IRC Logs for #crux Monday, 2011-01-31

pitillogood morning00:58
prologicAnyone here have an Amazon EC2 account ?01:08
tilmanfrinnst: did you ever debug a horribly slow ssh on the sheeva/guruplug? i'm getting 1.6 mb/s from my guru; are 4096 bit keys just too large for its little brain?02:21
entetilman: afaik, the RSA key is only used for authentication, afterwards ssh uses AES or some other symmetric algo07:25
frinnsttilman: nope12:03
frinnstnever tried to transfer anything via ssh other than text :)12:03
entetilman: even my netbook is slow when copying over ssh. I tend to use rsyncd12:07
tilmanente: that's what my coworker told me today, and i was like :O13:01
enteyou can even disallow certain aes versions13:04
tilmani'll look into that13:05
tilmanfwiw, the sheevaplug has aes built into the cpu13:05
tilmanit's not trivial to make the system use it though13:05
enteyes, obviously :(13:05
tilmanfrinnst: btw, they posted the source code for the uapctl thing13:06
enteprobably needs some assembler workaround13:06
tilmanyou need one of marvell's kernel trees13:06
tilmanand a hacked up version of openssl13:06
tilmansomething with OCF or something ;)13:06
tilmanopen crypto framework ..13:07
entehaving aes in the instruction set sounds like a nice idea13:07
frinnstmy guruplug has been collecting dust since pretty much the day i got it :/13:07
entefrinnst: if you don't want it, give it to me :P13:07
tilmanmine's a dsl-router and download thingy :D13:07
frinnsthow's the heat issues these days?13:07
tilmanmy hardware mod has been working perfectly13:07
entewhen I realised there's something like the dockstar out there I was all "omg, do want!"13:07
tilman(nic fixed to 100 mbit/s mode though)13:07
entebut I realised it the minute the price started rising13:08
tilmanente: you were talking about the Ciphers option in sshd_config, right?13:09
entetilman: hold on, I'll ask bluewind13:10
entehe disabled everything except one algorithm to make the scriptkiddies go away13:10
ente(libssh which is what they use, didn't support it until very recently)13:11
ente(and scriptkiddies don't upgrade that frequently)13:11
enteanother friend of mine wrote a honeypot-sshd-implementation, emulating a shell, which collects the commands the kiddies use after login succeeds13:12
ente[20:13] < Bluewind> Ciphers aes256-ctr,aes192-ctr,aes128-ctr13:13
tilmani think aes128-ctr is what i'm using13:18
entemaybe you can configure it clientside as well13:19
enteworks clientside on per-host-basis13:20
tilmanswitching to arcfour gives me a speedup from 1.6 MB/s to 1.9 MB/s13:37
tilmanstill off by a factor of 10 ;)13:38
entehm... try rsyncd :P13:42
tilmanente: lennart's dockstar gets him 8-9 mb/s. ie on basically the same system13:43
tilmanso something's afoot :)13:43
enteI don't use ssh where not necessary, that's all :D13:45
tilmanmaybe i should rebuild openssl14:15
jaegerI've got a bunch of researchers running X apps (AFNI) over SSH, it can be annoyingly slow at times14:16
jaegerusing compression and arcfour,blowfish-cbc seems to be about the best speed I can get14:16
tilmanarcfour128 and arcfour work best for my setup14:18
frinnstwhy isnt gecko-mediaplayer in any (contrib) repo? am i the only one using wierd sites with wmv/real media?14:18
jaegerI've not seen a need for wmv/real in years14:19
jaeger(for me personally)14:19
tilmanfrinnst: yes :p14:19
thrice`I don't even have flash installed any more ;)14:19
jaegerI keep flash installed but have flashblock enabled by default :)14:20
RyoSthrice`: gnash?14:21
RyoSis it usable yet?14:22
tilmanso the openssl command line client seems to deal with aes-128-cbc okay15:15
tilmantimings look okay anyway15:15
tilmanpitillo: do you know anything about _slow_ ssh on crux-arm? :)15:52
*** Nox_fire has joined #crux19:03
*** Nox_fire has quit IRC19:16
andariussalutations and waffles22:59
