DGPLUG Summer Training Logs for 2018/06/26

13:30 : kushal #startclass
13:30 : Roll call
13:30 : j605 i_am_romeo: something like `tmp = s2[0:len(s2)-i] + ' ' + s2[len(s2)-i:len(s2)]`
13:30 : ankit774 Ankit Upadhyay
13:30 : prabhu Prabhu Sharan Singh
13:30 : GeekyShacklebolt Shiva Saxena
13:30 : newrg Rajat Gupta
13:30 : gutsytechster Prashant Sharma
13:30 : kushal Kushal Das
13:30 : vshuklajr Vivek Shukla
13:30 : storymode_7 Mayank Singhal
13:30 : pr97 Priyanka Sharma
13:30 : sidntrivedi012 Siddhant N Trivedi
13:30 : j605 Jagannathan Tiruvallur Eachambadi
13:30 : brute4s99 Piyush Aggarwal
13:30 : Aironly Deep
13:30 : ash_mishra Ashish Kumar Mishra
13:30 : prokbird tabrez khan
13:30 : Rakshit__ Rakshit Airani
13:30 : siddharth Siddharth Sahoo
13:30 : vait Vaibhav Triathi
13:30 : schubisu Robin Schubert
13:30 : garima Garima Gill
13:30 : devesh_verma Devesh Verma
13:30 : priyankasaggu119 Priyanka Saggu
13:30 : RatanShreshtha Ratan Kulshreshtha
13:30 : poojaencoded pooja kumari singh
13:30 : prarora98 Prateek Arora
13:30 : kvy kumar vipin yadav
13:30 : mzeeqazi Muhammad Zeeshan Qazi
13:30 : pooja pooja sulakhe
13:30 : Sarques Gajendra Saraswat
13:30 : jaydeep Jaydeep Borkar
13:30 : bhavin192 Bhavin Gandhi
13:30 : akshayg96 Akshay Gaikwad
13:31 : cypher_ Naman Sharma
13:31 : kps Karan Pratap
13:31 : sourabh1031 Sourabh Pruthi
13:31 : ananyo Ananyo Maiti
13:31 : i_am_romeo Aman Garcha
13:31 : snandi Shamik Nandi
13:33 : meanjeet Manjeet mehta
13:33 : darkJedi Akshay Iyer
13:33 : vishalIRC Vishal Kushwaha
13:34 : kushal Okay.
13:34 : codejacker ankur vishwakarma
13:34 : kushal Let us first do a review for the opsec chapter I pointed yesterday.
13:34 : VirtualRcoder shubham sharma
13:34 : kushal Any questions? ! please
13:34 : ankit774 !
13:34 : VirtualRcoder Roll call:Shubham Sharma
13:35 : poojaencoded !
13:35 : prokbird !
13:35 : kushal next
13:35 : ankit774 what if the password database got compromised?
13:35 : kushal ankit774, that is why choose a very strong master password :)
13:36 : next
13:36 : ankit774 kushal, ok
13:36 : kushal ankit774, also do you use a password manager which you can not trust
13:36 : ankit774 kushal, currently i use nothing; i will see to it
13:36 : i_am_romeo !
13:36 : adityad97 Roll call: Aditya Deshpande
13:37 : kushal ankit774, In the training, we can only suggest
13:37 : next
13:38 : ananyo !
13:38 : prokbird !
13:39 : kushal next
13:39 : ankit774 kushal, i haven't got time for now; cause this is kind of new for me; so i need to devote a lot of time, to learn and make use of the password manager; lets hope this weekend allows me to do the same.
13:39 : schubisu kushal, I think batul's queue wasn't empty
13:39 : kushal next
13:39 : priyankasaggu119 !
13:40 : kushal schubisu, yeah that is a bug
13:40 : next
13:40 : next
13:40 : poojaencoded I,was not able to attend last classes.So today is my first day
13:40 : kushal poojaencoded, no problem, you will just have to read the logs and catch up.
13:40 : prokbird got error while installing diceware using command sudo dnf install diceware.
13:40 : brute4s99 loved the DEFCON talk by Christopher Soghoian, cyber! It's all about perspective and choice of words, cyber!
13:40 : prokbird Failed to synchronize cache for repo 'fedora-HandBrake', disabling.
13:40 : Last metadata expiration check: 2:10:23 ago on Tue Jun 26 16:41:52 2018.
13:40 : No package diceware available.
13:40 : Error: Unable to find a match.
13:40 : kushal prokbird, which version of Fedora?
13:41 : prokbird older one, f24
13:41 : kushal prokbird, meanwhile please use the pip install method
13:41 : prokbird, ah, F24 is end of life.
13:41 : Please use a modern version of LInux
13:41 : prokbird ok
13:41 : j605 prokbird: also update to F28
13:41 : kushal prokbird, using such old linux is scary when it comes to security
13:41 : next
13:41 : prokbird j605, sure
13:41 : i_am_romeo kushal, can the encrypted usb be decyrbted and compromised ?
13:41 : poojaencoded ok
13:42 : kushal i_am_romeo, yes, if the passphrase is easy
13:42 : i_am_romeo kushal, ok
13:43 : kushal next
13:43 : ananyo Is it possible to generate passphrases with alphanumeric values with diceware as per some condition?
13:43 : gozmit Rollcall : Mayank
13:43 : kushal ananyo, I don't know, alphanumeric does not add much extra security
13:44 : Just use longer passphrases, fill free to add one extra word from the language you speak :)
13:44 : ananyo Yeah but certain websites do need to have them
13:44 : kushal ananyo, yeah, add that manually
13:44 : next
13:44 : priyankasaggu119 a)Firstly, the owning attacks can be done on mobile devices also?b)we usually use search engine for various shell scripts to solve our problem. Now, Is there any way to check whether those shell scripts will end up into some malicious act or not? Like there is a way to check for the URls or shortened URL s.
13:44 : ananyo kushal, ok
13:45 : kushal priyankasaggu119, a: yes, b: there is a way against those web based attacks, we will talk about it today (a bit).
13:46 : priyankasaggu119 ok kushal.
13:46 : kushal next
13:46 : Okay, going back to LYM
13:47 : Any questions till the chapters we have asked you to read?
13:47 : ankit774 !
13:47 : kushal It is okay to ask questions.
13:47 : next
13:47 : ankit774 about the links. i don't get it
13:47 : is it kind of pointer?
13:48 : kushal ankit774, which links?
13:48 : ankit774 soft and hard links
13:48 : kushal ankit774, Have you seen any shortcuts on Windows?
13:48 : kps_ !
13:48 : ankit774 kushal, yes
13:49 : kushal next
13:49 : ankit774, those are the softlinks
13:50 : Saksham_19o9 Roll Call : Saksham Srivastava
13:50 : kvy !
13:50 : ankit774 but when i made a softlink, it was present in that folder
13:50 : https://askubuntu.com/questions/108771/what-is-the-difference-between-a-hard-link-and-a-symbolic-link
13:50 : kushal next
13:50 : kvy kushal, a> How could i delete an environment variable ?
13:50 : kushal, b> My terminal is working correct with echo hello. but echo 'hello' is right command.
13:50 : kushal, c> Is updatedb command add indexes in front of all our files i mean how it works ?
13:51 : D1nz Roll call: dinesh
13:51 : ankit774 here it says that in syntax, you need to give a source and destination.
13:51 : kushal a> I just export an empty value
13:51 : ankit774, we will try to help you after the sesson.
13:51 : ankit774 kushal, ok
13:52 : Saksham_19o9 !
13:52 : kushal b> read the info page, seriously I never noticed :)
13:52 : c> it indexes all the files in the filesystem
13:53 : next
13:53 : siddharth_ !
13:53 : kvy ok thanks kushal
13:53 : Saksham_19o9 is any link given for today?
13:53 : kushal Saksham_19o9, no
13:53 : next
13:53 : sourabh1031 kvy echo hello gives hello in my machine as well
13:53 : kps !
13:54 : vshuklajr in echo hello . hello will be treated as variable , right ?
13:54 : kvy sourabh1031, yes but correct command is echo 'hello'
13:54 : vshuklajr, no
13:54 : siddharth_ What is the significance of a execute permission in a text file ? Because with read and execute permission the file can be opened.Then what is the significance of execute permission in text files ?
13:54 : kvy it's echo $hello
13:54 : siddharth_ ^^kushal
13:55 : ^^ kushal What is the significance of a execute permission in a text file ? Because with read and execute permission the file can be opened.Then what is the significance of execute permission in text files ?
13:56 : kushal siddharth_, for example, python or any other scripting language is written in text files.
13:57 : so if you have execute permission and a proper shabang line, it will execute properly.
13:57 : next
13:57 : kps Can just clicking on unknown links be sufficient to casuse a possibility of compromise or not until i install some third party app that link points me to?
13:58 : kushal kps, in many cases linking is enough to compromise
13:58 : I don't have any example right now, but, we will have more sessions with better examples.
13:59 : kps Ok kushal
13:59 : kushal next
13:59 : vishalIRC !
14:00 : kushal next
14:00 : caffeinatednerd !
14:00 : vishalIRC Is it safe to watch webstreams of Fifa? with all those ads opening?
14:01 : kushal vishalIRC, I don't know which site you are using. I guess the official sites are okay.
14:01 : next
14:01 : caffeinatednerd Why can't we encrypt external hard disks for backing up our data?
14:01 : vishalIRC kushal eg. ronaldo7.net
14:01 : kushal vishalIRC, I don't know, sorry.
14:01 : Guest23142 !
14:01 : kushal I also don't open by clicking random urls :)
14:02 : caffeinatednerd, who said you can not?
14:02 : vishalIRC kushal, Ok thanks !
14:02 : caffeinatednerd Yesterday, you said that we should use pen drives for backing up data
14:02 : kushal caffeinatednerd, I said USB drives.
14:03 : caffeinatednerd Why didn't you mentioned hard disks as they can store large amount of data.
14:03 : Sarques vishalIRC that's a very popular site, i don't think they will do anything absurd and also ads are way to earn money when a site has that much of traffic:)
14:03 : kushal vishalIRC, you should always try to block ads
14:03 : caffeinatednerd kushal, okay, my fault.
14:03 : Sarques vishalIRC but we can never be certain!(sadly)
14:03 : kushal caffeinatednerd, no problem :)
14:03 : vishalIRC Sarques, Google is a very popular site :)
14:03 : caffeinatednerd kushal, USB = Pendrives for me
14:03 : vishalIRC Sarques, yeah ^ agree.
14:04 : kushal caffeinatednerd, hehe
14:04 : next
14:04 : Guest23142 what we will learn in today's class?
14:05 : kushal Guest23142, we will learn about patience.
14:05 : Sarques vishalIRC yes, they do have an eye on our searches so as to give us ads of our likes, and that makes there possibilities of earning money even more high.
14:05 : kushal Okay, new things:
14:05 : or rather few more questions from me.
14:06 : Who all already watched the two documentaries we shared?
14:06 : newrg me
14:06 : kvy me
14:06 : vishalIRC me
14:06 : kushal We gave you the names.
14:06 : cypher_ me
14:06 : Guest23142 me
14:06 : kps Me
14:06 : vara1 which was the second one?
14:06 : sourabh1031 Only one
14:06 : ashwani Me
14:06 : ananyo watched one, citizenfour is half watched
14:07 : siddharth_ me
14:07 : GeekyShacklebolt me
14:07 : priyankasaggu119 1 -Nothing to hide.
14:07 : vshuklajr i watched citizenfour
14:07 : ash_mishra I watched citizenfour
14:07 : kushal First citizenfour and then Nothing to hide.
14:07 : vshuklajr Yet to watch Nothing to hide
14:07 : kps Watched all 3
14:07 : mzeeqazi citizenfour done, Internet's own boy done, Nothing to hide upto 1hr done
14:08 : newrg I have watched Internet's own boy and citizen four,yet to watch nothing to hide
14:08 : prokbird watched citizenfour only.
14:08 : kushal For the people who never knew about citizenfour, any comments after watching it?
14:08 : vishalIRC citizen 4 is really well directed, creepy at times.
14:09 : mzeeqazi kushal quite difficult to appreciate
14:09 : kushal vishalIRC, creepy in which sense?
14:09 : mzeeqazi, difficult as in?
14:09 : kps It was awesome; i had heard about es but never thought it was actually filmed; inspired !
14:09 : caffeinatednerd I didn't watched Citizen 4. But I have seen the Snowden movie
14:09 : kushal caffeinatednerd, vishalIRC please type the proper names.
14:10 : vshuklajr amazing, just as the point of view of film making in general
14:10 : vishalIRC kushal, in the sense that NSA has such capabilities.
14:10 : mzeeqazi kushal, lot of information with some heavy concepts
14:10 : kushal Any other comments?
14:10 : ortusolis Watched Internet's own boy and Citizenfour long back. Nothing to hide is incomplete at the moment.
14:10 : kushal What do you think about your own data now?
14:10 : prabhu I have watched the Snowden movie
14:10 : prokbird an eye opening documentary
14:11 : mzeeqazi kushal, all visible to tech giants
14:11 : prabhu Also, I've studied about Snowden. He is a hero.
14:11 : cypher_ I got enlightened about how our privacy is ruined by some intelligence agencies.
14:11 : prabhu NSA has the power to watch me through my webcam right now. That's how creepy it is.
14:11 : kushal Who all are yet to watch Citizenfour?
14:11 : ortusolis kushal, sad state of affairs. Only way to ensure security is to lock down ourselves from the internet. Even Tor's security is dependent on the end nodes.
14:11 : kushal prabhu, Yup.
14:11 : vshuklajr Don't to whom to trust . Seems like whole system is corrupt
14:11 : Saksham_19o9 watched nothing to hide and internet's own boy
14:12 : ash_mishra kushal, I read about Edward Snowden, and got to know that he is the president of Freedom of the Press Foundation, where you are a staff member. :)
14:12 : vishalIRC it's one thing to know that NSA spies, another to see the scale and power of its infrastructure.
14:12 : pdas no real privacy anymore
14:12 : vshuklajr *know
14:12 : ash_mishra Amazing documentary
14:12 : Saksham_19o9 me, citizenfour.
14:12 : kushal Who all are yet to watch Citizenfour?
14:12 : jaydeep me
14:12 : prabhu me
14:12 : prokbird kushal, i saw the guy used the gpg email.How to configure for that?
14:12 : kushal anyone else?
14:12 : ananyo me
14:12 : pr97 me
14:12 : ankit774 me
14:12 : kushal prokbird, we will teach you that, no worries :)
14:12 : priyankasaggu119 me
14:12 : ashwani Me
14:12 : brute4s99 ME
14:12 : rishibit me
14:12 : brute4s99 sorry caps was on
14:12 : inkaps me
14:12 : kushal brute4s99, :)
14:12 : i_am_romeo me
14:13 : Rakshit__ me
14:13 : prokbird kushal, thanks :)
14:13 : kps Kushal yay
14:13 : ananyo Yeah the gpg email really got my attention !
14:13 : snandi me
14:13 : kushal Please watch it as soon as possible :)
14:13 : Saksham_19o9 please give the link to citizenfour
14:13 : prabhu Snowden risked his life to get the data the proofs of Mass Surveilance to public. Julian Assange helped him
14:13 : ananyo https://youtube.com/watch?v=EDhB-A23IUk
14:14 : jaydeep kushal,sure :)
14:14 : sourabh1031 Me
14:14 : Aironly me
14:14 : mzeeqazi Saksham_19o9, duckduckgo it
14:14 : Saksham_19o9 i did. there is just trailers
14:14 : prabhu Random question. Does anyone know about Bradley Manning here?
14:14 : kushal everyone please stop.
14:15 : cypher_ !
14:15 : kushal next
14:15 : cypher_ What is a hacker? One who doubts -- @Snowden what does this mean?
14:15 : kps_ !
14:15 : kushal cypher_, That is quote from Snowden.
14:15 : cypher_, we will pass you the link to those talks.
14:16 : kps_, are you trying to type !
14:16 : kps Yes
14:16 : sidntrivedi012 !
14:16 : cypher_ i couldn't understand this,"One who Doubts"
14:17 : kushal kps, type it properly ;)
14:17 : Who wants to explain doubt to cypher_ ?
14:17 : newrg cypher_: read this http://www.catb.org/esr/faqs/hacker-howto.html
14:17 : kps Kushal :)
14:17 : cypher_ sorry I didn't get that?
14:18 : newrg cypher_: an essay about hackers by a hacker
14:18 : prabhu cypher_, Hacker is the one who doubts the system, one who doubts how things are happening, one who doubts everything.
14:19 : kushal next
14:19 : cypher_ prabhu: Now I get it, Thanks!
14:19 : kps !
14:19 : kushal next
14:19 : kps_ Suppose an individual is not at all aware of the fact that he is under survelliance; then how can we say that he doesn't have liberty because as long as the subject doesn't know he is under watch, he will be free at mind right?
14:19 : prabhu kushal, was my answer satisfying?
14:19 : kushal prabhu, ask cypher_ :)
14:20 : ankit774 cypher, hacker is someone who pushes technology to the front; uses it for innovation and invention; plays with new things in a helpful manner; 'hacker' is not a negative word
14:20 : prabhu kushal, he got it :)
14:20 : kushal kps_, nope, say if someone is clicking your photos from your computer whole day, how come you be free at mind?
14:21 : kps_ yds in that case we know that we are being watched
14:21 : newrg kps_: Propaganda works best when those who are being manipulated are confident they are acting on their own free will. -Joseph Goebbels(Nazi)
14:21 : kps_ ktshal yes exactly; thanks
14:21 : kps Kushal*
14:22 : siddharth_ kushal, I am leaving. Some urgent work to do.
14:22 : prabhu kps_, he won't be free at mind when the hacker uses the recorded surveillance videos or photos to manipulate him.
14:22 : kushal siddharth_, okay
14:22 : kps_ prabhu no thats not the context of my question
14:22 : i think kushal solved it
14:23 : kushal Moving to next topix.
14:23 : * topic
14:23 : Who all here does not have a blog or does not know what is blogging? Say me in the channel.
14:23 : newrg me
14:24 : Saksham_19o9 me
14:24 : farhan_ me
14:24 : vshuklajr me
14:24 : ankit774 me
14:24 : vishalIRC me
14:24 : mzeeqazi me
14:24 : pdas me
14:24 : cypher_ me
14:24 : snandi me
14:24 : meanjeet me
14:24 : kps_ ktshal know what a blog is but don't have a blog
14:25 : prabhu I have just wrote one blog til now.
14:25 : ananyo have a blog but don't blog regularly
14:25 : prabhu till*
14:26 : Rakshit__ thought about it, never got to actually doing it :p no idea what i'd blog about
14:26 : vara1 me
14:26 : Sarques me
14:26 : kushal heavy rain this side
14:26 : I may disconnect
14:26 : sidntrivedi012 !
14:26 : prabhu kushal, okay
14:27 : kushal For the blogging: read this chapter from jasonbraganza https://summertraining.readthedocs.io/en/latest/blogging.html
14:27 : prabhu kushal, What to do when you disconnect?
14:27 : devesh_verma I don't have a blog.
14:27 : kushal Also for tonight's reading: https://theintercept.com/2018/06/25/att-internet-nsa-spy-hubs/
14:28 : I will end the class now, but we will continue the discussion.
14:28 : Also things to do tonight: open a blog at wordpress.com
14:28 : kvy ok kushal
14:28 : Sarques kushal yep
14:29 : devesh_verma Okay
14:29 : ankit774 kushal, ok
14:29 : kps_ ktshal sure
14:29 : snandi ok
14:29 : ash_mishra kushal, is it necessary for everyone to write a blog?
14:29 : kps_ does that read ktshal?
14:29 : kushal ash_mishra, Yes.
14:29 : bhavin192 kps_, yes
14:29 : ash_mishra kushal, Why?
14:29 : kushal ash_mishra, read the chapter to know why
14:30 : ash_mishra kushal, ok
14:30 : kushal after you have created your blog, please add it to this page
14:30 : https://pad.riseup.net/p/dgplug18
14:30 : kps_ bhavin192 i think this irc client has a bug
14:30 : kushal I have added two example there.
14:30 : sidntrivedi012 kushal, sorry,I couldn't ask the question.My question is- why doesn't diceware provide a password with special characters.it only provides alphabets.
14:31 : kushal sidntrivedi012, special characters do not make the passwords strong.
14:31 : j605 sidntrivedi012: long words have more entropy(difficult to guess even for a computer)
14:31 : kushal Please stay online at least till 9pm and discuss here.
14:32 : i will end the session now.