Working on this new server in php7...
imc indymedia

Los Angeles Indymedia : Activist News

white themeblack themered themetheme help
About Us Contact Us Calendar Publish RSS
Features
latest news
best of news
syndication
commentary


KILLRADIO

VozMob

ABCF LA

A-Infos Radio

Indymedia On Air

Dope-X-Resistance-LA List

LAAMN List




IMC Network:

Original Cities

www.indymedia.org africa: ambazonia canarias estrecho / madiaq kenya nigeria south africa canada: hamilton london, ontario maritimes montreal ontario ottawa quebec thunder bay vancouver victoria windsor winnipeg east asia: burma jakarta japan korea manila qc europe: abruzzo alacant andorra antwerpen armenia athens austria barcelona belarus belgium belgrade bristol brussels bulgaria calabria croatia cyprus emilia-romagna estrecho / madiaq euskal herria galiza germany grenoble hungary ireland istanbul italy la plana liege liguria lille linksunten lombardia london madrid malta marseille nantes napoli netherlands nice northern england norway oost-vlaanderen paris/Île-de-france patras piemonte poland portugal roma romania russia saint-petersburg scotland sverige switzerland thessaloniki torun toscana toulouse ukraine united kingdom valencia latin america: argentina bolivia chiapas chile chile sur cmi brasil colombia ecuador mexico peru puerto rico qollasuyu rosario santiago tijuana uruguay valparaiso venezuela venezuela oceania: adelaide aotearoa brisbane burma darwin jakarta manila melbourne perth qc sydney south asia: india mumbai united states: arizona arkansas asheville atlanta austin baltimore big muddy binghamton boston buffalo charlottesville chicago cleveland colorado columbus dc hawaii houston hudson mohawk kansas city la madison maine miami michigan milwaukee minneapolis/st. paul new hampshire new jersey new mexico new orleans north carolina north texas nyc oklahoma philadelphia pittsburgh portland richmond rochester rogue valley saint louis san diego san francisco san francisco bay area santa barbara santa cruz, ca sarasota seattle tampa bay tennessee urbana-champaign vermont western mass worcester west asia: armenia beirut israel palestine process: fbi/legal updates mailing lists process & imc docs tech volunteer projects: print radio satellite tv video regions: oceania united states topics: biotech

Surviving Cities

www.indymedia.org africa: canada: quebec east asia: japan europe: athens barcelona belgium bristol brussels cyprus germany grenoble ireland istanbul lille linksunten nantes netherlands norway portugal united kingdom latin america: argentina cmi brasil rosario oceania: aotearoa united states: austin big muddy binghamton boston chicago columbus la michigan nyc portland rochester saint louis san diego san francisco bay area santa cruz, ca tennessee urbana-champaign worcester west asia: palestine process: fbi/legal updates process & imc docs projects: radio satellite tv
printable version - js reader version - view hidden posts - tags and related articles

View article without comments

Random Update Notes

by johnk Spoof Attempt of:e7d6fe675bd4411ed24b6a7e5ed7d4b35 Tuesday, Jul. 29, 2025 at 12:43 PM

A short note about what idVer is.

idVer was a feature to allow people to create semi-verifiable, consistent IDs on this site.

This site has no user database. So how can we tell if someone is who says they're "johnk" is really "johnk"? You can't.

So by filling out the "secret" field, you can produce an idVer value.

Nobody understood this.

Then, I must have shortened the author field at some point, causing a bug, that prevented idVer from being used.

Report this post as:

Continued...

by johnk idVer:e7d6fe675bd4411ed24b6a7e5ed7d4b350041f2a Tuesday, Jul. 29, 2025 at 1:08 PM

Of course, someone could try and just copy paste the author with the idVer part in there. I did that in the OP.

So I added a feature that would flag those attempts.

This was, a pretty half-baked way to do this.

I should have just punted the post if there's an idVer in the author field.

---

Aside from that, there's a whole other problem, where the field is named "secret", and the instructions call it "id verfication code", and then it's labeled as "idVer".

That's so inconsistent. It should be called:

secret

hash

hash:123f23sdfar32r

This is tech jargon, but so what? So is "idVer" and all the other terms. At least "hash" can be searched and you can learn what a hash is from Wikipedia.

So the terms here have to change.

The hash is also way too long. It needs to be turned from a long, 41 char hex value into something like hash:AMZEFSD, a short alpha value.

---

The point of idVer was to make a kind of identity that didn't have a user database. No user database means no accounts, no passwords, nothing.

No OpenID, no OAuth, no nothing.

---

What it doesn't do is integrate with PGP style signatures, which are based on public and private keys. So the posts can be altered by the admin.

Of course, the user can use PGP style signatures, and post the public key after the post.

Report this post as:

Things I overlooked. test post

by johnk Tuesday, Jul. 29, 2025 at 9:29 PM

One thing I overlooked is that the article database is also a user database, once this hash is calculated.

Past uses of the author and secret could be used to verify future uses of the author and secret. If the author forgets the secret, their identity is damaged, going forward.

They'd have to create a new username.

----

Another likely security hole is people using the same password they use for another site. If this site's salts are compromised, then the password can be cracked.

----

As noted before, the more secure solution, to use PGP to sign posts, is better. The problem, of course, is hardly anyone understands it, and even people who understand it, often don't use it.

I searched for a browser extension for PGP GPG and found only one with 90 installs, that's very old.

On Linux, I found kgpg, which is a GUI that manages keys *and* has a gui to sign files and bits of text.

The infrastructure to use GPG is also confusing (to me).

This is all sad :(

---

This username/secret system doesn't really address the actual trust issue - which is whether the person you're reading is even worth reading.

Someone with a consistent ID can be bad.

This site's been "infected" by at least two long-term asses. Aleth, a "communist" who seems to actually be an Italian Catholic Ultranationalist Anti-Semite. Patrice Faubert, an "anarchist" poet who sometimes goes misogynist.

To their credit, they're stalwarts. They spam like machines. Aleth was an anti-Semite long before Gaza, and in a style which was pretty clearly bigoted. Patrice has been on here decades, and the misogyny predated this whole "incel misogyny" thing. I hide Patrice without reading his material mainly because he spams, and harms the site's ranking.

There's also a new person who is a 9/11 truther. I'm flipflopping on them, and might not hide them, if their stuff has some useful info. At this time, they seem to have an axe to grind with the Covert Action Magazine, and defending RFK Jr. I don't like their material, but it merits a closer reading.

The fact I don't agree with someone is not my basis for hiding. It's more about 1. fascism, 2. spamming, 3. conspiracy theory.

Report this post as:

GPG signed

by johnk idVer:e7d6fe675bd4411ed24b6a7e5ed7d4b350041f2a Tuesday, Jul. 29, 2025 at 9:42 PM

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA512

I'll address censoring anti-semitism, because I'm sure someone reading this will assume Aleth is "antizionist" or something like that.

Antizionism isn't hidden on this site. It's been anything from a 0 state, 1 state, 2 state on here. I think nearly every article about Israel-Palestine has sided with Palestine. We've also published Latuff, who's been accused of antisemitism, and, I think, very occasionally, legitimately -- but he's been acceptable.

Aleth's stuff generally feels like conspiracy theory. Since it's in Italian, usually, I autotranslate, and try to guess if it's legit. It's often about the Catholic Church, about which I know almost nothing, so I can only go on a vibe.

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEE68yR68mOiMrmCxoyvFZQoR7fNh4FAmiJQAYACgkQvFZQoR7f

Nh4CWwf+ON7eDLL2a1sk4MWl1+hbden81InpNX15yFsYbxDSwKFM+QgpU0r5FUIY

vJBWdTrN5P5rTjst4dXDpBd/tXD0rAzzlPJd65mktFgPhl57Ayi9yOGlRqj1FZCk

beYajAQfAPVxkYXzb+hjuDD0o0ozDHRD3QK6RJEJoQ2hzd6eB2xfG8tnB7i0USkT

pxPum99UVz+znk+PeMHVER67UPM6H8lXvZOOIzAffPVRJntB8kosoNU1ar+VSg+O

RldU8OBJio30W5ROtCu2LvonEQVcmuDJg39e5iZA53SQGsq6rHCfE/zZ7IeJXG1c

5hbaNDsNd5OoeLeKA55pDyE7Nq7Gww==

=w+cp

-----END PGP SIGNATURE-----

Report this post as:

GPG failed

by johnk idVer:e7d6fe675bd4411ed24b6a7e5ed7d4b350041f2a Tuesday, Jul. 29, 2025 at 9:46 PM

Well, that failed.

The text filtration features on the site altered the posted text, causing the PGP signature to be invalid.

The filtration alters whitespace, and might change the character set (because this software was written before UTF-8 was widespread).

So, I guess PGP won't work on here. LOLz.

Report this post as:

© 2000-2018 Los Angeles Independent Media Center. Unless otherwise stated by the author, all content is free for non-commercial reuse, reprint, and rebroadcast, on the net and elsewhere. Opinions are those of the contributors and are not necessarily endorsed by the Los Angeles Independent Media Center. Running sf-active v0.9.4 Disclaimer | Privacy