Home liberachat/#xmonad: Logs Calendar

Logs on 2023-04-14 (liberachat/#xmonad)

00:33:47 catman joins (~catman@user/catman)
00:52:09 × malook quits (~Thunderbi@176.18.63.131) (Ping timeout: 256 seconds)
01:07:03 × catman quits (~catman@user/catman) (Quit: WeeChat 3.8)
01:19:35 catman joins (~catman@user/catman)
01:53:26 werneta joins (~werneta@70-142-214-115.lightspeed.irvnca.sbcglobal.net)
02:12:25 × td_ quits (~td@i53870908.versanet.de) (Ping timeout: 240 seconds)
02:14:34 td_ joins (~td@i53870905.versanet.de)
02:37:05 × Ou42_away quits (~Ou4242a@2600:1700:e930:41b0:7ca:70b7:3912:5ed0) (Quit: Leaving)
02:48:43 × terrorjack quits (~terrorjac@2a01:4f8:c17:87f8::) (Quit: The Lounge - https://thelounge.chat)
02:51:22 terrorjack joins (~terrorjac@2a01:4f8:c17:87f8::)
02:53:54 × srk quits (~sorki@user/srk) (Remote host closed the connection)
02:54:14 srk joins (~sorki@user/srk)
03:39:18 × catman quits (~catman@user/catman) (Ping timeout: 265 seconds)
04:02:23 × thunderrd quits (~thunderrd@183.182.115.185) (Ping timeout: 260 seconds)
04:15:02 thunderrd joins (~thunderrd@183.182.110.247)
04:25:57 catman joins (~catman@user/catman)
05:17:34 × catman quits (~catman@user/catman) (Ping timeout: 276 seconds)
06:00:05 × m5zs7k quits (aquares@web10.mydevil.net) (Ping timeout: 240 seconds)
06:00:32 m5zs7k joins (aquares@web10.mydevil.net)
06:08:35 catman joins (~catman@user/catman)
06:23:41 <jusa> geekosaur: btw modified SubLayouts.hs worked, but it required logoff/on to take effect, just calling restart "xmonad" True wasn't enough.. I have xmonad now from stack, I wonder if that is causing that? anyways, thanks again, now I at least have the correct font and I can continue with life :)
06:36:08 mncheck joins (~mncheck@193.224.205.254)
06:47:45 × catman quits (~catman@user/catman) (Ping timeout: 240 seconds)
07:25:33 × werneta quits (~werneta@70-142-214-115.lightspeed.irvnca.sbcglobal.net) (Ping timeout: 255 seconds)
07:27:09 werneta joins (~werneta@70-142-214-115.lightspeed.irvnca.sbcglobal.net)
07:36:57 cfricke joins (~cfricke@user/cfricke)
07:48:05 × cfricke quits (~cfricke@user/cfricke) (Ping timeout: 240 seconds)
07:49:42 cfricke joins (~cfricke@user/cfricke)
08:07:25 <geekosaur> did you try mod-shift-space? the type won't have changed
09:00:09 × liskin[m] quits (~liskinmat@2001:470:69fc:105::768) (Quit: You have been kicked for being idle)
09:00:09 × unclechu quits (~unclechu@2001:470:69fc:105::354) (Quit: You have been kicked for being idle)
09:10:23 × ft quits (~ft@p4fc2a88b.dip0.t-ipconnect.de) (Quit: leaving)
11:39:11 malook joins (~Thunderbi@46.52.55.36)
13:19:29 × mncheck quits (~mncheck@193.224.205.254) (Remote host closed the connection)
13:32:00 mc47 joins (~mc47@xmonad/TheMC47)
15:02:19 × thunderrd quits (~thunderrd@183.182.110.247) (Ping timeout: 250 seconds)
15:17:20 × malook quits (~Thunderbi@46.52.55.36) (Ping timeout: 248 seconds)
15:58:38 <geekosaur> @ask Ou42 Is there a reason for you to not use an ssh key? From what I see about Personal Access Tokens, they're an alternative to passwords, not really to ssh keys
15:58:38 <lambdabot> Consider it noted.
15:58:51 liskin[m] joins (~liskinmat@2001:470:69fc:105::768)
15:59:05 unclechu joins (~unclechu@2001:470:69fc:105::354)
15:59:09 <geekosaur> @ask Ou42 Also I note they seem to be betwixt and between about classic vs. fine grained tokens
15:59:09 <lambdabot> Consider it noted.
16:00:13 × liskin[m] quits (~liskinmat@2001:470:69fc:105::768) (Client Quit)
16:00:13 × unclechu quits (~unclechu@2001:470:69fc:105::354) (Client Quit)
16:03:37 mncheck joins (~mncheck@193.224.205.254)
16:06:39 × mc47 quits (~mc47@xmonad/TheMC47) (Remote host closed the connection)
16:12:24 × werneta quits (~werneta@70-142-214-115.lightspeed.irvnca.sbcglobal.net) (Remote host closed the connection)
16:26:49 <geekosaur> …afaict we have to opt the organization into personal access tokens
16:27:03 liskin[m] joins (~liskinmat@2001:470:69fc:105::768)
16:27:18 unclechu joins (~unclechu@2001:470:69fc:105::354)
16:27:37 <geekosaur> …are you two married at the hip or something?
16:28:28 ft joins (~ft@p4fc2a88b.dip0.t-ipconnect.de)
16:29:59 catman joins (~catman@user/catman)
16:30:16 × catman quits (~catman@user/catman) (Client Quit)
16:31:42 catman joins (~catman@user/catman)
16:42:45 × catman quits (~catman@user/catman) (Ping timeout: 240 seconds)
17:26:51 <liskin> geekosaur: I think after the recent leaked ssh host keys incident some people/orgs might be switching to tokens
17:27:19 <liskin> (because https has certificate authorities whereas ssh is mostly trust on first use)
17:35:15 × scardinal quits (~supreme@customer-212-237-101-39.ip4.gigabit.dk) (Quit: leaving)
17:47:01 scardinal joins (~supreme@customer-212-237-101-39.ip4.gigabit.dk)
17:48:39 × terrorjack quits (~terrorjac@2a01:4f8:c17:87f8::) (Quit: The Lounge - https://thelounge.chat)
17:51:16 terrorjack joins (~terrorjac@2a01:4f8:c17:87f8::)
17:56:38 catman joins (~catman@user/catman)
18:07:45 × catman quits (~catman@user/catman) (Ping timeout: 240 seconds)
18:09:13 Guest51 joins (~Guest51@106.51.64.60)
18:35:10 <geekosaur> seems odd, they can't leak secret keys
18:36:02 <geekosaur> can't even MITM with it
18:37:01 <geekosaur> anyway does that mean I should go turn on tokens for the xmonad org? right now as I understand it token access will be rejected until I enable it
18:38:20 <geekosaur> (if you go to the config it shows a panel which defaults to them enabled -but- it's the first of a series of questions in configuring token access and the default without completing that configuration is reject, if I understand the docs right)
18:44:20 × Guest51 quits (~Guest51@106.51.64.60) (Quit: Client closed)
18:56:07 malook joins (~Thunderbi@46.52.55.36)
19:13:55 <geekosaur> okay, did the token dance
19:14:16 <geekosaur> also I am amused that a MS product recommends 1password
19:15:55 <geekosaur> oh, far as I can see they leaked their own key, not users' keys. don't think PATs would help there
19:15:56 <liskin> Dunno, why would we want to enable tokens?
19:16:08 <geekosaur> we've already had someone try to use one
19:16:20 <geekosaur> (Ou42)
19:16:24 <geekosaur> and get access denied
19:16:32 <liskin> To use with xmonad?
19:16:38 <liskin> That seems really weird
19:16:53 <geekosaur> why? it's just a way to auth to github
19:16:59 <liskin> Anyway, can't go deeper, getting off a plane
19:17:07 <geekosaur> but they're not an org member so they don't get any perms from it
19:17:38 <geekosaur> (well, R/O perms)
19:31:24 × gdd quits (~gdd@129.199.146.230) (Ping timeout: 255 seconds)
19:44:07 <liskin> I'll take a look later.
19:45:38 <geekosaur> actually I'm a bit confused now, I did the token setup and then it took me back to step one after telling me we were "enrolled"
19:45:45 <geekosaur> there's no evidence of it??
19:47:02 <geekosaur> okay, now the PAT sidebar is a dropdown menu and the settings are hidden in there
19:47:11 <liskin> Anyway, re tokens and leaks: the equivalent of a host key in that scenario is the server TLS cert. If leaked, its revocation would be published using OCSP and a new one would be signed by the CA.
19:47:12 <geekosaur> this is not my idea of good UI design
19:47:32 <liskin> I really don't think we need to enable that
19:47:39 × cfricke quits (~cfricke@user/cfricke) (Quit: WeeChat 3.8)
19:48:38 <liskin> I mean, it could be useful for some of my sponsors scripts, but I really don't think it should affect any users
19:53:49 <[Leary]> If I'm not mistaken, I'd already been using a token to auth to github and push to contrib, so I'm not sure what the issue is supposed to be. Doesn't the guy just need to configure his local git to use it?
19:54:14 <geekosaur> maybe
19:54:43 <liskin> Yeah that's a good point. I've generated a bunch of tokens and used them for all sorts of things
19:54:51 <geekosaur> they were going on about needing to run a local key manager but afaict that's not necessary, it behaves like a password by default
19:55:17 <liskin> The problem with my tokens is that I can't really make them limited to xmonad
19:55:37 <liskin> So they can either access everything I can (which is... a lot), or nothing
19:55:52 <liskin> Having an org-scoped token would be useful
19:55:57 <geekosaur> that sounds like a classic token
19:56:05 <geekosaur> they have fine-grained access tokens in beta
19:57:20 <geekosaur> the stupid part is they still have services and endpoints which don't support them, so you still have to use a classic token
19:57:54 <geekosaur> (which has been around for a long time, I got one to try (and fail) to migrate issues from code.google.com)
20:01:17 <liskin> Well I don't have that one any more
20:02:12 <liskin> The ones I have are limited in scope somewhat, but those are just the repo:read and org:whatever scopes
20:02:28 <liskin> But they can still read everything I can, all orgs
20:03:16 <geekosaur> yeh, read access control seems to be somewhat lacking
20:03:27 <geekosaur> apparently they think write/admin is all that matters
20:04:17 <geekosaur> we can in fact block tokens from the org end, but there's no way for a user to request a r/o token specific to an org
20:04:21 <geekosaur> afaict
20:05:09 <geekosaur> well, not entirely true aiui, but any public repo has r/o access via token
20:05:33 <geekosaur> private repos have more control but those aren't free…
20:06:48 <geekosaur> flip side, that's essentially the same access you get with no access control at all
20:07:11 <geekosaur> a restricted token would seem to be somewhat useless if you could evade it just by not using it
20:15:36 <geekosaur> huh, I stand corrected. "Each token can only access resources owned by a single user or organization."
20:15:41 <geekosaur> (the new style ones)
20:15:52 × malook quits (~Thunderbi@46.52.55.36) (Remote host closed the connection)
20:43:45 mesaoptimizer joins (apotheosis@user/PapuaHardyNet)
20:52:01 mesaoptimizer parts (apotheosis@user/PapuaHardyNet) ()
20:55:42 malook joins (~Thunderbi@2a02:9b0:4029:5ee:f4d2:55d9:9a06:14dd)
21:36:44 × malook quits (~Thunderbi@2a02:9b0:4029:5ee:f4d2:55d9:9a06:14dd) (Remote host closed the connection)
22:16:57 stackdroid18 joins (~stackdroi@de1.hashbang.sh)
22:17:02 × terrorjack quits (~terrorjac@2a01:4f8:c17:87f8::) (Quit: The Lounge - https://thelounge.chat)
22:19:37 terrorjack joins (~terrorjac@2a01:4f8:c17:87f8::)
22:24:01 × terrorjack quits (~terrorjac@2a01:4f8:c17:87f8::) (Quit: The Lounge - https://thelounge.chat)
22:27:04 terrorjack joins (~terrorjac@2a01:4f8:c17:87f8::)
22:45:00 mesaoptimizer_ joins (apotheosis@tilde.institute)
22:45:05 × mesaoptimizer_ quits (apotheosis@tilde.institute) (Client Quit)
22:54:30 × stackdroid18 quits (~stackdroi@de1.hashbang.sh) (Quit: hasta la vista... tchau!)

All times are in UTC on 2023-04-14.