Berkeley CSUA MOTD:Entry 37630
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/05/25 [General] UID:1000 Activity:popular
5/25    

2005/5/11 [Computer/SW/Security, Academia/Berkeley/CSUA/Motd] UID:37630 Activity:high
5/11    I know kchang's de-anonymizer is putting a crimp in your style, but
        can you people who scp to /etc/motd.public please stop overwriting?
        \_ A little thought should help you realize that's impossible.
           \_ A little quality thought should help you realize that:
              "Overwriting" is being used in the context of "screwing up
              other people's changes".
              If you turn off brain and assume the literal definition of
              overwrite, you might realize you're "overwriting" [literally]
              /etc/motd.public every time you save it in an editor.
              Finally, scp users can reduce frequency of overwriting
              [contextual meaning] by reducing the lag time between the scp
              "get" and "put".
              \_ Well, they should be diffing and merging as the final step
              \_ No, they should be diffing and merging as the final step
                 before putting. This leaves a pretty tiny window for potential
                 overwrites. But can someone tell me how kchang is logging
                 file access? What OS features help with this? I'm curious to
                 know for other possible applications.
                 \_ I signed a pact with Satan
        \_ Hm, how about this feature. If you put in "-anon" at the end of
           your post, then my Ashcroft script will not reveal your id? -kchang
                 \_ Note that "tiny window for potential overwrite" is a
                    longwinded way of saying "that's impossible".
                 \_ it shouldn't be hard to modify motdedit to do this.
        \_ Play nice, or we'll take away your cookies. Or, perhaps, make it
           so that you can't scp the motd. - almighty root
           \_ hmm, maybe make it so that the motd is only editable through
              motdedit and make that a suid file w/ sudo'er perms for everyone.
              everyone should then be anon, and no more scp. yes, I'm replying
              to myself. =)
              \_ I concur. Let's enforce some type of lock/unlock mechanism.
                 \_ Make the trains run on time while you're at it.
                    \_ locking and semaphores - the first step towards fascism.
                       \_ You missed the "enforce" part didn't you?
                          \_ So tell me, if you've done any work with databases
                             or file systems, how useful is a lock that is not
                             enforced?
                             \_ Hey, I didn't realize the motd was that
                                important to you.
              \_ fuck motdedit.  In the ear.  It's not a technical problem.
                 \_ Technically, yes it is a technical problem. Access is
                    provided throuh a mechanism that causes corruption. Any
                    time such a mechanism exists and is exploitable, it puts
                    the infrastructure at risk. Asking users nicely not to do
                    it is not a solution Either you live with the corruption
                    or you fix it. As a CS grad, you should know this.
                    \_ Uhm, we're talking about motd...wtf are you talking
                       about?  This isn't a general "all locks and
                       synchronization are bad" thread, this is a "motdedit
                       is a shitty technical solution which doesn't even
                       really address all the problems" thread.  As a high
                       school grad this should be obvious to you.
                       \_ First of all, tell us why motdedit is broken, and
                          maybe we can come up with something better.
                          \_ Because of patronizing motdedit users.  Anything
                             without patronizing evangelists that works would
                             be better.
                       \_ As important as MOTD is for a bunch of users here,
                          most of whom are CS grads, I'd wager any technical
                          problem could be ironed out quickly. Anyways,
                          whatever, this is your guys' problem. I don't use
                          MOTD and everytime I read it, I feel less inclined to
                          put as much time into maintaining this system as I
                          do. I was offering solutions to a real problem of
                          corruption. But hey, if you people like broken, then
                          broken you get.
                          \_ Broken >> supercilious motdedit nazi assholes
                             Go or stay, use it or don't use it, it's a free
                             country, and nobody is particularly pining for
                             you either way.  Go, and be happy, my son.
                              xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                             \_ No offsense, but go fuck yourself. As root, VP,
                             \_ No offsense, but go eat a carrot. As root, VP,
                                and now president of the CSUA my policies on
                                sorrying non-student accounts is much more
                                draconian than that of my predecessors. You
                                may have been a student once, but our ultimate
                                mission is to provide service to current
                                students - and when people make this a hostile
                                environment, I won't blink to kick them off our
                                server. Although I value the insight and
                                participation of alumni in the CSUA, I'd advise
                                you not to fuck it up for everyone. If you
                                disagree with an idea, then voice your reasons
                                - not some immature tirade and rant. This is
                                not your personal soap box, this is a server
                                for use by university students.
                                xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

                          \_ I suggest we first solve the problem of people
                             posting lines longer than 80 columns or people
                             with their tabstop not set at 8.
                             \_ I suggest pliers or a heavy bludgeon.  There's
                                nothing like broken bones to keep columns
                                down to a reasonable size.
        \_ Hm, how about this feature. If you put in "-anon" or some type of
           identity at the end of your thread, then my Almighty Ashcroft
           script will not reveal your id? -kchang
           \_ How about we just squish your ass right now? -anon
              \_ I wouldn't do that. John Ashcroft is watching you.
                 \_ But...but...I put "-anon" at the end!  Pretty please let me
                    be anonymous? -anon
                   \_ Well I haven't implemented it, I'm just soliciting
                      opinions and should there be enough demand, I'll do it.
                      \_ Anyone who has worked with group-writable files
                         has come to the conclusion that locking and
                         logging is important; I'd like to see motdedit
                         (or something functionally similar like RCS)
                         required.  -tom
                         \_ Because the motd is mission critical!  Seriously,
                            if this were source code, I'd agree.  An anonymous
                            posting board where anyone can add or delete?  Feh.
                            \_ It blows me away how worked up people get
                               about a lame ass world writeable file.
           \_ kchang, I like to troll. the motd is too boring. can you include
              an 'exclude' list of names? ;) we need to revive the motd of
              better topics!!!
        \_ Perhaps the de-anonimizer is a good thing. Its like that old
           Donald Duck count to 10 before you explode cartoon. You have
           to think about whether or not your really want to write that
           comment before you do. It makes the discussion more civilized.
ERROR, url_link recursive (eces.Colorado.EDU/secure/mindterm2) 2025/05/25 [General] UID:1000 Activity:popular
5/25    

You may also be interested in these entries...
2013/10/24-11/21 [Computer/Companies/Apple] UID:54747 Activity:nil
9/19    "No, A Severed Finger Will Not Be Able to Access a Stolen iPhone 5S"
        http://mashable.com/2013/09/15/severed-finger-iphone-5s
        I'm sure the Apple QA department has tested extensively that a severed
        finger will not be able to access a stolen iPhone 5S.
        \_ It doesn't matter whether or not a severed finger can be used.  It
           matters whether or not a robber thinks that a severed finger can be
	...
2013/6/6-7/31 [Politics/Foreign/Asia/China, Computer/SW/Security] UID:54690 Activity:nil
6/6     Wow, NSA rocks. Who would have thought they had access to major
        data exchangers? I have much more respect for government workers,
        crypto experts, mathematicans now than ever.
        \_ flea to Hong Kong --> best dim-sum in the world
           \_ "flee"
        \_ The dumb ones work for DMV, the smart ones for the NSA. If you
	...
2012/8/29-11/7 [Computer/SW/Security] UID:54467 Activity:nil
8/29    There was once a CSUA web page which runs an SSH client for logging
        on to soda.  Does that page still exist?  Can someone remind me of the
        URL please?  Thx.
        \_ what do you mean? instruction on how to ssh into soda?
           \_ No I think he means the ssh applet, which, iirc, was an applet
              that implemented an ssh v1 client.  I think this page went away
	...
2012/9/20-11/7 [Computer/SW/Unix, Finance/Investment] UID:54482 Activity:nil
9/20    How do I change my shell? chsh says "Cannot change ID to root."
        \_ /usr/bin/chsh does not have the SUID permission set. Without
           being set, it does not successfully change a user's shell.
           Typical newbie sys admin (on soda)
           \_ Actually, it does: -rwsr-xr-x 1 root root 37552 Feb 15  2011 /usr/bin/chsh
	...
2012/8/7-10/17 [Computer/SW/Security] UID:54455 Activity:nil
8/6     Amazon and Apple have lame security policies:
        http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all
        "First you call Amazon and tell them you are the account holder, and
         want to add a credit card number to the account. All you need is the
         name on the account, an associated e-mail address, and the billing
         address. "
	...
2012/5/8-6/4 [Computer/SW/Unix] UID:54383 Activity:nil
5/8     Hello everyone!  This is Josh Hawn, CSUA Tech VP for Spring 2012.
        About 2 weeks ago, someone brought to my attention that our script
        to periodically merge /etc/motd.public into /etc/motd wasn't
        running.  When I looked into it, the cron daemon was running, but
        there hadn't been any root activity in the log since April 7th.  I
        looked into it for a while, but got lost in other things I was
	...
2012/2/9-3/26 [Computer/SW/Security, Computer/SW/Unix] UID:54305 Activity:nil
2/9     Reminder: support for mail services has been deprecated for *several
        years*. Mail forwarding, specifically .forward mail forwarding, is
        officially supported and was never deprecated.
        \_ There is no .forward under ~root.  How do we mail root and how do
           we get responses?
           \_ root@csua.berkeley.edu is and always has been an alias.
	...
2013/10/24-2014/2/5 [Academia/Berkeley/CSUA/Motd, Computer/SW] UID:54746 Activity:nil
9/26    I remember there was web version of the motd with search function
        (originally due to kchang ?).  The last time I used it it was hosted
        on the csua website but I can't remember its url (onset of dementia?)
        now. Can somebody plz post it, tnx.
        \_ http://csua.com
           \_ for some reason I couldn't log in since Sept and the archiver
	...
2012/9/5-11/7 [Academia/Berkeley/CSUA, Academia/Berkeley/CSUA/Motd] UID:54472 Activity:nil
9/4     It looks like there are some issues with wallall at the moment. Any
        plans for it getting fixed? I can run wall, but wallall just gives an
        error.
        \_ Asking questions on the motd will not get any attention from
           any undergrad. You should email politburo or perhaps csua. -ausman
        \_ Asking questions on the motd will not get attention from any
	...
2012/4/23-6/4 [Academia/Berkeley/CSUA/Motd] UID:54359 Activity:nil
4/19    Motd updater thingy seems to be broken, does anyone know why?
        If not, I will take a look later in the day. -ausman
        \_ /etc/motd.public is not getting copied into /etc/motd for a while.
           \_ Now it works and no one knows why. Strange. -ausman
	...
2012/2/6-3/26 [Academia/Berkeley/CSUA, Academia/Berkeley/CSUA/Motd] UID:54301 Activity:nil
2/6     Um, what happened to http://www.csua.berkeley.edu/~myname ?
        "The requested URL /~myname/ was not found on this server."
        \_ Try emailing root or politburo. I don't think that the
           undergrads use this machine anymore. -ausman
        \_ Ausman is mostly right. LDAP went down due to an expired cert and
           took down most of the rest of our stuff. It's probably a thing with
	...
2012/2/24-3/26 [Academia/Berkeley/CSUA/Motd] UID:54313 Activity:nil
2/24    What newsreader should I use on soda?
        \_ USENIX? You serious? Everyone switched to RSS.
           \_ I think you mean usenet not usenix.  usenet was generally much
              better than blogs / rss (cf. comp.lang.c, comp.lang.perl,
              the usenet oracle, alt.* with digg, slashdot, etc.)
           link:reader.google.com is the best
	...