DocScrutinizer05usually it just keeps downloading youtube videos you closed a 20 min ago. This time it retried connecting to dunno what15:52
DocScrutinizer05now I'm wasted after 1h of DEFCON-115:54
DocScrutinizer05I already thought something rooted my PC15:54
jon_yDocScrutinizer05: why are you not running your own resolver? :(16:00
jon_yyou can enforce DNS signing checks for extra paranoia :)16:00
jon_yyour own resolving DNS server for networks under your control16:01
DocScrutinizer05because this OpenSuse distro is configured that way by default? I didn't know I'm "running my own resolver"16:01
jon_yor better yet, on every device capable of accessing the internet16:01
jon_yunbound is pretty easy to setup16:01
DocScrutinizer05what would that help?16:01
jon_ybind is fine too if you don't mind the learning curve16:01
jon_yits just that I come from a country where ISP is blatantly fucjking with the DNS for censorship16:02
jon_yand supposed anti-piracy efforts16:02
DocScrutinizer05well, so what's the solutions, except using a different DNS?16:02
jon_ydo your own lookup16:03
jon_yhave your local DNS query from the root16:03
DocScrutinizer05you're aware that DNS is hierarchical?16:03
jon_ydon't trust the ISP server16:03
DocScrutinizer05I don't16:03
jon_ynot even
jon_yor opendns16:03
DocScrutinizer05I picked my own DNS16:04
jon_ythere used to be but it died16:04
DocScrutinizer05and obviously is EVIL16:04
jon_yanyway, the top level domains are signed16:04
DocScrutinizer05but the DNS I picked went south16:04
jon_yso at least 1 level of defense16:04
DocScrutinizer05I don't think I could query tld16:05
jon_ywhat do you mean?16:05
jon_ydig com.?16:05
DocScrutinizer05I wonder what DNS you suggest I should query, and how using my own resolver does change anything with the issues this DNs might give me16:06
jon_yoh NAT died16:07
jon_yyeah, nothing much you can do about it16:07
DocScrutinizer05no, the DNS I configured since I know it's run by good guys died16:07
jon_yexcept maybe a more intelligent firewall to limit your kio_http16:08
jon_ythe next best thing is to look it up from root16:08
DocScrutinizer05then kio went mad on that 32byte reply for everything, and then kio killed my NAT16:08
jon_yit is how I got around government DNS blocks16:08
*** Hurrian has joined #maemo16:09
jon_yanyway, this is best used against ISPs messing around with DNS16:09
jon_yor if you want to be independent on any single DNS provider16:09
jon_ythere are at least half a dozen root dns servers, all signed of course16:09
DocScrutinizer05yes, that's why I originally configured my very own set of DNS addr in resolv.conf16:10
jon_yyou point your dns to root?16:10
jon_yI don't think that would work16:10
DocScrutinizer05I point it to IP of a DNS server of some nice little company I know16:10
jon_yI am saying that now they are gone, the next best course of action is to run your own recursive resolver16:11
DocScrutinizer05who I know doesn't give sh*t about spying on their 3000 customers16:11
jon_yyour network will query the resolver, the resolver will look up the records from root16:11
jon_yit is slower than google or opendns, but more secure16:12
DocScrutinizer05what ever root is16:12
jon_yand easier to bring up if it goes down16:12
jon_yroot means the DNS responsible for top "." domain16:12
DocScrutinizer05I don't think they are open to john doe16:13
jon_ythey would know where the servers delegated for com, org, net etc16:13
jon_ythey are, I am using them now16:13
jon_ythe only hard part is setting up a recursive resolver, which is to say bind or unbound16:14
*** louisdk has quit IRC16:14
jon_yonce you have that up, just have your local dhcp or what not point to it16:15
DocScrutinizer05and then you say I shall run my own DNS here for my LAN?16:15
DocScrutinizer05sounds like a hell of configuration16:15
jon_yit's pretty low maintenance16:15
jon_yI have mine running for 2 years already without messing with it16:16
DocScrutinizer05yeah sure, just tell me how to make the DD-WRT tell all the Nxx0 devices and other appliences to use my local DNS which I also have to run on a 24/7 on machine16:17
jon_ydo you have a 24/7 machine?16:17
DocScrutinizer05not really16:17
jon_ysome DD-WRT routers are big enough to run their own resolvers16:17
jon_ynot sure which model you have16:18
jaskadnsmasq needs something to forward to16:18
jon_yraspberry pi is awesome for this :)16:18
jaskasmallest i can think of is pdns-recursor16:18
DocScrutinizer05Linksys WRT54G/GL/GS16:18
jon_yis that the newest model?16:18
jon_yiirc the newer model is pretty sucky16:19
DocScrutinizer05prolly not, given it's at least 4 years old16:19
jaskano its the old good model.. atleast older g and gl16:19
jaskawrt54gl is what i have at home running tomato.. ive seen it with uptimes 500+ days16:19
jon_ythe old model had double the amount of RAM16:19
DocScrutinizer05yeah, that's about what mine had too... until 1h ago :-S16:20
*** Hurrian has quit IRC16:20
*** Hurrian_ has joined #maemo16:20
jon_ywell, if you do get another smallish device like a rpi, it should run a dns server nicely16:20
jon_yit can live behind NAT16:20
jon_yhave whatever router DHCP config point to it16:21
jon_yI don't know what Dlink thought it was doing to screw over buyers16:21
*** kimitake_idle has joined #maemo16:21
jon_yI mean Linksys16:21
DocScrutinizer05DLink omg16:23
jon_yjaska: does pdns-recursor do DNSSEC?16:23
jaskanot sure16:23
DocScrutinizer05I nuked that dlink shit and got me this dd-wrt from a friend16:23
jon_yyour NAT might not like it though16:23
*** sequantz has joined #maemo16:24
jon_yyou can check with:16:24
jaskalooks like no dnssec validation yet16:24
jon_ydig +dnssec AAAA in .gov.16:24
jon_yor A for ipv416:24
jon_yit should point you to servers in control of the gov domain16:25
jon_yquery for "." is fine too, since TLDs are also signed16:25
DocScrutinizer05dig: '.gov.' is not a legal name (empty label)16:25
jon_yfine, whitehouse.gov16:26
jon_yat least bind dig allows .gov.16:26
jon_yfrom ISC Bind16:26
Hakkidig +dnssec AAAA in gov.16:26
Hakkiworks better16:26
*** Dynamit has quit IRC16:27
jon_ygoogle's supports dnssec16:27
*** NIN101 has joined #maemo16:29
jon_yDocScrutinizer05: reducing the NAT ttl helps wonders if you have too many connections16:39
jon_yit would help the NAT daemon to forget certain port associations16:40
DocScrutinizer05jon_y: I know16:47
DocScrutinizer05let's see, the router had 4080some open sessions 20s after rebooting it16:48
jaskathats pretty wtf.16:49
DocScrutinizer05now tell me, how long may NAT keep a session before dropping it, to keep up with that rate of new sessions created?16:50
jaskawhat sort of nat device is it? linux?16:51
DocScrutinizer05kio_foo is foobar16:52
*** goldkatze has quit IRC16:55
*** goldkatze has joined #maemo16:56
warfareDocScrutinizer05: Usual timeout for established nat entries is 5 days.17:04
warfareDocScrutinizer05: Have a look in /proc/sys/net/ipv4/netfilter/17:05
DocScrutinizer05I think I reduced it to some 2 or 3 minutes17:09
DocScrutinizer05on that dd-wrt17:09
DocScrutinizer05anyway after killall kio-http the number of connections droped from 4090 to ~30 during maybe 3 minutes17:10
DocScrutinizer05I dunno what that kio_crap is doing, since netstat didn't show anything unusual17:11
*** sixwheeledbeast has quit IRC17:31
DocScrutinizer05kerio: ?18:32
kerioi have a first-level math degree :D18:32
DocScrutinizer05so that's your excuse to highlight me?18:32
DocScrutinizer05I really dunno how you degree is relevant18:36
keriowell, i got it like 2 hours ago18:37
DocScrutinizer05oooh, fine :-)18:37
merlin1991congratz kerio20:13
