4 February 1925 | A French Jewish woman, Ginette Kolinka (née Cherkasky), was born in Paris.
She was deported to Auschwitz from Drancy in April 1944. She was transferred to Bergen-Belsen and then to Theresienstadt. She survived.
Today she turns 99.
I noticed something strange at #fosdem: people are finishing their talk right on time.
That would be VERY UNUSUAL in an academic research conference. Here, in this engineering community, I still haven't saw a speaker having to be stopped half way.
I can actually attend the presentations I want without bad surprises.
And that's so relaxing.
2/2 Most of you don't find ochre in nature. But did you know that you can paint with nearly every soil or grinded stone?
Try to collect some soil where it is very fine, without too much plant decay. You can try it pure or grind it. Then mix it like pigments for painting. The easiest, especially for children, is some white school glue. And start your experiments! The soil will tell you its stories ...
#soil #pigments #painting #geology #stones #edu #EduTainment #colours #nature #natureArt
@popey My experience from academic conferences was that Windows people didn't know the hot-key to switch to projector output, Linux people didn't know which driver to install to switch to projector output, and Mac people had forgotten to bring the right dongle.
@dannotdaniel @shortridge At the time, I was the last level of support on a team which was the catch-all for issues which didn’t fall into another team’s specific area of responsibility. We got all the weird problems with random areas of the company’s products which maybe five people worldwide used. We also got all the problems which confounded people at the earlier levels. It was systems programming *and* top-tier sysadmin work rolled into one.
I miss some aspects of that job, but it was mostly horrible. Every time I catch myself romanticizing it and thinking about going back, I remind myself that while chasing that particular issue, I was paid barely above poverty-level.
@shortridge While working tech support, I got a call on a Monday. Some VPNs which had been working on Friday were no longer working. After a little digging, we found the negotiation was failing due to a certificate validation failure.
The certificate validation failure was happening because the system couldn’t check the CRL.
The system couldn’t check the CRL because it was too big. The system doing the validation only allocated 512kB to store the CRL, and it was bigger than that. This is from a private certificate authority, though, and 512kB is a *LOT* of revoked certificates. Shouldn’t be possible for this environment to hit within a human lifespan.
Turns out the CRL was nearly a megabyte! What gives? We check the certificate authority, and it’s revoking and reissuing every single certificate it has signed once per second.
The revocations say all the certificates (including the certificate authority’s) are expired. We check the expiration date of the certificate authority, and it’s set to some time in 1910. What? It was around here I started to suspect what had happened.
The certificate authority isn’t valid before some time in 2037. It was waking up every second, seeing the current date was after the expiration date and reissuing everything. But time is linear, so it doesn’t make sense to reissue an expired certificate with an earlier not-valid-before date, so it reissued all the certs with the same dates and went to sleep. One second later, it woke up and did the whole process over again. But why the clearly invalid dates on the CA?
The CA operation log was packed with revocations and reissues, but I eventually found the reissues which changed the validity dates of the CA’s certificate. Sure enough, it reissued itself in 2037 and the expiration date was set to 2037 plus ten years, which fell victim to the 2038 limitation. But it’s not 2037, so why did the system think it was?
The OS running the CA was set to sync with NTP every 120 seconds, and it used a really bad NTP client which blindly set the time to whatever the NTP server gave it. No sanity checking, no drifting. Just get the time, set the time. OS logs showed most of the time, the clock adjustment was a fraction of a second. Then some time on Saturday, there was an adjustment of tens of thousands of seconds forward. The next adjustment was hundreds of thousands of seconds forward. Tens of millions of seconds forward. Eventually it hit billions of seconds backwards, taking the system clock back to 1904 or so. The NTP server was racing forward through the 32-bit timestamp space.
At some point, the NTP server handed out a date in 2037 which was after the CA’s expiration. It reissued itself as I described above, and a date math bug resulted in a cert which expired before it was valid. So now we have an explanation for the CRL being so huge. On to the NTP server!
Turns out they had an NTP “appliance” with a radio clock (i.e, a CDMA radio, GPS receiver, etc.). Whoever built it had done so in a really questionable way. It seems it had a faulty internal clock which was very fast. If it lost upstream time for a while, then reacquired it after the internal clock had accumulated a whole extra second, the server didn’t let itself step backwards or extend the duration of a second. The math it used to correct its internal clock somehow resulted in dramatically shortening the duration of a second until it wrapped in 2038 and eventually ended up at the correct time.
Ultimately found three issues:
• An OS with an overly-simplistic NTP client
• A certificate authority with a bad date math system
• An NTP server with design issues and bad hardware
in case there are other nerds out there who haven’t yet read this classic, behold “the case of the 500-mile email” https://www.ibiblio.org/harris/500milemail.html
I adore the “absurd computer-borne mysteries” genre and kindly ask for more content from the annals of y’all’s careers
@RobW That is amazing! I do know how hard that is because my wife made this ...
I suspect we have lots in common :-)
Living in the #wetlands of #Polesia (also spelled #Polesie) in #EasternPoland. Surrounded by #bogs and #forests, trying not to fuck up surrounding nature too much.
Taking care of a small pack of #dogs – #IdąPsięta.
Luddite working with hi-tech.
#RuralBroadband provider by accident. Starting a small LoRaWAN project to monitor our wetlands. Coding in #Python. Dealing with dirty data, cleaning them when time allows.
#Atheist. I don't *believe* in #science – science is the *only* thing that protects us from belief.
Fuck nazis.
My account on Twitter is still up, for good reasons. https://twitter.com/szescstopni
I check facts before I toot.
I sometimes toot in Polish.
Zdolny, ale leniwy.