Domain: monkey.org
Stories and comments across the archive that link to monkey.org.
Stories · 779
-
Red Hat Linux 7.3 Released
qurob was the first of many readers to submit that Red Hat 7.3 has been released. Press release doesn't contain any surprises, just lists a bunch of stuff thats included with the dist. (Evolution, Mozilla, Apache). So go find a mirror if you're a Red Hat runner. Update: 05/06 14:05 GMT by T : christooley helpfully points out this list of mirrors. -
21.3" LCD Monitor Reviewed
SLDave wrote in to plug his review of the 21" NEC MultiSync LCD 2110, the monster LCD that lists for a scant $3800. The largest Apple screen is cheaper, and I'm not sure how I would feel about being forced into 1600x1200 all the time. And at the price of a decent used car? Update: 05/01 18:31 GMT by T : ARP has another idea, writing: "Here is a review of Samsung's 210T which is another 21.3" LCD. Not only is this cheaper than the NEC, but it also has DVI as well as RCA and S-video inputs that turn into a high-definition multimedia display." -
IBM Bails Out of the Hard Drive Market
DJ STORM writes: "IBM has decided to exit the hard drive market citing the market has become too competitive.They plan to sell 70% of the their HD business to Hitachi. The new company name is unknown. One has to wonder if this has anything to do with IBM's troubled Deskstar GXP series." IBM will still have part ownership of the resulting venture, but it sounds like no more Deskstars. Update: 04/17 16:33 GMT by T : You may also find interesting some older posts about IBM's work on increasing hard drive storage (1, 2, 3); hopefully, the new company will continue that R&D effort. -
Browser Wars II: CompuServe Strikes Back
securitas writes "Today CompuServe (an AOL subsidiary) launched CompuServe 7.0 with Netscape as the underlying browser. CompuServe started testing Komodo, a Gecko-based client, last year, and is now experimenting with Gecko-based AOL clients. CompuServe's 3 million-member user base is seen as a testbed before turning AOL's 34 million members into Netscape users later this year." Update: 04/16 20:54 GMT by T : Also an interesting story at CNN on the upcoming Mozilla 1.0. RC1 is very nice, as have been most recent builds. -
11 Things About Spider-Man
An Anonymous Coward writes: "This has got to be the most inane, greedy thing I have heard of yet! The owners of the billboards on Times Square are suing Sony and those involved with the production of Spider-Man 'for digitally superimposing advertisements for other companies over their billboard space in the film.' Their argument: '[the ads] do not depict the area accurately.' Oh, and a guy in spider costume swinging from the buildings does? Give me a break!" That's one thing; read below for the other 10, if you can handle some movie spoilage. Update: 04/14 21:04 GMT by T : Oh, and a 12th thing: as reader marcsiry points out, that's "Spider-Man," not "Spiderman."CheeseburgerBlue writes with his space-saving, 10-thought mini-review.
- "Worst opening titles sequence ever. Probably recycled out of un-used material from 'The Last Starfighter.' Truly IntelliVision-level graphics here.
- Peter hacks himself an awesome wannabe costume at first. This is good, because nobody is so well-rounded as to be ass-kickingly fierce, unswerving moral, academically gifted *and* a knock-down seamtress to boot. (It's unheard of, aside from that mama's boy show-off Clark Kent.)
- There is actually some credible character development. (Smacks own agape jaw in disbelief.) So much for the frickin' Batman franchise.
- We are treated to several exciting shots of M.J.'s heaving bosom through clinging wet fabric, which I thoroughly enjoyed.
- J. Jonas Jamieson: beautiful! This character absolutely could not have been done better. It's like a really angry Perry White mixed with Lou Grant, drunk.
- Nice casting. Not only is Peter's pal Harry the spitting image of his screen father (Dafoe), but he also makes a passable Anakin Skywalker. (I can't wait to see what kind of a Darth sombitch Harry turns into in the sequels.)
- Many agree that the animated Spidey flying around looks like crap in the TV spots. Luckily, in context, it works. I found that what the C.G. webslinger lacks in verisimilitude is made up for in choreography -- the sequences of Spidey swinging through Manhattan and thrilling and fun.
- I've always counted on Spiderman to deliver some quality wise-cracks, in stark contrast to Superman's squarejawed mumbling about truth and justice. I also expect Peter Parker to have a dark side that is less cheese-gothic than Batman's silhouetted form baying at the moon. This movie delivers -- Spidey's character is perfectly true to form.
- Great pacing. It's more than half-way through the movie before Peter really becomes Spiderman. His gradual transition to superherohood is convincing, and helps sell Peter as a real guy along the way.
- Despite the fact the Green Goblin essentially kicks his own ass in this movie, he does duke it out pretty cool with Spidey a few times first. (The best part is when the angry New Yorkers pelt him with trash for messin' with their friendly neighborhood Spider-Man.)"
-
Id Software and Activision Wolfenstein Source
An enthusiastic Anonymous Coward writes: "Id Software and Activision released the sources of Return to Castle Wolfenstein. Single-player and multiplayer included. Unbelievable! Another great surprise from Id Software!" Update: 04/14 15:19 GMT by T : Note: don't get your hopes up -- these are the sources for the game code, not the engine. -
Lycoris - Linux for the Masses?
Dejected @Work writes "MSNBC.com, a definitely sketchy source of Linux information, just came out with an article "Linux for the Masses" about the ease of installing Lycoris(formerly Redmond Linux) on the desktop. The author even concluded you can 'fall in love with an ever-easier-to-use operating system.' It sounds like great news but am I missing something?" Several favorable reviews of this distro recently. It looks like all you have to do to get the reviewers on your side is to let them play solitaire during the install. :) Update: 04/13 14:53 GMT by T : Eric Krout also suggests the two-part review (part one and part two) over on monolinux. -
Slashback: Favoritism, Alternacy, Moo
Slashback with more on handheld everything-boxes, a softer review of the new Sharp Zaurus, raising money for open technologies, Gateway's singing cow, and getting around with alternative root servers -- all below. Enjoy. Update: 04/12 06:41 GMT by T : There's an update below in the part on alternate root servers, too. A double-barrel of Mossberg. Dave Aiello (author of our recent review of Handspring's Treo all-in-one handheld) writes with nice update for anyone thinking of shelling out for one: "Walter Mossberg did a comparative overview of the Handspring, Kyocera, Samsung, and RIM integrated PDAs and phones in the first edition of 'The Mossberg Solution' (a new column he is writing)."Speak of the devil -- Arrgh writes: "PC Magazine has posted a more favourable review (4 out of 5 stars) of the Zaurus--they had none of the sync problems Walt Mossberg wrote about."
Give money to these guys, please. Jeff Gerhardt of the American Open Technology Consortium writes after the post about this "GeekPAC" on Slashdot.
"Although the last 24 hours was one hell of a pain in the ass, at 4:00 am we were through with that second draft and in large measure due to the constructive comments from the /. community. Yes I got a lot of nutty emails about how I should be working on more important issues like global warming and ending "greed" (can you believe that one??? how the hell can we do that.), but for the most part the comments were well thought out. As a whole I think that the whole /. community should be proud.
In particular I have pages of operational suggestions and contact names across the US. The suggestion that has tickled me the most is a suggestion for a fund raising methodology for the "PAC" organization. This came from a couple guys who were debating the idea between the two of them, until it really solidified into a plan. And, we are going to do it. The plan is simple and uses the thing we love so much, technology.
We will set up a series of paypal account links, having created a category for every House or Senate member that appeals to our overall goals and objectives. If then there is a news item about an issue and one of these "good guy" politicos does something to help the cause, the PAC will write a 2-3 sentence quote that will happen to have the paypal link included inside the quote. Media sites will then be able to include the link as a part of the quote, because afterall its news right (wink wink)!!!!
This would then facilitate the people _out there_ to throw a buck at the good guy as a impulse purchase to show gratitude. It need some refinement, but I think it provides portals an opportunity to provide a political opportunity to their communities, without looking too overtly political in the process."
No more Portable Monopoly. Dr.Jones writes "...well, not really. It seems Portable Monopoly is being forced to give up their web address 'Due to legal issues with Hasbro over the usage of the word "monopoly"'. Fortunately, they will have a new site up next week (Triton Labs), and they're still on target to ship the lighting kit next month. Seems like a bit of a stretch on Hasbro's part though."
Not as much of a stretch maybe as Parker Brothers claiming the word clue.com.;)
Do cows wake up and smell the Rosen? prostoalex writes: "Newsfactor has a story on Hillary Rosen expressing dissatisfaction with Gateway's ad campaign. Who would have thought?"
... and routing around it. With a nice detailed followup to a recent Ask Slashdot post, Dr. Zowie writes: "For those who want to use alternative DNS roots but are stuck behind port-80 proxies, a simple solution may exist, thanks to several folks who wrote in to suggest it. Section 5 of RFC 2068 gently deprecates using relative URI's in HTTP requests, and in fact most web clients generate absolute URI's even though relative URI's are allowed by the standard. My ISP's not-quite-transparent proxy directs outbound port 80 packets correctly if (and only if) there's a relative URI in the request. A little 10-line local proxy that munges absolute URI's into relative URI's before emitting them to the ISP seems to solve the problem for now: I can retrieve all the nice goodies that most of you can't at www.dev.null, , www.computer.geek, and paradox.null.
Oh, and if you live near the Colorado front range and aren't a purist about routing, Peak to Peak is a pretty good outfit for dialup and DSL service. Their tech support is extremely accessible and quite good (though our views differ on the correctness of payload-switched routing)."
Update: 04/12 06:41 GMT by T : Richard Sexton writes: "While it's great to see your continued coverage of Open Roots can I just put in a quick plug for ORSC? We're older and have way more tlds.
The coordination amongst Open Roots takes place at IRON; for lack of a better term, it's the Open IANA."
Kissing and making nice. panker writes "Sun had previously given JavaRanch a cease and desist order because of a trademark issue. Sun is now backing down and being friends. Slashdot covered the first half of this issue earlier."
-
Slashback: Favoritism, Alternacy, Moo
Slashback with more on handheld everything-boxes, a softer review of the new Sharp Zaurus, raising money for open technologies, Gateway's singing cow, and getting around with alternative root servers -- all below. Enjoy. Update: 04/12 06:41 GMT by T : There's an update below in the part on alternate root servers, too. A double-barrel of Mossberg. Dave Aiello (author of our recent review of Handspring's Treo all-in-one handheld) writes with nice update for anyone thinking of shelling out for one: "Walter Mossberg did a comparative overview of the Handspring, Kyocera, Samsung, and RIM integrated PDAs and phones in the first edition of 'The Mossberg Solution' (a new column he is writing)."Speak of the devil -- Arrgh writes: "PC Magazine has posted a more favourable review (4 out of 5 stars) of the Zaurus--they had none of the sync problems Walt Mossberg wrote about."
Give money to these guys, please. Jeff Gerhardt of the American Open Technology Consortium writes after the post about this "GeekPAC" on Slashdot.
"Although the last 24 hours was one hell of a pain in the ass, at 4:00 am we were through with that second draft and in large measure due to the constructive comments from the /. community. Yes I got a lot of nutty emails about how I should be working on more important issues like global warming and ending "greed" (can you believe that one??? how the hell can we do that.), but for the most part the comments were well thought out. As a whole I think that the whole /. community should be proud.
In particular I have pages of operational suggestions and contact names across the US. The suggestion that has tickled me the most is a suggestion for a fund raising methodology for the "PAC" organization. This came from a couple guys who were debating the idea between the two of them, until it really solidified into a plan. And, we are going to do it. The plan is simple and uses the thing we love so much, technology.
We will set up a series of paypal account links, having created a category for every House or Senate member that appeals to our overall goals and objectives. If then there is a news item about an issue and one of these "good guy" politicos does something to help the cause, the PAC will write a 2-3 sentence quote that will happen to have the paypal link included inside the quote. Media sites will then be able to include the link as a part of the quote, because afterall its news right (wink wink)!!!!
This would then facilitate the people _out there_ to throw a buck at the good guy as a impulse purchase to show gratitude. It need some refinement, but I think it provides portals an opportunity to provide a political opportunity to their communities, without looking too overtly political in the process."
No more Portable Monopoly. Dr.Jones writes "...well, not really. It seems Portable Monopoly is being forced to give up their web address 'Due to legal issues with Hasbro over the usage of the word "monopoly"'. Fortunately, they will have a new site up next week (Triton Labs), and they're still on target to ship the lighting kit next month. Seems like a bit of a stretch on Hasbro's part though."
Not as much of a stretch maybe as Parker Brothers claiming the word clue.com.;)
Do cows wake up and smell the Rosen? prostoalex writes: "Newsfactor has a story on Hillary Rosen expressing dissatisfaction with Gateway's ad campaign. Who would have thought?"
... and routing around it. With a nice detailed followup to a recent Ask Slashdot post, Dr. Zowie writes: "For those who want to use alternative DNS roots but are stuck behind port-80 proxies, a simple solution may exist, thanks to several folks who wrote in to suggest it. Section 5 of RFC 2068 gently deprecates using relative URI's in HTTP requests, and in fact most web clients generate absolute URI's even though relative URI's are allowed by the standard. My ISP's not-quite-transparent proxy directs outbound port 80 packets correctly if (and only if) there's a relative URI in the request. A little 10-line local proxy that munges absolute URI's into relative URI's before emitting them to the ISP seems to solve the problem for now: I can retrieve all the nice goodies that most of you can't at www.dev.null, , www.computer.geek, and paradox.null.
Oh, and if you live near the Colorado front range and aren't a purist about routing, Peak to Peak is a pretty good outfit for dialup and DSL service. Their tech support is extremely accessible and quite good (though our views differ on the correctness of payload-switched routing)."
Update: 04/12 06:41 GMT by T : Richard Sexton writes: "While it's great to see your continued coverage of Open Roots can I just put in a quick plug for ORSC? We're older and have way more tlds.
The coordination amongst Open Roots takes place at IRON; for lack of a better term, it's the Open IANA."
Kissing and making nice. panker writes "Sun had previously given JavaRanch a cease and desist order because of a trademark issue. Sun is now backing down and being friends. Slashdot covered the first half of this issue earlier."
-
GNOME One Step Closer To Using .NET
fader writes: "On gnome.org is an article indicating that there are now GTK bindings for C#. Basically, when combined with MONO, this means that you should be able to write at least some rudimentary .NET applications for GNOME." Update: 04/12 00:30 GMT by T : Hetz points out that Qt already has this capability (also in Alpha): here's a link to the Qt-CSharp project, and a proof-of-concept screenshot as well. -
MSNBC on Infinera's Optical Chip
pnoti writes: "This article at MSNBC is a loose overview of Infinera's new chip with circuits that control the flow of light instead of the flow of electrons. 'If this chip performed as they hoped, it would shatter many of the theoretical limits regarding the behavior of light in optical communications networks.'" Update: 04/10 04:26 GMT by T : That's MSNBC, not The New York Times -- oops. -
Driving from Alaska to Siberia
Pelerin writes "The team from the Ice Challenger project are driving from Alaska to Provodanya, in Siberia; across the 56-mile field of ice floes that each winter "joins" America and Russia. At the last minute the Russian authorities have denied the entry permit but the crew says they're on track to reach the Big Diomedes islands, which lie across the date line, thereby proving it's possible to do this. This feat is not as easy as it sounds due to the harsh Artic winter conditions, and the fact that the ice floes themselves are drifting at a pretty good clip. It takes a specially built vehicle to tackle this adventure. Geek quotient: pretty high :)" If you just want to drive to Alaska, you might go with Philip Greenspun. And if these guys don't make the trip to Russia this year, they might not get a chance. Update: 04/08 12:21 GMT by T : DrShrink adds to the story: "The two made it to Siberia, however were turned back due to not gaining permission to enter Russian territory." -
1024-bit RSA keys In Danger Of Compromise?
antiher0 writes "According to an email from Lucky Green that came across bugtraq yesterday, 1024-bit encryption should no longer be considered pristine. Bernstein released a proposal that outlines the creation of a machine capable of breaking 1024-bit crypto on the order of minutes or even seconds for the measly cost of ~$1B USD. For a more thorough discussion, check out the original email." Update: 03/26 03:16 GMT by T : And don't forget to revisit Bruce Schneier's analysis of Bernstein's claims, which cast doubt on the practicality of breaking such large keys anytime soon. -
NASA GRACE Launched
James Evans writes: "NASA has successfully launched GRACE (http://www.csr.utexas.edu/grace/). The Gravity Recovery and Climate Experiment uses 2 satellites, which communicate via a microwave ranging system, in an effort to map the Earth's gravity fields with amazing accuracy." Update: 03/18 02:37 GMT by T : secondsun points to this CNN story on the project as well. -
Slashback: Galileo, Backlight, Tariffs
Slashback tonight brings you several updates and amplifications on everything from Java in phones and a GPS system in Europe, to the future of Internet audio streaming and (related) near-unbelievable proposed tariffs on nearly anything that will hold data (in Canada). Read on below for the details.The man is not often wrong. Doc Searls writes: "I wrote a piece piece at the Linux Journal site that you might want to check out. The very first comment is 'This needs to be Slashdotted.' I agree. And not because I'm looking for attention. I want to *call* attention to the CARP Report, which will kill Webcasting with fees. It's a big deal, and I don't see anybody else talking about it. Yet. And we need to."
Would you say that these are more 'puppies," "babies," or "mommas"? Vladimir Vuksan writes: "There are already hundreds of so called Java midlets that will presumably execute on these Nokia puppies or any other Java enabled browser. Check out http://midlet.org/jsp/index.jsp"
Too bad I can't get the entire Economist free just by reading the ads. FortKnox writes: "ZDNet is running a story about generic "Ad-Free Subscription Services" being used on the internet today. The review of these services is from the 'Ad Space Buyer' and how marketing execs are not keen on the idea. Something interesting to read, seeing Slashdot is testing the services."
How about a countersuit for strong-arm tactics? iosphere writes "According to an article on Wired, the judge in BT's case issued a ruling that questions whether or not the technology that was patented is really analogous to todays definition of a hyperlink. She questions how the patent, which was written with only a single computer terminal in mind, can apply to the internet as we know it now."
Update: 03/15 00:31 GMT by T : arget writes with a few more data points: "An article at News.com suggests that Prodigy has won a TKO in the first round. Another story at ZDNet is more neutral, but quotes an expert saying that prior art will 'come back to haunt BT's efforts.' Both articles agree that motions for summary judgement and probably a ruling will come soon."
Portable Monopoly kylus writes "Roughly a month after it was last mentioned here, the Gameboy Advance light project over at Portable Monopoly takes another step closer to fruition. While the official release date is in May, the group will begin accepting preorders on Friday, March 15th for the $35 light kit, which has been officially named 'Afterburner.' In addition to this news, they've provided some video captures of the product in action."
Remember, as reader Vito puts it, that's Portable Monopoly's warranty-voiding, solder-requiring, tech-support-suiciding Gameboy Advance internal lighting kit. :) Your own risk, et cetera.
This goes beyond disputes about how to spell "meter." meehawl writes with an update on the European Union's plans for a GPS workalike system, which we had previously reported had been scrapped.
"So after the Pentagon removed GPS's Selective Availability, the maximum GPS accuracy is typically within 10 to 20 meters. Differential GPS can reduce this to minute levels, very useful for calling in airstrikes and pinpointing installations, and so on.
So it's probably no surprise that the the European Union's plans to build their own GPS system, the Galileo Project, met such stern resistance from the U.S., with Deputy Defence Secretary Paul Wolfowitz asking EU defence ministers not to go ahead, saying it could complicate US satellite-assisted warfare and furthermore could be more easily used by anti-US military forces.
The EU has has now rejected the latest message from the U.S., a State Department exhortation to forgo development. Interestingly, the latest rebuff was framed as an anti-monopoly stance, that competition in satellite navigation would be good for business.
Apparently, Osama is responsible for this latest rebirth of the European space industry.
Perhaps more worryingly, in a related development a UK company was awarded the "Skynet 5" military communications system contract. Don't these people watch movies at all?"The principle of the thing. Boone^ writes "It's been well covered, but The Tech Report has written a nice little article going through the finer points of the proposed levy and why there should be more people than just Canadians lobbying against it."
Perhaps some more apprentices will emerge from the woodwork? pynchin writes "Kyle Sallee, creator of Sorcerer GNU Linux has just announced on #sorcerer that he will no longer be involved with SGL. Some disgruntled SGL users forked the distro a few days ago -- see www.lunar-penguin.com for details."
-
Slashback: 640K, Pioneer, Payback
Slashback tonight with an mini-avalanche of updates and corrections on Pioneer 10 (it's not a Star Trek series), Canadian copyright hearings, Intel's stance on SSSCA and similar laws, and -- Oh Yes, whether 640K really is enough for anyone. Read on for the details. Update: 03/05 00:19 GMT by T : "Pioneer," not "Voyager." Asleep at the keyboard.Kudos to the guys behind Pioneer 10! Soft writes: "As a follow-up to yesterday's story, Pioneer 10 was successfully contacted for its 30th birthday, as announced in sci.space.news. The commands that were sent yesterday have been executed by the spacecraft, and more data has been collected by the Geiger Tube Telescope." lostchicken adds a link to Associated Press wire story on Yahoo!', writing "Not bad for a 30 year-old spacecraft. Perhaps those making time capsules could learn something from this?" Several readers also pointed out the SpaceDaily version of the goings on.
What, in the middle of Canadian winter?! schon writes: "An update to this /. story - The Canadian Copyright Board has announced the details of the public hearings on Canadian Digital Copyrights, at http://strategis.ic.gc.ca/SSG/rp00838e.html. Interested parties should register before attending (details available on the page.)"
Sent to you in compliance with the current Federal legislation An Anonymous Coward writes: "Back in June of 2000 Slashdot.org reported a story called ' Taking On A Spammer' about a spammer being hacked by a pissed sys-admin. The Behind Enemy Lines web page talked about a pump-and-dump spam done by Premier Services and Mark Rice."
(See this page for more information on that scam.)
"Well on February 25, 2002 the SEC filed charges against Mark Rice!"
Death of a legend? Jean-Luc writes "The New York Review of Books has published an article that contains an e-mail from Bill Gates denying he ever said the infamous "640K should be enough for anyone" quote. He foists the blame on IBM and claims he tried to convince them to include more address space from the get go. Very technical and fairly convincing, showing that for all his might Bill is still basically a geek's geek."
They hadn't even gotten to the bowlderizing chip yet ... Dan Gilmor pointed out Intel's strong statement Thursday on copy protection front, "much stronger than the letter sent yesterday. Surprising given their history..." Maybe Intel believes they can do a better job of what deciding what goes into Silicon than a committee of bureaucrats steered by the entertainment moguls can.
-
1086 Domesday Book Outlives 1986 Electronic Rival
mccalli writes :"Thought people might find this amusing. In 1986, the UK compiled an electronic domesday book. They used BBC Master computers to do it, and the result was put on laserdisc. I actually used this project whilst at school. This article states that nothing can now read these merely 15-year old discs. The original, written approx. 1086, is still doing fine thank you very much." Sounds like a good candidate for Bruce Sterling's Dead Media Project. (Speaking of Sterling, the "graying cyberpunk" has an interesting article in the Austin Chronicle on the upcoming SXSW Interactive conference called "Information Wants to be Worthless" -- thanks to reader ag3n7.) Update: 03/03 19:38 GMT by T : That's "domesday" not "doomsday." -
MusicCity's Morpheus violating GPL
dotslash writes "The new Morpheus Preview Edition client [download.com] is actually just a fork of Gnucleus an open source GPLd Gnutella client. Upon installation Morpheus PE displays the GPL and asks the user to accept. It is currently being distributed without source in violation of article 3 of the GPL. Gnucleus developers are not too happy about this. This Morpheus client is being downloaded by thousands of frustrated Morpheus users who have been cutoff the FastTrack/Kazaa network and are now migrating to Gnutella. The violation of the GPL is blatant and will also be the first glimpse of the GPL for many of these new users. It seems like the executives at MusicCity have decided that they prefer free 'as in beer' not 'as in speech.'" Update: 03/03 05:10 GMT by T : It looks like the source is available now, gpl.txt and all. -
MySQL AB and Nusphere Go to Court Over GPL
A little fairy whispered in our ear: "MySQL AB is seeking a temporary injunction against NuSphere, even though they've finally released the source code for Gemini and MySQL Advantage. According to the GPL, NuSphere lost the right to redistribute when they violated #3 by not providing the source code originally. The FSF will testify tomorrow in court, according to this Newsforge article." Newsforge and Slashdot are both part of OSDN. We've done a couple of previous stories about the MySQL AB vs. Nusphere conflict: the original story, a follow-up, and a note about a countersuit. Update: 02/26 21:15 GMT by T : bkuhn (Bradley Kuhn of the Free Software Foundation) writes: "The FSF has a press release on the matter and affidavit that we filed is also available." -
Good News On Two Open-Codec Fronts
davidu writes: "The Fraunhofer Institute in Germany (makers of the mp3 codec) licensed the divx ;-) video codec for future use. This is good for users because the codec is open source and is now on its way to becoming a standard. For those who don't know, this is unrelated to the failed Circuit City program, hence the smiley. ;-)" On the audio side of things, Mike Hicks writes: "Saw this on LWN's Daily Updates. Kenwood has come up with a car audio playing system that understands the Ogg Vorbis compression format, the Music Keg. Me want.. Time to start digging for spare change in the couch ..." Update: 02/05 03:24 GMT by T : Two clarifications below put a slight damper on each of these, though the overall news is still good.Vince Busam from Phatnoise writes: "The author of the mp3newswire article goofed big time! Nowhere does it state that the Keg plays Ogg files, only the desktop software. Ogg will be supported when free ARM libraries are available. The author is further incorrect when he mentions the Kenwood X959 plays MPEG video files on the tiny OLE display. I have no idea where he got that idea." And reader Guspaz points out: "OpenDivX is indeed opensourced, but it is not the same as DivX 4, which was what was liscenced (And is what people download to use)."
-
WinInformant Says Windows More Secure Than Linux
nihilist_1137 excerpts from this WinInformant article, which reads in part: "For at least the first 8 months of 2001, open-source poster child Linux was far less secure than Windows, according to the reputable NTBugTraq, which is hosted by SecurityFocus, the leading provider of security information about the Internet. ... A look at the previous 5 years--for which the data is more complete--also shows that each year, Win2K and Windows NT had far fewer security vulnerabilities than Linux, despite the fact that Windows is deployed on a far wider basis than any version of Linux." I wonder how many sysadmins (Windows or Linux) would agree with this conclusion. Update: 02/04 16:54 GMT by T : Looks like the WinInfo site has gone down since the story was submitted, so you may have to content yourself in the meantime with the Bugtraq numbers. Update: 02/04 19:30 GMT by T :Several readers have pointed out that the conclusions WinInformant makes based on the Bugtraq data are not those of SecurityFocus; the headline has been changed accordingly. -
WinInformant Says Windows More Secure Than Linux
nihilist_1137 excerpts from this WinInformant article, which reads in part: "For at least the first 8 months of 2001, open-source poster child Linux was far less secure than Windows, according to the reputable NTBugTraq, which is hosted by SecurityFocus, the leading provider of security information about the Internet. ... A look at the previous 5 years--for which the data is more complete--also shows that each year, Win2K and Windows NT had far fewer security vulnerabilities than Linux, despite the fact that Windows is deployed on a far wider basis than any version of Linux." I wonder how many sysadmins (Windows or Linux) would agree with this conclusion. Update: 02/04 16:54 GMT by T : Looks like the WinInfo site has gone down since the story was submitted, so you may have to content yourself in the meantime with the Bugtraq numbers. Update: 02/04 19:30 GMT by T :Several readers have pointed out that the conclusions WinInformant makes based on the Bugtraq data are not those of SecurityFocus; the headline has been changed accordingly. -
Separating the iMac
Emous Pratt writes: "There is a neat article up on iMacLinux.net which talks you through separating the monitor and computer parts of the iMac. It is very detailed, with lots of cool screenshots including this one of the completed machine, and this one showing the machine is still working. This is useful if you want to run Linux and not run the monitor, or if your monitor is broken." Update: 02/03 19:37 GMT by T : Note for the curious: this is about the old iMac (CRT equipped), not the new lampish G4 variety. -
Ximian to Change License for Mono
A Commentor writes: "According to news.com Ximian is changing the license to Mono from GPL to a variant of the XFree license. Apparently this is due to a partnership with Intel." Update: 01/28 15:03 GMT by T : There's a story at NewsForge as well, where RMS weighs in firsthand on the license choice. -
Tracking Down The AMD "Processor Bug"
tercero writes: "over at the Gentoo Linux website there is an update on the AMD processor bug mentioned here. The sum up is that AMD claims it's not a bug with the Athlon processor, but with the motherboard. More detailed information can be found on this LKML post." An Anonymous Coward points to a similar explanation at Linux Weekly News. Update: 01/25 01:25 GMT by T : Daniel Robbins from Gentoo clarifies: "AMD is not calling this a 'motherboard' issue, it is an interaction between a feature of the Athlon called 'speculative writes' and the design of the GART, which is not cache-coherent. It's a 'Athlon/cache coherency/GART' problem, not a 'motherboard' problem." -
Mega Public WAN In Sydney
Chris Meder writes: "As posted on CFGN - The Nation , gibed by the recent unreasonable price hikes in Broadband connectivity in Australia, which come already after a strained relationship between Broadband users and the major telco/ISP Telstra BigPond Internet, a group of people in the largest Australian metropolitan city of Sydney have decided to form a city wide amateur wireless network. The team behind this clever idea have also put up a detailed graphical database of people interested and are still looking for more numbers to get this off the ground." This last part reminds me of the Global Access Wireless Database, as featured here. Update: 01/23 18:53 GMT by T : Reader Peter Mann wrote to point out that "there's a mailing list for a similar wireless project in Sydney at http://sydney.air.net.au." -
Next Generation Xybernaut Wearable
shanenewsom sent in linkage to a story running on the BBC which talks about the new Xybernaut Poma. A little light on the specs, although the headmounted screen is 640x480 and it runs WinCE. But it really does look like the first practical wearable. It should be available in March. Update: 01/21 18:52 GMT by T : Reader Eureses points out that the display is actually 800x600 rather than 640x480. -
KaZaA Resumes Downloads, Company Sold?
Robert Johnson writes "According to an article on Dotcom Scoop, popular file-sharing service KaZaA may have been sold over the weekend. "As of last week the company was based in the Netherlands. However, upon close examination of its new terms of use license, the company now says, "This License as well as all disputes arising out of or in connection with this Agreement shall be governed by the laws of the New South Wales, without regard to or application of choice of law rules or principles. Any dispute arising out of or in connection with this License, or in future agreements resulting there from, shall be exclusively resolved before the competent court in New South Wales," the article states. New South Wales is an Australian state." Update Apparently the website reverted to the former content which might raise a few eyebrows. Update: 01/21 18:17 GMT by T : DotcomScoop writes: "KaZaA isssued a statement regarding its sale after our story was published." Here is the statement and a little more info. -
Writing Messages In Empty Space With GPS
meiocyte writes: "This New Scientist story about leaving messages in empty space seems very cool. You upload a message (or perhaps a picture, audio clip, etc.), it gets tagged with your GPS coordinates, and then anyone else who goes there gets to see/hear it. Every GPS-resolvable parcel of empty space will have its own web site!" Combine this with user-forums, and restaurant ratings could take on a whole new dimension. Update: 01/20 23:28 GMT by T : Oops -- looks like I duped Michael. Sorry. -
P4 2.2GHz Overclocked to 3.5GHz
GraveD sent linkage to a site explaining how a homemade nitrogen cooling system overclocked a P4 from 2.2Ghz to an incredible 3.5ghz. There's plenty of stuff to poke at over there. Update: 01/17 20:42 GMT by T : boaworm writes: "According to this paper, the Finnish geeks have successfully oveclocked a Pentium 4 to 3675 Mhz. They claim it is a new World Record, and it sure looks like they beaten another O/C'd Pentium 4 submitted earlier today on slashdot. (Summary in English in the end)." -
Slashback: Squashing, N'Synch, Yopy
A quick Slashback for you this evening with more on the clones who won't get to be killed onscreen, the Yopy (alas!), hacking your PVR, and a skeptical reaction to recent claims of dramatically increased compression. Read on for the goods.Waitaminute, what happens there between the "lead" stage and the "gold" stage again? HomerSimpson writes: "Recently on /. I read of a compression scheme reported to provide huge gains for the compression of random data. New Scientist reports, however, that the claims are unlikely at best."
Perhaps we can watch some other bands be slaughtered instead? eruditorium writes: "Apparently, the negative public reaction to n'sync's appearence in episode 2 has caused lucas to drop their cameo. See it here on Scifi Wire." san1701 links to another similar posting about this important issue at TheForce.Net.
On-again, off-again is not good for electronic projects. cd_Csc writes: "CNET is reporting on Samsung's newest Windows CE based PDA and mentioned (as a side note) that, 'A Samsung representative also confirmed the cancellation of Yopy, the company's planned Linux-based PDA.'"
Update: 01/11 02:41 GMT by T : Looks like it's not quite that simple: Bill Kendrick writes "LinuxDevices.com caught wind of today's Slashback regarding the Yopy PDA's demise.
Well, fortunately for Yopy fans, they got the real scoop directly from G.Mate..." Thanks for the quick response, Bill, and sorry for spreading false information.
Imagine explaining to your kids what VCRs were. jimmcq writes: "Slashdot previously ran a story asking about Hacking the New Replay TV Units. There have been several recent breakthroughs to allow a PC to emulate a Replay 4000 so that video can be shared in both directions. The source code has been released under the GPL. There are also several variations including a java version and an Apache/PHP Server."
-
Even Flash Can Get Viruses
Mechel Conrad writes: "Heise Online(German) writes about a Virus called SWF/LFM-926. It consists of a Macromedia Flash movie and seems to be the first of its kind. It uses Flash's scripting language in order to open a debug terminal creating and executing a file called V.COM, which infests other .SWF Files. Although the virus is not very dangerous and not widespread yet, it suggests clear security holes in Flash." The translation of the Heise article is quite readable, too. Update: 01/08 22:47 GMT by T : bdavenport adds: "this report on Yahoo lists a new Shockwave virus as low grade due to the need of manual downloading. infoworld is reporting that McAfee has upgraded to high risk after several Fortune 500 firms have reported it in the wild, arriving as an email attachment." -
How Google Saved USENET
Masem writes: "Salon has a well-written article article on the recent revival of much of the USENET archives from '81 to '90 by Google. It mentions that much of the recovery was thanks to years of work in transferring data off 140-some 10" magnetic tapes (~120megs of data) to a more conventional format in order to recover much of the early posts. Even a reference to the previous Slashdot story is made." Update: 01/07 23:52 GMT by T : btempleton adds: "O'Reilly Network asked me to do an article on similar themes and rememberances of USENET history." Thanks, Brad. -
Time Canada Shows New iMac
Kira-Baka writes "Okay, Time Canada screwed up big time. They have pictures of the new iMac which will be released tomorrow during the Mac World Expo keynote on their front page. it is likely that they will be getting a letter soon so though..." I'll be posting a full report on the keynote and other MacWorld goodness tomorrow as it happens. Time Canada seems a bit slow, but in short, think little pod of iMac with superdrive and flat panel screen. Update: 01/07 13:22 GMT by T : Several readers have pointed out that the story can (for now) still be found mirrored here, though it's been pulled from the Time site. -
FIRST Robotics Competition Starts Today
cscx writes: "Today is the kickoff day of the 2002 FIRST Robotics Competition. For those of you that don't know what FIRST (Dean Kamen, Segway, IT) is, it's an organization meant to interest high-school students in science and engineering by giving them 6 weeks to build a complete functioning robot. (By the way, FIRST is what most likely inspired BattleBots) Teams, although they require funding to pay for the kits, receive many different mechanical and electrical (the programmable control system kicks ass! :) parts in the kits, along with full copies (donated by the companies) of Autodesk Inventor, Character Studio, 3D Studio Max, and Reactor, as well as Microsoft Office XP, Frontpage, and Project. There is a live webcast of the kickoff, with an unveiling of the game at 11:00 EST." Update: 01/05 16:15 GMT by T : Here's a link to the webcast information page; the webcast is available in WMF and RealMedia formats, and will be archived as RealMedia. -
Gnumeric 1.0 Has Arrived
plastercast writes: "Gnumeric 1.0 is now out, which makes the Gnome desktop even more 1.0-tastic, with the recent milestones of Galeon and Evolution. ... For those that do not know, Gnumeric is a spreadsheet program with the ability to include all sorts of neat bonobo objects, and also can create graphs through guppi, the Gnome graping program. Enjoy!" Update: 12/31 20:08 GMT by T : That's "graphing." Graping is for the stroke of twelve. Update: 12/31 21:01 GMT by T : Jody Goldberg writes "You folks posted the story a touch too quickly. The release announcement just went out 5 minutes ago." -
Gnumeric 1.0 Has Arrived
plastercast writes: "Gnumeric 1.0 is now out, which makes the Gnome desktop even more 1.0-tastic, with the recent milestones of Galeon and Evolution. ... For those that do not know, Gnumeric is a spreadsheet program with the ability to include all sorts of neat bonobo objects, and also can create graphs through guppi, the Gnome graping program. Enjoy!" Update: 12/31 20:08 GMT by T : That's "graphing." Graping is for the stroke of twelve. Update: 12/31 21:01 GMT by T : Jody Goldberg writes "You folks posted the story a touch too quickly. The release announcement just went out 5 minutes ago." -
Portable .NET Reaches A Quarter Million Lines
Pnet Guy writes: "Portable .NET is a component of the dotGNU meta project to provide a CLI (ECMA standard) platform for free software. The project true to its name runs on a variety of platform including Linux,Hurd and Cygwin GNU systems. To avoid any legal problems Pnet has decided to go the hard way and bootstrap our compiler off gcc. Unlike Mono which uses microsoft's runtime to run their compiler. Our premier developer Rhys Weatherly has contributed 254,423 lines written since Jan 1, 2001. Which amounts to about 5000 lines per week which is phenomenal for any programmer. He is dotGNU's one-man army. So join him in celebrating his quarter billion lines of his code." Update: 12/27 02:41 GMT by T : Note that as many readers have pointed out, that's just like the headline says -- a quarter million lines, rather than billion. Some related links to check out include the dotGNU home page, the Southern Storm Software (Rhys Weatherley's shop, with Portable .NET information), Mono's page and Pnet's CVS repository. -
Vendetta: A Christmas Story Part 2
RainbowSix writes: "The sequel to Vendetta: A Christmas Story is up. Check it out here. I haven't finished downloading it yet, but hopefully it will be as entertaining as the last one. At 25k/sec, hopefully people can post mirrors too. It is only in .mov format so far, so mpg linux people will have to move to a windows box until they post the other formats." Update: 12/26 05:34 GMT by T : marks writes: "We now have an official mirror of Vendetta Parts 1 and 2 up here via http and here via ftp. We have the Quicktime/AVI full movie and segments for Part 1, and the Quicktime Full Movie and Segements for Part 2." -
WinXP Security Flaw
Many readers have submitted word of the newest security hole in Windows XP. joshjs, for instance, writes: "Don't know if this is common knowledge at this point or not, but apparently some security researchers discovered that Windows XP's universal plug and play features contain a huge security flaw: 'A Microsoft official acknowledged that the risk to consumers was unprecedented because the glitches allow hackers to seize control of all Windows XP operating system software without requiring a computer user to do anything except connect to the Internet. ... Microsoft made available on its Web site a free fix for both home and professional editions of Windows XP and forcefully urged consumers to install it immediately.' Read more at the Washington Post's story." No OS is perfectly secure, but I bet a lot of new XP owners won't be too happy about this. Update: 12/20 20:05 GMT by T : fcrick submits a link to the same AP story at Wired, and several readers have pointed out that a patch is available. Update: 12/20 21:31 GMT by T : And as banuaba writes: "This hole also affects versions of 98 with XP File sharing installed and all versions of ME." -
WinXP Security Flaw
Many readers have submitted word of the newest security hole in Windows XP. joshjs, for instance, writes: "Don't know if this is common knowledge at this point or not, but apparently some security researchers discovered that Windows XP's universal plug and play features contain a huge security flaw: 'A Microsoft official acknowledged that the risk to consumers was unprecedented because the glitches allow hackers to seize control of all Windows XP operating system software without requiring a computer user to do anything except connect to the Internet. ... Microsoft made available on its Web site a free fix for both home and professional editions of Windows XP and forcefully urged consumers to install it immediately.' Read more at the Washington Post's story." No OS is perfectly secure, but I bet a lot of new XP owners won't be too happy about this. Update: 12/20 20:05 GMT by T : fcrick submits a link to the same AP story at Wired, and several readers have pointed out that a patch is available. Update: 12/20 21:31 GMT by T : And as banuaba writes: "This hole also affects versions of 98 with XP File sharing installed and all versions of ME." -
Ximian Adds Subscription
GeneJock writes "Apparently the days of free fast updates from Ximian are gone. The latest update to the Ximian suite replaces the old Red Carpet Manager with a newer version which includes access to a subscription service. This subscription service costs $9.95 a month ($7.95 for the first two months if you signup now). You can still get the updates for free but its slow going... looks like I'll be getting my updates overnight. Read all about it here." Can't fault a company for trying to make some money - hope it works. Update: 12/19 16:48 GMT by T : Please note: Ximian isn't cutting back on the free downloads, either -- in fact, just the opposite. Read below for some more information about this, including a link (yup) to a standalone static binary of Red Carpet, so you don't even need to use Ximian Gnome.Nat Friedman of Ximian points out that the introduction of the subscription service doesn't mean a reduction in the availability of free downloads, from Ximian and the 40 associated mirror sites. "We've actually grown the pipe by 500% over the past 4 to 6 months," he says. "We also have a mirror coordinator." He cites ever-increasing numbers of Red Carpet sessions as the reason for introducing a subscription; November alone saw three quarters of a million sessions.
That number seems likely to increase, in part because of Ximian partnerships with companies like HP, now shipping a preview release of Ximian Gnome on HP-UX, but also because the Red Carpet software update system no longer requires Ximan Gnome; Friedman passed along this link to distribution-specific static binaries which work with other distributions as well.
Despite new servers and more bandwidth, Friedman asserts that some users downloading software for free will inevitably hit servers at times "when they're getting 8k downloads and they'd rather be getting 50k, and that's really who the subscription is for."
-
U.S. To Drop Charges Against Sklyarov
Schmerd writes: "The New York Times has a story saying that charges will be dropped against Dmitry Sklyarov in exchange for his testimony against his employer ElcomSoft." Si adds: "It looks like Dmitri might be home for Christmas. This is not the end of the trial, but it appears Dmitri has been freed, pending certain stipulations." jij adds this breaking news article on the Associated Press wire as well. (The AP story is also at Wired). Update: 12/13 22:23 GMT by T : sam@caveman.org links to a slightly more in-depth AP report at the Seattle Post-Intelligencer. -
Online Journalism Same As Print/TV
jeffy124 writes "The NY State Supreme Court has ruled that online journalists have the same rights/protection as do print and television journalists in issues of public importance. The decision comes from the case of National Bank of Mexico v. Narconews.com, which last year reported that the bank's then-president was involved with narcotics trafficking. The bank claimed the allegations were fabricated and demanded the story be retracted. The court ruled that the online journalist was protected under the First Amendment, referring to the case NY Times v. Sullivan, the case that gave freedom of the press." Update: 12/12 16:23 GMT by T : gregorovius writes with a correction: "Banamex is a private bank that has no relationship whatsoever with the National Bank of Mexico, which is our government's FED equivalent. It must be noted that from some months ago Banamex is not even a Mexican bank; it's an American bank that operates in Mexico, being owned in its entirety by Citigroup." -
Cocoa Programming for Mac OS X
Michael Simmons contributed this review of what he claims is the best of the very few books out there for folks who want to learn Cocoa programming. The field is so small, in fact, that he can give a nutshell review along the way of the only other one he's encountered, O'Reilly's Learning Cocoa. Update: 12/13 15:45 GMT by T : Please note: Simmons is thanked in the acknowledgements of Hillegass' book. He explains: "I went to the Big Nerd Ranch, where the author teaches an amazing Cocoa course. While there, I received a pre-release copy of the book (it's the coursebook, actually.) I had found a bunch of errors and typos, and helped Aaron correct those errors and inconsistencies, so I'm guessing he is thanking me for my contributions to quality." Just to clear that up! Cocoa Programming for Mac OS X author Aaron Hillegass pages 416 publisher Addison-Wesley rating 8.5 reviewer Michael Simmons ISBN 0201726831 summary Learn to program OS X applicationsIntro to Cocoa
You can write Cocoa applications with either Objective-C or Java. If you aren't familiar with Objective-C, it's an extension to the C language that makes it object-oriented. I'm not sure why Apple decided to offer Java support for Cocoa, since almost every source of information on the Internet and all Cocoa resources seem to only refer to Objective-C. Since Java-written Cocoa applications will not run on any platform other than OS X, it was probably done as a marketing "thing" -- Apple is giving Java programmers the ability to program Cocoa applications, opening up the potential for more Cocoa engineers.
If you're interested in programming for Mac OS X, you've definitely heard of Cocoa by now. Cocoa is the name of the library of frameworks that gives you the ability to write advanced applications with ease. The Cocoa frameworks enable you to perform tasks that used to take a decent amount of code and implement it in a very straightforward manner. The hardest thing about learning Cocoa is that because it's so simple, it takes some getting used to.Until today, there was only one book if you wanted to learn Cocoa. That book is Learning Cocoa , which is published by O'Reilly and written by Apple Computer, Inc. The new kid on the block is Cocoa Programming for OS X, which is published by Addison-Wesley and written by Aaron Hillegass of the Big Nerd Ranch. With two books out, Cocoa programmers now have an actual choice of which book to buy. Which brings us to the point of this review -- which book is better?
Is it really O'Reilly?
Since Learning Cocoa was out first, I'll start with my analysis of it first. When I heard that O'Reilly was going to start publishing OS X programming books, I was stoked. O'Reilly books have historically been amazing -- very complete and straightforward sources that any programmer would be proud to have in his or her arsenal of knowledge. Unfortunately, Learning Cocoa falls short of the O'Reilly tradition, and makes me wonder if O'Reilly actually supervised the printing of this book.There are some good points about the book. It was the first and only Cocoa book, so when I got my copy back in May, I was looking forward to learning the language. It does provide some good examples on how to write Cocoa applications, which allows one to dive straight into Cocoa programming. The introduction to Cocoa is really good -- it gives a very in-depth description of Object-Oriented and Cocoa program design, which I really like. Additionally, it gives a very good background to the concepts and techniques of using Cocoa.
However, there is a real problem with this book. This book reads more like it was meant to be an internal reference at Apple, rather than a book for the beginner. Another problem is that the layout and order of the content is confusing. Unlike past O'Reilly books and other quality programming books, it seems like this time they took a bunch of internal technical documents on Cocoa, and sent them to the binding machines without further editing. That the book credits "Apple Computer, Inc." as the author provides good evidence for my theory.
The heart of the problem is that the reader has to really dig and explore through this book to find that info that he or she wants. When learning a new language or programming concept, a book should be easy to follow and it should allow the reader to focus on learning the actual concepts, and not having to figure out the flow of the book.
Aaron hits a home run
The "flow" statement is a perfect segue into my analysis of Cocoa Programming For Mac OS X. Right away, I could tell that I was going to like this book. The author, Aaron Hillegass, wrote this book like he is a friend speaking directly to the reader -- he takes you through each concept like he is right there with you. This book teaches you Cocoa by specifically having you write applications, and in each new chapter, you add new features. As you add each new feature, you'll learn an important Cocoa concept.O'Reilly's book also has the reader write applications and add features, one by one, but it does so in a very sporadic way. I was never really sure what the purpose of adding a certain method was, whereas with Aaron's book, each chapter is focused on an ordered and very specific concept, making it very clear what I was about to learn, and why.
Another part of this book that I really appreciate is the chapter on Objective-C. In just one chapter, I understood Objective-C. You must already know C and at least one object-oriented language (like C++ or Java,) but after reading this chapter, you will be able to write Cocoa applications in Objective-C.
This book comes with an online counterpart, powered by Techstra. Techstra is an online engine that allows you to enter any page of the book and get "extras." The extras include examples not in the book, solutions, errata, and even input from readers. It's very cool and very helpful.
A final and very strong point of Aaron's book is that it reflects the latest update of the Mac OS X development tools, Project Builder and Interface Builder. Apple just updated the development tools to version 10.1, substantially changing the UI and functionality, and the latest version is reflected in Aaron's book.
Conclusion
It's clear to see which book I'm giving the nod to. I know it appears like I'm being biased towards Cocoa Programming For OS X, but if can get to your local bookstore and actually compare the two books side by side, you'll see why I'm so enthusiastic about Aaron's book.I think having both books is a good choice, as the O'Reilly book does offer very in-depth information, which is useful once you learn Cocoa using Aaron's book. If O'Reilly changed the title to After Learning Cocoa, I think my perception of the book would be different.
Cocoa allows programmers to write powerful applications in a very short amount of time. I am amazed at the power and simplicity of the Cocoa frameworks, and can't wait to see what myself and other programmers end up creating in the future. I'm sure other books will come out in the future, but for now all we have is two. The one I'd recommend is Cocoa Programming for Mac OS X, but you already knew that. :)
You can purchase this book at Fatbrain. Want to see your own review here? Read the book review guidelines first :) -
Slashback: Highness, Hominess, Hole-ines
Slashback tonight with updates on SSH vulnerabilities, the Queen's web server, the European answer to GPS (in danger, it seems) and your ever-thinner rights to use software for anything you don't have specific permission for.Sometimes being British means self-flagellation. Ferox writes: "The November Web Site Survey from Netcraft reveals something interesting: 'Two years ago the Queen of England became an unlikely icon for the Linux revolution when her webmaster replaced Solaris as the platform for the Royal Family's site, citing the better price/performance of the Dell/Linux platform over the previous incumbent, Sun/Solaris. The open source community celebrated and speculated on when the Apache web server might receive the "By Royal Appointment" moniker. This week the site has changed platforms again, this time to Microsoft-IIS.'"
Keep your hands and passwords inside the car at all times. Niels Provos passed along word of his ongoing research into network security, with some slightly depressing news about the state of Internet security.
Even though the CRC32 bug has been found over a year ago, over 30% of all servers are still vulnerable today. Graph at http://www.citi.umich.edu/u/provos/ssh/crc32.png.
In February 2001, Razor Bindview released their "Remote vulnerability in SSH daemon crc32 compensation attack detector" advisory, which outlined a gaping hole in deployed SSH servers that can lead to a remote attacker gaining privileged access.
In November 2001, Dave Dittrich published a detailed analysis of the "CRC32 compensation attack detector exploit." This exploit is currently widely in use. CERT released Incident Note IN-2001-12.
At the Center for Information Technology Integration, Niels Provos and Peter Honeyman have been scanning the University of Michigan for vulnerable SSH server software to identify and update vulnerable SSH servers. However, scans of the Internet show that system and security administrators must react and update their SSH servers. At this writing, over 30% of all SSH servers appear to have the CRC32 bug.
A simple solution is to remove support for Version One of the SSH protocol. The majority of servers on the Internet support the SSH v2 protocol. To test whether your network has vulnerable SSH servers, you might use the ScanSSH tool.
References: "ScanSSH - Scanning the Internet for SSH Servers", Niels Provos and Peter Honeyman, 16th USENIX Systems Administration Conference (LISA). San Diego, CA, December 2001. This information is also available at http://www.citi.umich.edu/u/provos/ssh/
Don't play with your food, or your games. janolder writes "In the matter of the Civilization III translation project (articles on slashdot, apolyton and heise), the fans have gotten the short end of the stick. The project web site (translation.civ3.de) has been down for a while. Earlier this week, both the web site operator and Kai Fiebach, the project leader, signed Infogrames' cease and desists out of fear of further legal action. The legal position (not to mention the moral postion) of the fans did not appear to be too weak - EULA's are not binding in Germany and supplying patches to a program is certainly not the same as translating a book and distributing the translated manuscript.
Infogrames Germany has issued another press release (translation and my comments) justifying their legal action and position. It makes for an interesting peek into the mindset of a game publisher.
The good news is that Infogrames is considering a more timely release of Civilzation III in Germany.
The bad news is that the cease and desists apparently forbid any modification of Civ3 in any way, shape or form. So no more custom maps for your friends, custom rules or any such copyright infringing activity, please! Is it just me, or has the world suddenly become a less interesting place?"
Not as if Americans always know where we are, either. ByTor-2112 writes "Hate to be the bearer of bad news so soon after a story is posted, but as I commented on the previous story, it appears that galileo has some funding issues. Honestly, did anyone really expect the EU to go through with it? It took them long enough to agree on a common currency!"
-
Latest WinWorm Spreads Via ICQ And Outlook
mgooderum was among the many to write in about yet another snippet of malice making the Windows desktop rounds: "The latest email virus -- 'Goner' -- is apparently running around this morning (AP news story on Iwon here - no login needed). The virus is a typical worm that spreads via attachments and user's address books. It appears as a message with an attachment that starts: 'How are you ? When I saw this screen saver I immediately thought about you...' Goner is apparently non-destructive other than the normal DoS issues with the load from it forwarding itself everywhere. What's moderately unique are two features. One is its ability to replicate via ICQ as well as the usual Outlook and Outlook Express. Two is its small size -- it has a packed form that is only 159 bytes. Symantec has details here; McAfee has details here." Update: 12/04 21:57 GMT by T : That should read 159 kilobytes. And as many posters have pointed out, "destructive" is in the eye of the beholder. -
Evolution 1.0 Released
jdavidb writes: "I pulled up the Ximian redcarpet updater this morning and discovered that Evolution 1.0 is finally available! Now Outlook can start facing some serious competition, although there's still a long way to go. (Evolution does not yet emulate all the Outlook viruses, of course, nor does it integrate with Exchange Server.)" Here's Ximian's full announcement. Update: 12/03 14:59 GMT by T : Nat Friedman of Ximian points out that they're offering a software extension which does allow integration with Exchange 2000. There's good story on the new iteration of Evolution at NewsForge, too. -
This is IT?
Dave (picked at random) and 8000 other slashdot readers wrote in to tell us that they too had been overcome by the relentless hype machine that is IT, Ginger, Segway, whatever. Read about IT in your favorite hype-dispensing media outlet, each of which thinks that it has an exclusive on the story of IT. Flash diagram of IT. Time. NY Times. Reuters. And don't forget to watch the advertisement, errr, "demonstration" of IT on Good Morning Consumers tomorrow. Update: 12/03 13:37 GMT by T : Segway's webmaster John Grohol points out the segway website as well. -
Lineo Frees CP/M
rbeattie writes: "The Register is reporting that the code for 'the first generic operating system for microcomputers' is now open source. It's interesting to see the final chapter for the code that could have been what was MS-DOS. The article includes the requisite background of CP/M from Gary Kildall's snubbing of IBM to its transformation into DR-DOS, later being sold to Novell then to Caldera who spun it off with Lineo who finally opened up the source in October." The original story is actually at NewsForge. Update: 11/27 22:13 GMT by T : Note, thanks to reader Greg Head, that DR-DOS source appears available only for money; the original headline implied that DR-DOS source was also now available at no charge.