Domain: gmail.com
Stories and comments across the archive that link to gmail.com.
Stories · 2,907
-
Scholarships From FOSS Organizations?
Athaulf writes "I'm a high school kid with big dreams of prestigious technology schools like MIT or Cal-Tech. The problem is, my upper-middle class family had more down to Earth plans for me and my college choices (about $30,000/year more down to Earth, actually), so financial aid and college savings won't come anywhere near MIT's price tag. However, I've been programming in C for a while now, and might release a GPL'd Linux app soon. With this self-taught programming experience, academic merit, and plenty of extra curricular activities, are there any FOSS supporting organizations who might grant me a scholarship for my contributions? Do companies like Google or Red-Hat offer scholarships to big name schools in return for a few years of work after college?" -
Ubuntu 8.04 Beta Released
markybob writes "Ubuntu Hardy 8.04 beta has been released. It features GNOME 2.22 and uses Linux kernel 2.6.24. Furthermore, it uses Firefox 3 beta 4, and PulseAudio is enabled by default. To ease the transition of Windows users, it includes Wubi, which allows users to install and uninstall Ubuntu like any other Windows application. It does not require a dedicated partition, nor does it affect the existing bootloader, yet users can experience a dual-boot setup almost identical to a full installation." -
Gen Y Workers Reinventing IT for the Better
buzzardsbay writes "We all know the complaints about young employees. They depend too much on their parents' money, they need constant hand-holding, they have no job loyalty, they demand more than they're worth, they disrespect older employees, and they're naive about corporate culture. But despite this conventional wisdom, there's growing evidence that the different working styles of Gen Y workers might be causing fundamental — and beneficial — changes in the way enterprises run, especially when it comes to IT. For example, they may show better judgment when making tech purchases and are often better with green IT initiatives. This is a nice counterpoint to a previous story (and resulting incendiary comments) that dubbed young tech workers a risk to corporate networks." -
Can REDFLY sell in an EeePC market?
palmsolo (aka Matthew Miller) writes "I was lucky enough to get a chance to evaluate an early beta of the REDFLY device and just posted some initial impressions at ZDNet. As a person who commutes on the train 2 hours every day and usually always has a Windows Mobile device in tow, this is actually a perfect device for me; real productivity is possible with text entry and enjoy surfing on a larger display. However, at $500 can this device really compete in the Asus EeePC market or will it die like the Palm Foleo?" -
Young Employees Pose Increasing Risk to Networks
buzzardsbay writes "Baseline is reporting on an upcoming survey from Symantec and Applied Research-West that confirms many suspicions about the generation gap in the workplace, namely that younger workers will use your corporate network to run most any device, technology or social networking software they can get their hands on. Dubbed "Millenials," these workers born after 1980 are nearly twice as likely to use cell phones and PDAs at work, and half admit to installing unauthorized software on their employer's computers. On the upside, the Millenials are more security aware than their older co-workers." -
Newly Discovered Fungus Threatens World Wheat Crop
RickRussellTX writes "The UN reports that a variety of the rust fungus originally detected in Uganda in 1999 has already spread as far north as Iran, threatening wheat production across its range. The fungus infects wheat stems and affects 80% of wheat varieties, putting crops at risk and threatening the food sources for billions of people across central Asia. Although scientists believe they can develop resistant hybrids, the fungus is moving much faster than anticipated and resistant hybrids may still be years away. Meanwhile, national governments in the path of the fungus are telling folks that there is nothing to worry about." -
WiiWare Week Round Up
Mark Graham writes "All this week, UK games development site Develop has been running a series of articles under its 'WiiWare Week' banner, analyzing developer's affections for, and the potential success of Nintendo's upcoming WiiWare digital distribution platform. Most revealing is the claim that Nintendo has been secretly 'waging war' on the likes of Sony and Microsoft by capitalizing on frustrations over cuts to the Xbox Live Arcade royalty rate (down from 70% to 35% for any game making under $4m in revenue) and talking up the service's access to a wide audience to win over development support. It features commentary from both established developers (such as David Braben, creator of Elite, and Scott Orr, creator of Madden) — and indie teams (developers of new WiiWare games Pop and Gravitronix) making launch games for the service." -
Why Don't We Invent That Tomorrow?
museumpeace writes "In the NYTimes book review blog, David Itzkoff takes a look at a new book devoted to predicting which 'science fiction' technologies may really fly some day. The author is Michio Kaku, one of the inventors of string theory, so he bears a hearing. His picks include light sabers, invisibility and force fields." Which sci-fi tech do you think needs to get invented over the weekend? -
A Congressman Who Can Code Assembly
christo writes "In what appears to be a first, the US House of Representatives now has a Congressman with coding skills. Democratic Representative Bill Foster won a special election this past Saturday in the 14th Congressional District of Illinois. Foster is a physicist who worked at Fermilab for 22 years designing data analysis software for the lab's high energy particle collision detector. In an interview with CNET today, Foster's campaign manager confirmed that the Congressman can write assembly, Fortran and Visual Basic. Will having a tech-savvy congressman change the game at all? Can we expect more rational tech-policy? Already on his first day, Foster provided a tie-breaking vote to pass a major ethics reform bill." -
Net Neutrality Blasted by MPAA Bosses
proudhawk writes "The LA Times is reporting that the MPAA's Dan Glickman has taken another swipe against net neutrality at his recent ShoWest appearance. 'Glickman argued in his speech that neutrality regulations would bar the use of emerging tools that ISPs can use to prevent piracy. That's what some studio lobbyists have been telling lawmakers, too, in their efforts to derail neutrality legislation. And depending on how the regulations are written, they could be right.'" -
MPAA Touts Record Year For Hollywood
proudhawk writes "A blog posting in p2pnet today catches MPAA boss Dan Glickman at the ShoWest convention in Las Vegas crowing about Hollywood's profitable year: 'Today, we stand on a new mountaintop, and I have to say: I like the view... We had about 5 percent growth in both the domestic and worldwide box office, all-time highs on both fronts reminding us once again that good stories well told always find a place in our hearts, our lives and our local theaters.' What ever happened to the ravages of online piracy?" -
IT Labor Shortage Is Just a Myth
buzzardsbay writes "For the past few years, we've heard a number of analysts and high-profile IT industry executives, Bill Gates and Craig Barrett among them, promoting the idea that there's an ever-present shortage of skilled IT workers to fill the industry's demand. But now there's growing evidence suggesting the "shortage" is simply a self-serving myth. "It seems like every three years you've got one group or another saying, the world is going to come to an end there is going to be a shortage and so on," says Vivek Wadhwa, a professor for Duke University's Master of Engineering Management Program and a former technology CEO himself. "This whole concept of shortages is bogus, it shows a lack of understanding of the labor pool in the USA."" -
European Space Agency Launches New Orbital Supply Ship
erik.martino brings us a story about the European Space Agency's successful launch of a new type of cargo ship to resupply the ISS. The first Automated Transport Vehicle (ATV), named after Jules Verne, is the "very first spacecraft in the world designed to conduct automated docking in full compliance with the very tight safety constraints imposed by human spaceflight operations." Among other things, it carries water, oxygen, and propellant to help boost the ISS to a higher orbit. We recently discussed NASA's need for a new cargo transport system. Quoting: "Beyond Jules Verne, ESA has already contracted industry to produce four more ATVs to be flown through to 2015. With both ESA's ATV and Russia's Progress, the ISS will be able to rely on two independent servicing systems to ensure its operations after the retirement of the US space shuttle in 2010. It incorporates a 45-m3 pressurised module, derived from the Columbus pressure shell, and a Russian-built docking system, similar to those used on Soyuz manned ferries and on the Progress re-supply ship. About three times larger than its Russian counterpart, it can also deliver about three times more cargo." -
Hitchhiker's Guide Turns 30
XaN-ASMoDi writes "Yesterday saw the 30th anniversary of the very first broadcast of Douglas Adam's seminal work, "The Hitchhiker's Guide to the Galaxy", to mark this, Mark Vernon has written an article for the BBC News Magazine on the answer to The Question. 'It's 30 years since Douglas Adams' The Hitchhiker's Guide to the Galaxy made its debut on BBC radio, but its most famous mystery is still waiting to be resolved...'" -
Bill Allows Teachers to Contradict Evolution
Helical writes "In an attempt to defy the newly approved state science standards, Florida Senator Rhonda Storms has proposed a bill that would allow teachers to contradict the teaching of evolution. Her bill states that 'Every public school teacher in the state's K-12 school system shall have the affirmative right and freedom to objectively present scientific information relevant to the full range of scientific views regarding biological and chemical evolution in connection with teaching any prescribed curriculum regarding chemical or biological origins.' The bill's main focus is on protecting teachers who want to adopt alternative teaching plans from sanction, and to allow teachers the freedom to teach whatever they wish, even if it is in opposition to current standards." -
Aging Security Vulnerability Still Allows PC Takeover
Jackson writes "Adam Boileau, a security consultant based in New Zealand has released a tool that can unlock Windows computers in seconds without the need for a password. By connecting a Linux machine to a Firewire port on the target machine, the tool can then modify Windows' password protection code and render it ineffective. Boileau said he did not release the tool publicly in 2006 because 'Microsoft was a little cagey about exactly whether Firewire memory access was a real security issue or not and we didn't want to cause any real trouble'. But now that a couple of years have passed and the issue has not resolved, Boileau decided to release the tool on his website." -
The Ruby Programming Language
bdelacey writes "In January 2008, just in time for Ruby's 15th birthday, O'Reilly published The Ruby Programming Language. The co-authors make a strong writing team. Yukihiro (Matz) Matsumoto created Ruby. David Flanagan previously wrote Java In a Nutshell and JavaScript: The Definitive Guide — he has a CS degree from MIT with a concentration in writing. Drawings are the work of Rubyist-extraordinaire why the lucky stiff and technical reviewers include well known Rubyists David A. Black, Charles Oliver Nutter, and Shyouhei Urabe." Read on for the rest of Brian's review. The Ruby Programming Language author David Flanagan & Yukihiro Matsumoto with drawings by why the lucky stiff pages 444 publisher O'Reilly rating 9/10 reviewer Brian DeLacey ISBN 0-596-51617-7 summary A classic and comprehensive guide to Ruby. According to the Preface, Flanagan and Matz modeled this book after the K&R "white book" — The C Programming Language by Brian Kernighan and Dennis Ritchie. Like the "white book", The Ruby Programming Language has a simple structure and provides complete coverage. Just as K&R served as the de facto standard for "C", The Ruby Programming Language will likely be seen as the most authoritative language book for Ruby. Flanagan and Matz provide the following guidance for their readers:
"Because this book documents Ruby comprehensively, it is not a simple book (though we hope that you find it easy to read and understand). It is intended for experienced programmers who want to master Ruby and are willing to read carefully and thoughtfully to achieve that goal. ... [T]his book takes a bottom-up approach to Ruby: it starts with the simplest elements of Ruby's grammar and moves on to document successively higher-level syntactic structures from tokens to values to expressions and control structures to methods and classes. This is a classic approach to documenting programming languages." (p. 17)
You'll read all about boolean flip-flops, duck typing, lambdas, maps, metaprogramming, reflection and patterns of rhyming methods (collect, select, reject, and inject!). You'll also learn about new features in Ruby 1.9, like fundamental changes to text for Unicode support and the introduction of fibers fo coroutines. If it's in Ruby, it's almost certainly in this book. Chapters flow together nicely, although some could even stand on their own as educational materials for a computer science course (e.g. Chapter 7: Classes and Modules covers object-oriented programming and Chapter 8: Reflection and Metaprogramming elaborates on concepts like hooks, tracing, and thread safety).
In Ruby programming, difficult tasks are typically not only possible but often easy. It seems the authors take the same approach in their writing. For example, the complex topic of Domain Specific Languages (DSLs) sometimes creeps into deep discussions involving Ruby. Flanagan and Matz describe it simply and clearly: "A DSL is just an extension of Ruby's syntax (with methods that look like keywords) or API that allows you to solve a problem or represent data more naturally than you could otherwise." (p. 296)
During Ruby's first ten years, nearly two dozen books were in print in Japan but very few were available in English. That changed in 2004 when the introduction of Ruby on Rails created momentum for the language. A flood of new books followed, including Programming Ruby (2004, 2nd edition), The Ruby Way (2006, 2nd edition), Ruby for Rails (2006), and Learning Ruby (2007).
Programming Ruby, with lead author Dave Thomas, is self-described as a "tutorial and reference for the Ruby programming language." The Ruby Way, by Hal Fulton, was intended to complement Programming Ruby. Fulton noted: "There is relatively little in the way of introductory or tutorial information." Ruby for Rails, by David A. Black, has a clearly defined audience: "This book is an introduction to the Ruby programming language, purpose-written for people whose main reason for wanting to know Ruby is that they're working with, or are interested in working with, the Ruby on Rails framework." Learning Ruby, by Michael Fitzgerald, is a 238-page survey for "experienced programmers who want to learn Ruby, and new programmers who want to learn to program."
Programming Ruby and The Ruby Way each weigh in at over 800 pages. The binding on my copy of The Ruby Way came unglued and split in the middle after a year of use. The Ruby Programming Language is a slim, more manageable 444 pages and, in contrast, is the only one to cover Ruby version 1.9. In general, this is a great example of "less is more". Informative text boxes are sprinkled across the book with brief highlights on key technical thoughts. The first chapter's text box on "Other Ruby Implementations" (e.g. JRuby, IronRuby, Rubinius) could, however, be expanded into a several-page discussion of Ruby's various interesting architectures. Inclusion of IDEs and development tools (e.g. Eclipse, NetBeans, and TextMate) might also be helpful. These topics would nicely round out Chapter 10: The Ruby Environment.
The Ruby Programming Language has excellent cross-referencing. Section signs () feel like embedded HTML links that enable you to easily follow your coding curiosity around the book. Or you can just read it the old fashioned way, straight through. As an example, Chapter 3: Datatypes and Objects has subheadings (e.g. 3.1 Numbers) and well defined sections (e.g. 3.1.3 Arithmetic in Ruby.) The page-footers, table of contents and index also provide efficient navigational aids.
Artwork at the "edge of abstract expressionism" is something you might expect from The New Yorker magazine, but a computer book? The Ruby Programming Language introduces readers to "the edge of graphite expressionism". Original "smudgy residue" pencil drawings by why the lucky stiff creatively start each chapter.The Beatles' album cover for Sgt. Pepper's Lonely Hearts Club Band sparked intrigue and investigations into coded messages with hidden meanings. The same could happen here.
In Words and Rules: The Ingredients of Language, author Steven Pinker asks a simple question: "How does language work?" When I think about a new programming language, I have the same type of question in mind: "How does this language work?" Flanagan and Matz provide the answers in outstanding fashion. The Ruby Programming Language should help seasoned programmers who want to master Ruby. In addition, there is enough structure and sample code for determined novices to begin their programming explorations. Better than any other, this book defines the language. It is a classic and comprehensive guide for Ruby and a great 15th birthday present.
One long-time Rails developer sent me an email with their first impressions of The Ruby Programming Language: "I have been finding the book very useful, and I'm glad I did get it sooner rather than later." Matz said "Ruby is designed to make programmers happy." It looks like similar design thinking went into this book.
Brian DeLacey volunteers for the Boston Ruby Group
You can purchase The Ruby Programming Language from amazon.com. Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page. -
United Tech Bids $2.6B for Diebold
zhang1983 writes "United Technologies, parent company of jet engine-maker Pratt & Whitney, Otis elevator and Sikorsky Aircraft, said it made the unsolicited offer to Diebold for $2.63 billion on Friday after trying to negotiate a deal for two years. United Technologies said the company announced the offer Sunday night because executives believe their offer is "so compelling we thought shareholders should know about it."" -
158 Pages of Microsoft's Dirty Laundry
KrispyRasher writes "Even internally, Microsoft couldn't agree on what the base requirements to run Vista were, but that didn't stop it from inaccurately promoting the OS as running on some hardware. 158 pages of Microsoft internal emails reveal scandalous truths about the squabbles that took place in the lead up to Vista's launch." -
Microsoft Cuts Vista Price In 70 Countries
dforristall alerts us to an odd move by Microsoft: cutting the price of retail boxes of Vista in many markets. Analysts didn't see this one coming, and they are scratching their heads a bit over it; one called it "very unheard of." The price cuts vary by country — they're largest in the developing world where piracy levels are high — and they don't apply to OEM copies of Vista, which account for 90% of sales. "Gartner analyst Michael Silver said the move... is puzzling... [He] noted that the market for such upgrades is fairly limited. Those who bought XP in the fourth quarter of 2006 got a coupon for a free Vista upgrade, while most of those who have bought systems since then have gotten Vista. Machines purchased prior to 2006 probably aren't all that attractive as candidates for a Vista upgrade... 'The whole notion of upgrading PCs has sort of fallen by the wayside.'" -
Gaffes That Keep IT Geeks From the Boardroom
buzzardsbay writes "Yes, it's all in good fun to point out the mismatched belt and shoes and the atrocious hairstyles, but honestly, I'm committing three of these errors right now! Is that why I can't get a key to the executive washroom? Or is it my rebellious attitude and pungent man-scent that's keeping me down? The shocker in here was pigtails on women... I love pigtails on women!" -
iPhone SDK May Be 1-3 Weeks Late
tuxeater123 writes "According to a blog posting at BusinessWeek.com, the iPhone SDK could be pushed back by another 1-3 weeks. Unfortunately, the evidence provided, such as the media announcements that are usually made before most Apple releases, suggests that this may indeed be true. Apple usually sticks to their announced deadlines, however they have been known to break them occasionally." -
RMS Steps Down As Emacs Maintainer
sigzero writes "Short but sweet: RMS is stepping down as Emacs Maintainer: 'From: Richard Stallman, Subject: Re: Looking for a new Emacs maintainer or team, Date: Fri, 22 Feb 2008 17:57:22 -0500 Stefan and Yidong offered to take over, so I am willing to hand over Emacs development to them." -
Nanotechnology-Powered Wiper-Less Windshield
fab writes "Italian car designer Leonardo Fioravanti (who worked for Pininfarina for a number of years) has developed a car prototype without windshield wipers. This amazing technological feat is made possible thanks to the use of 4 layers of glass modified using nanotechnology. The first layer filters the sun and repels the water. The second layer, using 'nano-dust' is able to push dirt to the side. The third layer acts as a sensor that activates the second layer when it detects dirt, while the fourth layer is a conductor of electricity to power this complex mechanism. I haven't been able to find an English article, but there is always a google powered translation of the Italian article." -
In-Home Wireless Vs. Mobile Broadband
mklickman writes "I've been hearing more and more about mobile broadband offered by the big wireless phone providers, and for the first time came to ask myself how it compares to using a wireless router. Since my wife and I both have laptops, and we're out a lot, would it be wise and/or worth it to do away with the standard cable-modem-plus-router setup and switch over to mobile broadband with (for example) AT&T or Sprint? I'm not really concerned about the cost of the PC cards themselves; they're not much more expensive than a decent router. Also, the cost of the wireless service per month is only (roughly) ten dollars more than my current ISP is charging me. Is it a good idea?" -
Gates Explains Microsoft's Need for Yahoo
eldavojohn writes "Perhaps it's obvious to you and perhaps you'll be pleasantly surprised by his answer but Gates revealed to CNet why Microsoft needs Yahoo. From his response, "We have a strategy for competing in the search space that Google dominates today, that we'll pursue that we had before we made the Yahoo offer, and that we can pursue without that. It involves breakthrough engineering. We think that the combination with Yahoo would accelerate things in a very exciting way, because they do have great engineers, they have done a lot of great work. So, if you combine their work and our work, the speed at which you can innovate and get things done is just dramatically more rapid. So, it's really about the people there that want to join in and create a better search, better portal for a very broad set of customers. That's the vision that's behind saying, hey, wouldn't this be a great combination."" -
How to Convert Your HD-DVD Discs to Blu-Ray
eldavojohn writes "Are you one of the few who boarded the HD-DVD Titanic ship headed to the bottom of ocean to join BetaMax? Fret no longer, friend, simply convert those and pretend like you never invested in the wrong technology! All you need is a Windows machine with a fast processor, an HD-DVD drive, a Blu-Ray burner, 30GB of free disk space, at least, though 40GB or more is recommended and an internet connection to download the software! Or you can sit and be the crazy guy who continues to argue that HD-DVD is the superior technology whether it's true or not." -
Google Funds Work for Photoshop on Linux
S point 2 writes "Google has announced that they have hired Codeweavers, maker of the popular Wine software to make Photoshop run better on Linux. 'Photoshop is one of those applications that desktop Linux users are constantly clamoring for, and we're happy to say they work pretty well now...We look forward to further improvements in this area.' It is unknown whether or not the entire Creative Suite will be funded for support, but for the time being it seems Photoshop-on-Linux development is getting a new priority under Google." -
Hacking: The Art of Exploitation
David Martinjak writes "Hacking: The Art of Exploitation is authored by Jon Erickson and published by No Starch Press. It is the anticipated second edition of Erickson's earlier publication of the same title. I can't think of a way to summarize it without being over-dramatic, so it will just be said: I really liked it. The book, which will be referred to as simply Hacking, starts by introducing the author's description of hacking. Erickson takes a great approach by admitting that the common perception of hacking is rather negative, and unfortunately accurate in some cases. However, he smoothly counters this antagonistic misunderstanding by presenting a simple arithmetic problem. A bit of creativity is needed to arrive at the correct solution, but creativity and problem-solving are two integral aspects of hacking, at least to Erickson. The introduction chapter sets an acceptable tone and proper frame of mind for proceeding with the technical material." Below you'll find the rest of David's review. Hacking: The Art of Exploitation, 2nd Edition author Jon Erickson pages 472 publisher No Starch Press rating 9 reviewer David Martinjak ISBN 1-59327-144-1 summary An informative, and authoritative source on hacking and exploit techniques. Chapter 2 enters the subject of programming. The first few sections in the chapter may feel a bit slow to readers who have been coding for any legitimate length of time. Erickson explains some fundamental, yet essential, concepts of programming before finally moving into some actual code. Some readers may choose to skip these few pages, but they are necessary for brave new adventurers in the dark realm of development. The remainder of the chapter certainly compensates for any perceived slow-start. Each of the remaining sections presents a sufficient quantity of technical information, accompanied by descriptive, yet straightforward explanations.
I don't mean to disrupt the chronological progression of the book review, but it is important to highlight the excellence of the explanations provided in Hacking. Throughout the book, the writing provides adequate details and the content is to the point. Many sources on exploit techniques supply sparse information, or are too wordy and often miss the relevant and important concepts. Erickson does a phenomenal job in Hacking of explaining each subject in just the right manner.
The third chapter is the staple of the book. This chapter covers buffer overflows in both the stack and the heap, demonstrates a few different ways that bash can aid in successfully exploiting a process, and provides an essentially all-encompassing elaboration of format string vulnerabilities and exploits. As I said, this is the main portion of the book so I don't want to give away too much material here. Undoubtedly, though, this chapter has the best explanation of format string attacks that I have ever read. The explanations in Chapter 3, like the rest of the book, are of substantial value.
Chapter 4 focuses on a range of network-related subjects. At first I wondered why the chapter starts with rather basic concepts like the OSI model, sockets, etc. Then I realized it was consistent with the earlier chapters. Hacking presents some core concepts, then moves on to utilizing them in exploits. In this case, these specific concepts and techniques just hadn't been covered yet. The exploit toward the end of this chapter includes some of the concepts in the previous chapter, which also helps to cement the reader's understanding.
I will mention two main shortcomings. First, the material in the "Denial of Service" section of the Networking chapter was unnecessary for this book. Attacks like the Ping of Death, and smurfing were interesting developments when they were first discovered, and effective on a large scale. Now in 2008, almost all of the items in the "Denial of Service" section are either outdated or have been covered to an excessive extent. Rather than denial of service, I would have preferred to see a section on integer attacks. This would have fit perfectly with the book's theme as there are several issues surrounding numeric types in C of which many programmers are unaware. Considering the fact that the book is about hacking and much of the code is in C; integer attacks seem like a natural component to include. The second pitfall in this review is through a fault of my own. I cannot compare this second edition of Hacking with its original, first edition release as I unfortunately do not own the first edition. Hacking finishes out the second half of the book with chapters on shellcode, countermeasures, and cryptology. The chapter on cryptology is especially interesting as it contains a good mix of information without being too hardcore on the mathematics involved. There are plenty of gems in the shellcode and countermeasures chapters, as well. Specifically, Erickson does a stellar job of explaining return-(in)to-libc attacks, and dealing with the address space layout randomization in Linux. He covers the exploit technique for linux-gate.so in a randomized memory space before it was fixed in 2.6.18, then proceeds to demonstrate a different technique for successful exploitation on kernels at 2.6.18 and later.
Undeniably, Hacking: The Art of Exploitation is one of the quintessential books for its subject. A book this good is a rare find, and certainly worth the read for any individual interested in security.
David Martinjak is a programmer, GNU/Linux addict, and the director of 2600 in Cincinnati, Ohio. He can be reached at david.martinjak@gmail.com.
You can purchase Hacking: The Art of Exploitation, 2nd Edition from amazon.com. Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page. -
Cringely Looks at the WikiLeaks Debacle
dtwood writes "Infoworld's Cringely has an interesting take on the Julius Baer bank trying to silence WikiLeaks.org — and how stunningly stupid they've been. 'But the bank's solution is so mind-bogglingly stupid, you have to wonder if these guys need help getting their pants on each morning. First, this is exactly the kind of story bloggers and Net-centric journos crave. Big nasty corporation stomps all over plucky public-serving underdog. Who can resist that plot line? Second, the equation Bank Julius Baer = Money Laundering is now firmly cemented in the minds of everyone who has encountered this story, regardless of whether it's true. Trois: The documents in question, which might have been quickly forgotten alongside the 1.2 million others on the site, are now hotter than the Paris Hilton sex video. Dozens of mirror sites have sprung up, and Cryptome.org and PirateBay have squirreled away copies of the docs for any interested parties. " -
Can Scientists Dance?
cHALiTO writes "John Bohannon has a nice article in science magazine asking a simple question: can scientists dance? "The rules were simple: Using no words or images, interpret your Ph.D. thesis in dance form."" The answer to the question is, that some of the brightest minds, have no shame and some of the most challenged feet. -
U of MI Produces Strongest Laser Ever
eldavojohn writes "Weighing in at a mere 20 billion trillion watts per square centimeter and containing a measly 300 terawatts of power, the University of Michigan has broken a record with a 1.3-micron speck wide laser. It's about two orders of magnitude higher than any other laser in the world and can perform for 30 femtoseconds once every ten seconds — some of the researchers speculate it is the most powerful laser in the universe. 'If you could hold a giant magnifying glass in space and focus all the sunlight shining toward Earth onto one grain of sand, that concentrated ray would approach the intensity of a new laser beam made in a University of Michigan laboratory ... To achieve this beam, the research team added another amplifier to the HERCULES laser system, which previously operated at 50 terawatts. HERCULES is a titanium-sapphire laser that takes up several rooms at U-M's Center for Ultrafast Optical Science. Light fed into it bounces like a pinball off a series of mirrors and other optical elements. It gets stretched, energized, squeezed and focused along the way.'" And ... cue the evil chortling. -
POV-Ray Short Code Animation Winners
Paul Bourke writes "Every year the POVRay rendering community run a short code competition. The challenge is create an image using a limited number of bytes, normally just 256. This year the competition required the artist to create an animation rather than just an image. The winning entries are now online where you can see what can be created for a meager 512 bytes." -
China Bans Horror Movies
KublaiKhan writes "According to an article on Reuters, the Chinese censors have decided that horror movies are verboten. 'Offending content included "wronged spirits and violent ghosts, monsters, demons, and other inhuman portrayals, strange and supernatural storytelling for the sole purpose of seeking terror and horror," the administration said. This is apparently a sort of Chinese version of the Jack Thompson effect, as the "mental health of adolescents" is cited as one of the reasons for the ban. Presumably, this ban — much like the spitting ban — is intended to improve China's image in the rest of the world before the Olympics open; but given the Streisand effect, would this ban perhaps unintentionally spur a surge of horror movie popularity in China?" Blizzard has had trouble with skeletons in World of Warcraft , and I imagine this decision stems from similar objections. -
ICANN Finds No Wrong Doing in Domain Front Running
eldavojohn writes "Remember the investigation ICANN did in domain name front running? Well, it turns out that there was no wrong doing going on at all. What went wrong? Domain name 'tasting', which involves a free five day trial of a domain name, was the big culprit. From the article: 'In some cases ... the committee found that a separate practice of domain name tasting may be causing problems. That refers to someone testing the financial viability of a name for up to five days and then returning it for a full refund, using a loophole in registration policies. Domain tasting can tie up millions of Internet addresses, including ones someone checks but does not buy.' If you check for availability of a website and someone sees you do it and they reserve it before you, it's fair play." -
Microsoft Battles Vista Perception With Prizes
LambAndMint writes "In what can only be described as an act of utter desperation to overcome Vista's mostly negative public perception issues, Microsoft has put together an online "Fact or Fiction" quiz about Windows Vista. Every person who submits themselves to Microsoft indoctrination gets a free shirt and the chance to win a $15,000 prize. Some of the supposed 'facts' will make you feel like you're reading a document from an alternate reality. Get ready to get a job as a computer salesman for a mass-market retailer as you go through the quiz." -
Windows XP Update Library On a CD
KrispyKofta sends us to APC Magazine for a writeup on Project Dakota, a one-man effort to provide all Windows XP SP2 updates on one downloadable CD. It's poor man's XP SP3, but even when SP3 is out, the project will continue to offer a CD that will install all patches offline. "When was the last time you installed a fresh copy of Windows XP SP2? The process is still straightforward and relatively quick... but then you think 'I'll just make sure the patches are up to date,' and proceed to stare in horror at the 100+ security updates and critical fixes that Windows Update or WSUS demands you install. And it takes forever. A better option which we've just discovered is the innovative work of Alek Patsouris... it's a self-contained boot CD which contains all the necessary updates to automatically patch a Windows XP SP2 system with all the patches available at the CD's build time." -
Namco Blames Wii for Arcade Closures
milsoRgen noted a story about Namco Bandai is shuttering between 50 and 60 arcades in Japan and blaming the success of the Wii for the closures. "A lot of the types of games that people played at an arcade can now be done at home," said company spokesman Yuji Machida. To be fair they also blame the high cost of gasoline as well. -
W3C Gets Excessive DTD Traffic
eldavojohn writes "It's a common string you see at the start of an HTML document, a URI declaring the type of document, but that is often processed causing undue traffic to W3C's site. There's a somewhat humorous post today from W3.org that seems to be a cry for sanity and asking developers and people to stop building systems that automatically query this information. From their post, 'In particular, software does not usually need to fetch these resources, and certainly does not need to fetch the same one over and over! Yet we receive a surprisingly large number of requests for such resources: up to 130 million requests per day, with periods of sustained bandwidth usage of 350Mbps, for resources that haven't changed in years. The vast majority of these requests are from systems that are processing various types of markup (HTML, XML, XSLT, SVG) and in the process doing something like validating against a DTD or schema. Handling all these requests costs us considerably: servers, bandwidth and human time spent analyzing traffic patterns and devising methods to limit or block excessive new request patterns. We would much rather use these assets elsewhere, for example improving the software and services needed by W3C and the Web Community.' Stop the insanity!" -
Users Worldwide Feel Internet Is 'Safer'
buzzardsbay writes "Baseline Magazine is reporting on a study by Cisco that teases out the differing attitudes about online security among users across the globe. For instance, remote workers worldwide think the internet is getting safer ... except the folks in Italy and Germany. These folks also have a lot of faith in their corporate IT departments as 51 percent said their work computers are more secure than their personal PCs, and nearly half (45 percent) believe they are more vulnerable to malware and hacks when they're working outside their corporate perimeter. Irony of ironies, the Brazilians hold Net security in the highest regard." -
Microsoft Upgrades Vista Kernel in SP1
KrispySausage writes "One of the big features discussed in early speculation of Windows Vista SP1 was the kernel upgrade, which was supposed to bring the operating system into line with the Longhorn kernel used in Windows Server 2008. With Vista SP1 going RTM, there hasn't been so much as a peep from Microsoft about the mooted kernel update. Has it happened? Well the answer is yes it has. Presumably the main reason for Microsoft's silence on the subject is that as they're keen to promote the improvements and enhancements to Vista, rather than placing emphasis on a kernel upgrade, which some people might see as a risk of newly-introduced instability." -
Yahoo May Re-Consider Google Alliance, Rebuff Microsoft
anastasd writes "Reuters is reporting that Yahoo might consider a business alliance with Google as a way to top a $44.6 billion takeover proposal by Microsoft. 'Yahoo management is considering revisiting talks it held with Google several months ago on an alliance as an alternative to Microsoft's bid, that source said. At $31 a share, Yahoo believes the bid undervalues the company, two sources said. A second source close to Yahoo said it had received a procession of preliminary contacts by media, technology, telephone and financial companies. But the source said they were unaware whether any alternative bid was in the offing.'" -
The Effects of the Fibre Outage Throughout the Mediterranean
Umar Kalim writes "Analysts have been studying the effects of the fibre outage throughout the Mediterranean in terms of network performance, by examining the changes in packet losses, latencies and throughput. We initially discussed the outage yesterday. 'It is interesting that some countries such as Pakistan were mainly unaffected, despite the impact on neighboring countries such as India. This contrasts dramatically to the situation in June - July 2005, when due to a fibre cut of SEAMEWE3 off Karachi, Pakistan lost all terrestrial Internet connectivity which resulted, in many cases, in a complete 12 day outage of services. This is a tribute to the increased redundancy of international fibre connectivity installed for Pakistan in the last few years.'" -
Pre-20th Century Gadgetery
The Byelorussian Hatter writes "Wired, presumably bored to death of Cellphones, Zunes, MairBook Nacs and what-have-you, looks back at the elegant inventions of a less civilized age. 'The Turk was a chess player concealed in a table packed with cogs and gears, contrived to give the appearance of a mighty chess-playing machine. Atop the table, an articulated automaton would be seen to make the moves determined by the master within. One of the 18th and 19th century's many illustrious hoaxes, the Turk is perhaps the greatest gadget that wasn't.'" -
Pope Denounces Some Biotech as Affront to 'Human Dignity'
eldavojohn writes "Today in a speech the pope denounced human cloning, embryonic stem cell research and artificial insemination, citing them as a violation of 'human dignity.' That said, the pope did 'appreciate and encourage' research on stem cells from non-embryonic cells in the human body. The pope encouraged the Vatican to be a leading voice in the philosophy and discussion of bioethics. 'Church teaching certainly cannot and must not weigh in on every novelty of science, but it has the task to reiterate the great values which are on the line and to propose to faithful and all men of good will ethical-moral principles and direction for new, important questions,' Benedict said." -
AIDS Drug Patent Revoked In US
eldavojohn writes "Doctors Without Borders is reporting that four patents for tenofovir disoproxil fumarate, a key AIDS/HIV drug, have been revoked on grounds of prior art. This is potentially good news for India & Brazil who need this drug to be cheap; if the US action leads to the patent being rejected in these countries, competition could drastically lower prices. But the ruling bad news for Gilead Sciences. The company has vowed to appeal. We discussed this drug before." -
Programming As Art — 13 Amazing Code Demos
cranberryzero writes "The demo scene has been around for twenty years now, and it has grown by leaps and bounds. From the early days of programmers pushing the limits of Ataris and Amigas to modern landscapes with full lighting, mapping, and motion capture, demo groups have done it all and done it under 100k. To celebrate this art form, I heart Chaos takes a look at thirteen of the best demo programs on the web. Flash video links are included, but it's more fun to download them and give your processor something fun to chew on." -
Mitt Romney Answers Tech Questions
DesScorp sends a link to a TechCrunch interview in which GOP presidential candidate Mitt Romney answers questions of interest to techies. Included are questions on H-1B visas, Internet taxation, venture capital taxation, alternative energy, and carbon emissions. Finally, we learn that Romney is a PC guy, and get a summary of what's on his iPod. -
Engineered Mosquitoes Could Wipe Out Dengue Fever
Christina Valencia points us to a Wired story about scientists who plan to use genetically modified mosquitoes to reduce the population of Dengue-carrying insects. The altered genes cause newly born mosquitoes to die before they are able to breed if they are not supplied with a crucial antibiotic. This is a more aggressive approach than the anti-Malaria work we discussed last year. From Wired: "Mosquitoes pass dengue fever to up to 100 million people each year, according to the Centers for Disease Control and Prevention. Up to 5 million die. If the scientists can replicate their results in real field conditions, their technology could kill half of the next generation of dengue mosquitoes, which scientists say would significantly reduce the spread of the disease. If all goes well the company envisions releasing the insects in Malaysia on a large scale in three years." -
Saving in OOXML Format Now Probably A Bad Idea
orlando writes "Much drama is unfolding prior to the OOXML Ballot Resolution Meeting in Geneva, currently schedule for the end of February. After that there's a subsequent 30 day period while countries can still change their vote. As a result, Bob Sutor is recommending that saving your documents in OOXML format right now is probably about the riskiest thing you can do, if you are concerned with long term interoperability. At this point nobody has the vaguest idea what OOXML will look like in February, or even whether it will be in any sort of stable condition by the end of March. 'While we are talking about interoperability, who else do you think is going to provide long term complete support for this already-dead OOXML format that Microsoft Office 2007 uses today? Interoperability means that other applications can process the files fully and not just products from Microsoft. I would even go so far as to go back to those few OOXML files you have already created and create .doc, .ppt, and .xls versions of them for future use, if you want to make sure you can read them and you don't want to commit yourself to Microsoft's products for the rest of their lives.'"