Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #185162 > unrolled thread

Unusual LUKS setup

Started byNicolas George <george@nsup.org>
First post2017-08-14 11:50 +0200
Last post2017-08-14 16:50 +0200
Articles 20 on this page of 21 — 8 participants

Back to article view | Back to linux.debian.user


Contents

  Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 11:50 +0200
    Re: Unusual LUKS setup Darac Marjal <mailinglist@darac.org.uk> - 2017-08-14 12:20 +0200
      Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 16:40 +0200
        Re: Unusual LUKS setup Bastien Durel <bastien@durel.org> - 2017-08-14 17:10 +0200
          Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 18:00 +0200
            Re: Unusual LUKS setup Bastien Durel <bastien@durel.org> - 2017-08-16 10:10 +0200
              Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 15:40 +0200
    Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-14 12:30 +0200
      Re: Unusual LUKS setup tomas@tuxteam.de - 2017-08-14 16:40 +0200
        Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 18:10 +0200
          Re: Unusual LUKS setup tomas@tuxteam.de - 2017-08-14 21:30 +0200
        Re: Unusual LUKS setup Curt <curty@free.fr> - 2017-08-15 14:20 +0200
          Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-15 17:30 +0200
            Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 21:10 +0200
              Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 04:50 +0200
                Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-16 09:40 +0200
                  Re: Unusual LUKS setup Zenaan Harkness <zenaan@freedbms.net> - 2017-08-16 15:30 +0200
          Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 21:00 +0200
            Re: Unusual LUKS setup Brian <ad44@cityscape.co.uk> - 2017-08-15 21:40 +0200
              Re: Unusual LUKS setup <tomas@tuxteam.de> - 2017-08-15 22:20 +0200
      Re: Unusual LUKS setup Nicolas George <george@nsup.org> - 2017-08-14 16:50 +0200

Page 1 of 2  [1] 2  Next page →


#185162 — Unusual LUKS setup

FromNicolas George <george@nsup.org>
Date2017-08-14 11:50 +0200
SubjectUnusual LUKS setup
Message-ID<uekav-2tS-27@gated-at.bofh.it>
Hi.

I have been using LUKS to encrypt part of my system, with a rather
unusual setup, and I would like to ask for advice on making it more
standard without sacrificing my requirements.

My requirements are:

- Protect me from casual invasions of my privacy in case the computer 
  were stolen.

- Being able to unlock the system remotely through SSH.

- Minimize the duration of the second-longest interval between required
  manual operation during boot.

  Which translate in practice by: minimize the time between the first
  interaction I must have with Linux and the moment I have an usable
  session.
  
- Minimize the number of keystrokes required during boot.

The second point requires an explanation. Like many people, in the
morning I switch on this computer with the following sequence: start the
boot, go take care of physiological needs, finish the boot. During the
longest part of the boot, I am somewhere else, hence my focus on the
second longest part. Since the duration of the POST is incompressible,
the longest part of the boot is usually the time between pressing the
power button and the first interaction required by Linux.

My current solution to achieve this consists in the following steps:

- The system partitions are not encrypted. The partitions containing
  personal data are encrypted using LUKS.
  
- I have a shell script that asks me for the passphrase once and uses it
  to unlock all the partitions, and I have configured sudo to be able to
  run that script without authentication.
  
- I have a minimalistic home on the system partition with a SSH key that
  allows me to log in, and a shell startup file that automatically runs
  the shell script to unlock.
  
- I also have an user with an empty password whose login shell is a
  script that invokes the shell script to unlock.
  
- I have configured systemd to only launch xdm when the partitions have
  been unlocked.
  
With the following scheme, the system boots fully automatically and
becomes functional, except the personal data is not mounted. I can log
in through SSH and unlock and mount it. Or I can log in on the text
console to unlock and mount it, and then wait a few seconds for xdm to
start.

It all works rather well, but I wonder if there are more supported ways
of achieving the same result.

Regards,

-- 
  Nicolas George

[toc] | [next] | [standalone]


#185163

FromDarac Marjal <mailinglist@darac.org.uk>
Date2017-08-14 12:20 +0200
Message-ID<uekDw-2U0-11@gated-at.bofh.it>
In reply to#185162

[Multipart message — attachments visible in raw view] — view raw

On Mon, Aug 14, 2017 at 11:27:00AM +0200, Nicolas George wrote:
>Hi.
>
>I have been using LUKS to encrypt part of my system, with a rather
>unusual setup, and I would like to ask for advice on making it more
>standard without sacrificing my requirements.
>
>My requirements are:
>
>- Protect me from casual invasions of my privacy in case the computer
>  were stolen.
>
>- Being able to unlock the system remotely through SSH.
>
>- Minimize the duration of the second-longest interval between required
>  manual operation during boot.
>
>  Which translate in practice by: minimize the time between the first
>  interaction I must have with Linux and the moment I have an usable
>  session.
>
>- Minimize the number of keystrokes required during boot.
>
>The second point requires an explanation. Like many people, in the
>morning I switch on this computer with the following sequence: start the
>boot, go take care of physiological needs, finish the boot. During the
>longest part of the boot, I am somewhere else, hence my focus on the
>second longest part. Since the duration of the POST is incompressible,
>the longest part of the boot is usually the time between pressing the
>power button and the first interaction required by Linux.

It sounds to me, then, that you'd like the system to be unencrypted, but 
your home to be encrypted. You want to look into PAM, which I'm sure can 
do this. With PAM, the system would come up and all the system daemons 
would start. Towards the end of that (or perhaps earlier, depending on 
the dependencies), login methods (getty / x-display-manager / sshd / 
etc) would become available. You'd log in on one of those and PAM would 
ensure that your home is decrypted as part of the session start-up. 

A quick google suggests that pam_mount is your friend here. I *think* 
that pam_mount should be able to mount other directories (as well as 
home), so if you have a media partition that you'd like mounted, that 
can be done.


-- 
For more information, please reread.

[toc] | [prev] | [next] | [standalone]


#185189

FromNicolas George <george@nsup.org>
Date2017-08-14 16:40 +0200
Message-ID<ueoH8-5ij-11@gated-at.bofh.it>
In reply to#185163
Le septidi 27 thermidor, an CCXXV, Darac Marjal a écrit :
> It sounds to me, then, that you'd like the system to be unencrypted, but
> your home to be encrypted.

Indeed, that is exactly what I have now.

>			     You want to look into PAM, which I'm sure can do
> this. With PAM, the system would come up and all the system daemons would
> start. Towards the end of that (or perhaps earlier, depending on the
> dependencies), login methods (getty / x-display-manager / sshd / etc) would
> become available. You'd log in on one of those and PAM would ensure that
> your home is decrypted as part of the session start-up.
> 
> A quick google suggests that pam_mount is your friend here. I *think* that
> pam_mount should be able to mount other directories (as well as home), so if
> you have a media partition that you'd like mounted, that can be done.

Thanks for the pointer. Unfortunately:

- If you use SSH, you have to adjust /etc/ssh/sshd_config like this:

  UsePAM yes
  UsePrivilegeSeparation no
  ChallengeResponseAuthentication no
  PasswordAuthentication yes

The second and last point are both deal breakers on their own. Plus,
glimpsing at the rest of the documentation, I do not see how it is
better than mounting the partition from the session's startup scripts.

Regards,

-- 
  Nicolas George

[toc] | [prev] | [next] | [standalone]


#185193

FromBastien Durel <bastien@durel.org>
Date2017-08-14 17:10 +0200
Message-ID<uepaa-5HJ-9@gated-at.bofh.it>
In reply to#185189
Le lundi 14 août 2017 à 16:17 +0200, Nicolas George a écrit :
> - If you use SSH, you have to adjust /etc/ssh/sshd_config like this:
> 
>   UsePAM yes
>   UsePrivilegeSeparation no
>   ChallengeResponseAuthentication no
>   PasswordAuthentication yes

You don't. pam_mount will ask you for your password (after ssh
authentication) if you didn't provided one

-- 
Bastien

[toc] | [prev] | [next] | [standalone]


#185195

FromNicolas George <george@nsup.org>
Date2017-08-14 18:00 +0200
Message-ID<uepWA-60G-69@gated-at.bofh.it>
In reply to#185193
Le septidi 27 thermidor, an CCXXV, Bastien Durel a écrit :
> You don't. pam_mount will ask you for your password (after ssh
> authentication) if you didn't provided one

Thanks for the clarification. If you are right, then you probably should
file a bug report for outdated documentation.

But still, "UsePrivilegeSeparation no" is a deal breaker on its own.

Regards,

-- 
  Nicolas George

[toc] | [prev] | [next] | [standalone]


#185332

FromBastien Durel <bastien@durel.org>
Date2017-08-16 10:10 +0200
Message-ID<uf1yN-4Ab-7@gated-at.bofh.it>
In reply to#185195
Le lundi 14 août 2017 à 17:35 +0200, Nicolas George a écrit :
> Le septidi 27 thermidor, an CCXXV, Bastien Durel a écrit :
> > You don't. pam_mount will ask you for your password (after ssh
> > authentication) if you didn't provided one
> 
> Thanks for the clarification. If you are right, then you probably
> should
> file a bug report for outdated documentation.
> 
> But still, "UsePrivilegeSeparation no" is a deal breaker on its own.
> 
> Regards,
> 
In my setup (openssh 7.5), there is no UsePrivilegeSeparation setting,
it's on by default. And pam_mount is able to mount my encrypted
partitions when I log via SSH.

Regards,

-- 
Bastien

[toc] | [prev] | [next] | [standalone]


#185350

FromZenaan Harkness <zenaan@freedbms.net>
Date2017-08-16 15:40 +0200
Message-ID<uf6Ia-7Ci-9@gated-at.bofh.it>
In reply to#185332
On Wed, Aug 16, 2017 at 09:48:23AM +0200, Bastien Durel wrote:
> Le lundi 14 août 2017 à 17:35 +0200, Nicolas George a écrit :
> > Le septidi 27 thermidor, an CCXXV, Bastien Durel a écrit :
> > > You don't. pam_mount will ask you for your password (after ssh
> > > authentication) if you didn't provided one
> > 
> > Thanks for the clarification. If you are right, then you probably
> > should
> > file a bug report for outdated documentation.
> > 
> > But still, "UsePrivilegeSeparation no" is a deal breaker on its own.
> > 
> > Regards,
> > 
> In my setup (openssh 7.5), there is no UsePrivilegeSeparation setting,
> it's on by default. And pam_mount is able to mount my encrypted
> partitions when I log via SSH.

If you need Goliath-OS compatible volumes, a year or so ago I managed
to script Veracrypt for a friend's "home" folder (forgotten what
that's even called on Windows sorry), and so they feel safe to be
able to 'upgrade' to any real operating system in the future.

[toc] | [prev] | [next] | [standalone]


#185164

From<tomas@tuxteam.de>
Date2017-08-14 12:30 +0200
Message-ID<uekNb-2XS-5@gated-at.bofh.it>
In reply to#185162
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Aug 14, 2017 at 11:27:00AM +0200, Nicolas George wrote:
> Hi.
> 
> I have been using LUKS to encrypt part of my system, with a rather
> unusual setup, and I would like to ask for advice on making it more
> standard without sacrificing my requirements.

[...]

> - The system partitions are not encrypted. The partitions containing
>   personal data are encrypted using LUKS.

I tend to the other extreme: everything (save /boot) is encrypted,
as one big (physical, in the LVM sense) volume. Partitions whithin
it are logical (LVM) volumes. Yes, that's more or less the standard
Debian way.

Among other things this gives me peace of mind about (copies of)
sensitive data hanging around /var (/var/lib/postgresql, for example,
has a copy of my banking transactions history somewhere).

This brings the "LUKS question" to the earliest point, namely when
trying to mount /.

Now SSH... to fulfill that in this setting, the initramfs must have
some ssh server capability. I've heard that you can bake in dropbear
SSH in the initramfs, which sounds pretty elegant. Never tried, though.

Downside would be that now you've got *two* sshd instances to take
care of, security-wise.

No idea about how (or whether) that interacts with systemd (and
honestly, not very keen on finding out :)

Perhaps you knew all of this, but perhaps this gives you some ideas.

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmReqIACgkQBcgs9XrR2kb9igCZASe/htbyVdUGTjU3GzSS2tL4
ougAnA6rwQGe9EPJshxhFsraDfOAMDiT
=R3Jm
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#185190

Fromtomas@tuxteam.de
Date2017-08-14 16:40 +0200
Message-ID<ueoH8-5ij-21@gated-at.bofh.it>
In reply to#185164
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Aug 14, 2017 at 04:26:09PM +0200, Nicolas George wrote:
> Le septidi 27 thermidor, an CCXXV, tomas@tuxteam.de a écrit :
> > I tend to the other extreme [...]

> No, it is not the earliest point [...]

I see. Still, you could perhaps use your trick to "collect" the
passphrase early.

[...]

> It would also require duplicating the network setup in the initrd:

This, OTOH, is definitely more serious, and makes your current
approach more attractive for your use case.

[...]

> You seem to be suffering from a systemd obsession, maybe you should
> consult a therapist about that :-Þ

And you are either prey to a God complex (knowing better what's right
for others) or a helper syndrome. Or both.

- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmRtccACgkQBcgs9XrR2kZYXwCaA+1Esl+gShs+ioMsjKmecqSX
oVgAnR+unHn6E01ZyOH91NJ6M3RhoVqt
=j9Ya
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#185197

FromNicolas George <george@nsup.org>
Date2017-08-14 18:10 +0200
Message-ID<ueq6f-6jm-39@gated-at.bofh.it>
In reply to#185190
Le septidi 27 thermidor, an CCXXV, tomas@tuxteam.de a écrit :
> I see. Still, you could perhaps use your trick to "collect" the
> passphrase early.

Even if I could find a convenient way to enter the pass phrase as early
as the bootloader, it cannot happen before the end of the POST, and the
POST is a significant part of the boot time.

Since it is not possible to enter the pass phrase at the very beginning
of the boot, the very end it must be to fulfill my requirements.

> And you are either prey to a God complex (knowing better what's right
> for others) or a helper syndrome. Or both.

What makes you say that? I did not pretend that I know better what is
right for you.

But systemd has absolutely nothing to do with the discussion for now,
and yet you brought it up for no apparent reason.

Regards,

-- 
  Nicolas George

[toc] | [prev] | [next] | [standalone]


#185209

Fromtomas@tuxteam.de
Date2017-08-14 21:30 +0200
Message-ID<uetdL-89B-1@gated-at.bofh.it>
In reply to#185197
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Aug 14, 2017 at 05:43:04PM +0200, Nicolas George wrote:
> Le septidi 27 thermidor, an CCXXV, tomas@tuxteam.de a écrit :
> > I see. Still, you could perhaps use your trick to "collect" the
> > passphrase early.
> 
> Even if I could find a convenient way to enter the pass phrase as early
> as the bootloader, it cannot happen before the end of the POST, and the
> POST is a significant part of the boot time.
> 
> Since it is not possible to enter the pass phrase at the very beginning
> of the boot, the very end it must be to fulfill my requirements.

Understood.

> > And you are either prey to a God complex (knowing better what's right
> > for others) or a helper syndrome. Or both.
> 
> What makes you say that? I did not pretend that I know better what is
> right for you.

Hm. Proposing I see a doctor because I don't want to deal with systemd
was a bit asking for it (tongue-in-cheek noted, granted).

> But systemd has absolutely nothing to do with the discussion for now,
> and yet you brought it up for no apparent reason.

I just stated that it might interact (it *has* interacted with LUKS
passphrase entering in the past, remember) and that's not me the one
to find that out.

Another, perhaps crazy approach (if you have the right motherboard)
might be coreboot :)

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmR+YoACgkQBcgs9XrR2kZO3wCfYEnqRSm0EqvtdKzjU6qf/iT6
M5IAnAmjUFMw/dH+qXoO/yy2LTC0xiJg
=b0+b
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#185252

FromCurt <curty@free.fr>
Date2017-08-15 14:20 +0200
Message-ID<ueIZc-1d4-11@gated-at.bofh.it>
In reply to#185190
On 2017-08-14, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
>
>
> And you are either prey to a God complex (knowing better what's right
> for others) or a helper syndrome. Or both.
>

Christ! What happened to Little Goody Two-Shoes?

-- 
"If you want to build a ship, don’t herd people together to collect
wood and don’t assign them tasks and work, but rather teach them to
long for the endless immensity of the sea." — Antoine de Saint-Exupéry 

[toc] | [prev] | [next] | [standalone]


#185273

FromZenaan Harkness <zenaan@freedbms.net>
Date2017-08-15 17:30 +0200
Message-ID<ueLX4-30v-17@gated-at.bofh.it>
In reply to#185252
On Tue, Aug 15, 2017 at 12:13:21PM +0000, Curt wrote:
> On 2017-08-14, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
> >
> >
> > And you are either prey to a God complex (knowing better what's right
> > for others) or a helper syndrome. Or both.
> >
> 
> Christ! What happened to Little Goody Two-Shoes?

This is a family friendly list, so we ought not take the Lord's name
in vain ... and neither should we assert God complexes on one another
- we're humans and ought show a little tolerance toward one another.

Besides, --I'm-- the only one around here whom you may deify - for
all this humility that just bursts out of ... out of ... THAT's
right!! ME :)

:D

[toc] | [prev] | [next] | [standalone]


#185307

From<tomas@tuxteam.de>
Date2017-08-15 21:10 +0200
Message-ID<uePnY-5ik-23@gated-at.bofh.it>
In reply to#185273
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Aug 16, 2017 at 01:28:13AM +1000, Zenaan Harkness wrote:
> On Tue, Aug 15, 2017 at 12:13:21PM +0000, Curt wrote:

[...]

> > Christ! What happened to Little Goody Two-Shoes?
> 
> This is a family friendly list,

You sure?

>                                 so we ought not take the Lord's name
> in vain ... and neither should we assert God complexes on one another
> - we're humans and ought show a little tolerance toward one another.

I try, I try.

> Besides, --I'm-- the only one around here whom you may deify - for
> all this humility that just bursts out of ... out of ... THAT's
> right!! ME :)
> 
> :D

Guru no enough? ;-D

Cheers
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmTRLUACgkQBcgs9XrR2kaO2QCcDGSv8zMhh8CEuF8nvuNfrngu
0qsAn165Y/k3T8xnj95ili6opzT44MZ8
=f3kF
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#185325

FromZenaan Harkness <zenaan@freedbms.net>
Date2017-08-16 04:50 +0200
Message-ID<ueWz7-1gX-5@gated-at.bofh.it>
In reply to#185307
On Tue, Aug 15, 2017 at 09:00:05PM +0200, tomas@tuxteam.de wrote:
> On Wed, Aug 16, 2017 at 01:28:13AM +1000, Zenaan Harkness wrote:
> > On Tue, Aug 15, 2017 at 12:13:21PM +0000, Curt wrote:
> 
> [...]
> 
> > > Christ! What happened to Little Goody Two-Shoes?
> > 
> > This is a family friendly list,
> 
> You sure?

Of that I am absolutely certain :)

You see, a year or three back a certain Code of Conduct or "CoC" was
instituted with "the Debian community".

And further, a certain self foresaw certain (to his self) self
evident problems with this newly minted and well intentioned if
grandiose and subtly yet fundamentally problematic community polemic
undoubtedly soon to <ahem> expose itself.

And further yet, this certain self took it upon his certain self to
be certain in his ultimately self deprecating, yet cheeky (if
persistent) "in your FACE, Debian!" type of tantrum about this newly
minted Rule Of Authority, otherwise swung around the place as a Code
of Conduct, "Official" no less :)

Such swinging of sarcastic sultry parodies in fractally self
referential factual and entirely blunt alludings to double entendrés
between the lines overloading the sugar spoiled cotton wool
generations in the name of the glorious, glorious authority of the
CoC, for some strange and almost unfathomable reason, utterly failed
to go unnoticed, especially when such tendrés hit the -project list
as well.

Make no mistake, there was no mistake to ensure no mistakes in
comprehension of the fractually parodic irony at stake for all future
generations of Debianistas :)

And so, further further yet, one slightly sad yet admittedly
belligerently ironic and in-your-face parodic poster, was thereafter
and thereby banned (and truly, somewhat predictably) from this here
very list!

And further still from all other glorious Debian lists :,(

Fear not dear empath - no tears were shed, instead shed were
temerity, uncertainty, fear and dread!

And so, bold and justified, sure in the truth of the self-parody and
petty tyranny thereby exposed for the world to see, this certain self
cackled as a hyena might, on into the night, with delight :D

Yes, you heard that's right, the Debian CoC reared its authoritarian
head in the face of my raising the very issue that it might be swung
in our faces and ultimately be somewhat detrimental to our community.

So careful there, my tentative cotton-wool busting friends, your
friendly order in the Debian realm may not quite as it seems in the
face of wild swinging humour parties. Words! Words I tell you -
powerful, mighty words they are, have no doubt.

Speak. Speak your truth. Speak it clearly and boldly and with ne'er
an apology.

Then be silent.

Let the world digest your words and continue quietly to make it a
better place, and all shall be well in your heart.

Carpé diem, all,
Z



> > so we ought not take the Lord's name
> > in vain ... and neither should we assert God complexes on one another
> > - we're humans and ought show a little tolerance toward one another.
> 
> I try, I try.
> 
> > Besides, --I'm-- the only one around here whom you may deify - for
> > all this humility that just bursts out of ... out of ... THAT's
> > right!! ME :)
> > 
> > :D
> 
> Guru no enough? ;-D
> 
> Cheers
> -- t
> 

[toc] | [prev] | [next] | [standalone]


#185330

From<tomas@tuxteam.de>
Date2017-08-16 09:40 +0200
Message-ID<uf15L-498-11@gated-at.bofh.it>
In reply to#185325
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Aug 16, 2017 at 12:48:58PM +1000, Zenaan Harkness wrote:
> On Tue, Aug 15, 2017 at 09:00:05PM +0200, tomas@tuxteam.de wrote:
> > On Wed, Aug 16, 2017 at 01:28:13AM +1000, Zenaan Harkness wrote:
> > > On Tue, Aug 15, 2017 at 12:13:21PM +0000, Curt wrote:
> > 
> > [...]
> > 
> > > > Christ! What happened to Little Goody Two-Shoes?
> > > 
> > > This is a family friendly list,
> > 
> > You sure?
> 
> Of that I am absolutely certain :)
> 
> You see, a year or three back a certain Code of Conduct or "CoC" was
> instituted with "the Debian community".
> 
> And further, a certain self foresaw certain [...]

Oh, goody. Now I'm all dizzy %-)

But that seems to be the all too old tale of Scylla and Charybdis,
did I get that right?

Cheers
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmT9VQACgkQBcgs9XrR2kbNUQCffu2g3o0EEbWGwup3YUlt8eUR
lhUAn1kZZ6Uc/d/pOREVgu85TD7UujBB
=hgyu
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#185349

FromZenaan Harkness <zenaan@freedbms.net>
Date2017-08-16 15:30 +0200
Message-ID<uf6yt-7z9-17@gated-at.bofh.it>
In reply to#185330
On Wed, Aug 16, 2017 at 09:33:40AM +0200, tomas@tuxteam.de wrote:
> On Wed, Aug 16, 2017 at 12:48:58PM +1000, Zenaan Harkness wrote:
> > On Tue, Aug 15, 2017 at 09:00:05PM +0200, tomas@tuxteam.de wrote:
> > > On Wed, Aug 16, 2017 at 01:28:13AM +1000, Zenaan Harkness wrote:
> > > > On Tue, Aug 15, 2017 at 12:13:21PM +0000, Curt wrote:
> > > 
> > > [...]
> > > 
> > > > > Christ! What happened to Little Goody Two-Shoes?
> > > > 
> > > > This is a family friendly list,
> > > 
> > > You sure?
> > 
> > Of that I am absolutely certain :)
> > 
> > You see, a year or three back a certain Code of Conduct or "CoC" was
> > instituted with "the Debian community".
> > 
> > And further, a certain self foresaw certain [...]
> 
> Oh, goody. Now I'm all dizzy %-)
> 
> But that seems to be the all too old tale of Scylla and Charybdis,
> did I get that right?

Oh absolutely :)

(Although I am gifted with the jaw-dropping humility of Odysseus,
I only wish I also had the muscles and golden locks of Ulysses ;D
)

[toc] | [prev] | [next] | [standalone]


#185306

From<tomas@tuxteam.de>
Date2017-08-15 21:00 +0200
Message-ID<uePei-4Zy-17@gated-at.bofh.it>
In reply to#185252
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, Aug 15, 2017 at 12:13:21PM +0000, Curt wrote:
> On 2017-08-14, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
> >
> >
> > And you are either prey to a God complex (knowing better what's right
> > for others) or a helper syndrome. Or both.
> >
> 
> Christ! What happened to Little Goody Two-Shoes?

You just sent me down a cultural rabbit hole. Thank you for that ;-)

Cheers
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmTRCgACgkQBcgs9XrR2kZa0QCfUr3gVfawea29B8B5e8JZryz6
6Y8Ani+yARk7yntPWMDj/pCaWmgCY5fF
=3yZp
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#185311

FromBrian <ad44@cityscape.co.uk>
Date2017-08-15 21:40 +0200
Message-ID<uePR0-5sj-13@gated-at.bofh.it>
In reply to#185306
On Tue 15 Aug 2017 at 20:57:44 +0200, tomas@tuxteam.de wrote:

> On Tue, Aug 15, 2017 at 12:13:21PM +0000, Curt wrote:
> > On 2017-08-14, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
> > >
> > >
> > > And you are either prey to a God complex (knowing better what's right
> > > for others) or a helper syndrome. Or both.
> > >
> > 
> > Christ! What happened to Little Goody Two-Shoes?
> 
> You just sent me down a cultural rabbit hole. Thank you for that ;-)

Were you muttering "I'm late! I'm late! For a very important date!" at
the time?

(You like puzzles. Work that one out, :) )

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#185317

From<tomas@tuxteam.de>
Date2017-08-15 22:20 +0200
Message-ID<ueQtI-5Vx-11@gated-at.bofh.it>
In reply to#185311
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, Aug 15, 2017 at 08:35:56PM +0100, Brian wrote:
> On Tue 15 Aug 2017 at 20:57:44 +0200, tomas@tuxteam.de wrote:
> 
> > On Tue, Aug 15, 2017 at 12:13:21PM +0000, Curt wrote:
> > > On 2017-08-14, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
> > > >
> > > >
> > > > And you are either prey to a God complex (knowing better what's right
> > > > for others) or a helper syndrome. Or both.
> > > >
> > > 
> > > Christ! What happened to Little Goody Two-Shoes?
> > 
> > You just sent me down a cultural rabbit hole. Thank you for that ;-)
> 
> Were you muttering "I'm late! I'm late! For a very important date!" at
> the time?
> 
> (You like puzzles. Work that one out, :) )

Now *this* one I kew :-)

thanks
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmTVvAACgkQBcgs9XrR2kaHTACeMgmE42T8HVCC6BTjwGbEAE8Z
VPwAnRkHUzgrUG/Pcc4HKsG7QIpi7P9J
=zafo
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web