Slashback: Aptitude, Consolation, Security
apt-get install common.sense According to this message from Pixel in the apt-rpm mailing list, Linux-Mandrake is the second RPM-based distro to use APT, after Conectiva's own distro. So, despite the existance of non-free similar products recently covered in /., APT is gaining acceptance to be the unified package manager front-end for Linux.
Can your parents install Debian?
Now there's some smidgeon of Justice for ya Foggy Tristan writes "
According to Wired news story, Uzi Nissan has won a battle, but not the war, against Nissan in a domain name dispute over nissan.com.
For now, however, Uzi Nissan must display a prominent banner on his site that tells people he has nothing to do with the car company and where people can find Nissan.
" You knew this was going to happen ... RobM9999 writes: "The BugTraq mailing list over at SecurityFocus is reporting what appears to be the first vulnerability in the NSA's Security-Enhanced Linux that was originally written about here. The original post to the BugTraq mailing list is here."What would have been more surprising is if no security bugs were found when a project like this has its source opened to the world. Best to get that laundy clean, eh?
Could be they're just serious gamers tech81 writes "Here's an article on MSNBC that has an update to this story previously posted on Slashdot concerning Iraq possibly buying and stockpiling PS2's for military purposes. Looks like they weren't able to get an PS2's, so they grabbed the originals. . ."
So that's why the bidding on eBay went so high, eh?
Read 'em and weep The next part of our continuing reprint of Jon Katz' Hellmouth series is up.
Both of the other replies are wrong (Advanced Packaging Technology and Another Package Tool).
But both got it half right.
According to 'man apt', it's "Advanced Package Tool".
"We registered nissancomputer.com and offered it to him for free," Schindler said. "But he has no interest in being Nissan Computer -- his real name -- because he wants to exploit the substantial confusion.... If Ui Nissan was using nissancomputer.com, there would not be a lawsuit."
Ok, so Nissan Motor Co Ltd wants Nissan.Com, when it hasn't registered NissanMotorCoLtd.com and NissanMotor.com and NissanMotors.com isn't good enough? I think Uzi's got a good case.
HIV Crosses Species Barrier... into Muppets
Er, no. We just sold him arms when he was fighting Iran in the late Eighties. He seized power quite well on his own, and the Soviets provided him with arms and military advisors for his first fifteen years or so.
There's no "we" in team, only "me"
*.tar.gz
Oh, so just like Slackware then?
installpkg foo.tgz
--
$x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
$x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
Slapped with a talking Boogie Bass, actually.
People would assume from that article that Sadam could take a Gameboy, put the right cartridge in it and fly to the moon.
He could if was playing Lunar Lander on his Gameboy!!
cpeterso
all the United States has succeeded in doing is punishing the Iraqi people it says it's trying to protect.
Er, no, we aren't trying to protect the Iraqi people. We are trying to keep Saddam from building up enough forces to threaten the regional balance of power again by cutting off his money. It's old-fashioned balance-of-power politics, and its working exactly as intended.
Now, admittedly, U.S. politicians have been spouting lots of moralistic rhetoric about it. Hussein spouted lots of moralistic rhetoric about the justice of his invasion of Kuwait. In both cases, the rhetoric not only has nothing to do with what's happening, but never did and never will.
Frankly, we want Hussein to remain in charge of Iraq. If he falls, there's a good chance that the Kurds break off into their own country in the north, destabilizing our long-time ally Turkey. And there's a good chance the Shi'ite south also breaks off and becomes part of or an ally of Iran, putting the Iranians on the Kuwait border. Democracy is nice, but democracy in Iraq carries a severe risk to several long-term U.S. allies and to the economies of the democracies in North America, East Asia, and Europe.
Instead, the embargo leaves Saddam with enough power to keep his country united and defend itself from invasion, while rendering it unable to invade neighbors. Which is exactly what the U.S., EU, Turkey, Saudi Arabia, Kuwait, and Israel want.
There's no "we" in team, only "me"
The effect of the embargo on Saddam Hussein has been to INCREASE his power. If you stop and think about it, you'll realize why... Saddam already has the wealth, power and contacts necessary to procure basically whatever he wants on the black market. The effect is, if you're an Iraqi and you want access to imported goods - i.e., the Good Life - you will be beholden to Saddam Hussein. If you are part of the middle-class group that Saddam provides for, then what's good for Saddam is good for you.
If there were no embargo, the Good Life incentive to keep Saddam in power would be at least diluted.
At the very, very least, it should be quite clear that if you want to get rid of Saddam, then the sanctions method is, uh, not exactly producing sparkling results yet. In fact, the sanctions only make the ruling class stronger while punishing everyone else.
So ask yourself this... the US is not ignorant of these facts. Why do they work so hard to keep the embargo in place?
There is a reason... but if you think it's all the propaganda you rattled off in your post, you're not using your head. The answer is in plain sight.
no. i was thinking more along the lines of
...
...
...
#tar -zxf foo.tar.gz
#cd foo
#configure
#make
#make install
#echo Precompiled binaries are for the weak.
FluX
After 16 years, MTV has finally completed its deevolution into the shiny things network
"It is seldom that liberty of any kind is lost all at once." -David Hume
Didn't you read the AMD/Transmeta story? It won't be long at all before you can do an apt-get *insert favorite processor instruction set*.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Yu Suzuki
Yu Suzuki
Deamcast. It's thinking.
If you're really interested in reading up on this stuff, here's an interesting article written by Noam Chomsky. It's at the very least an interesting read for opposing opinions: http://www.zmag.org/chomsky/articles/z9804-rogue.h tml
Jeremy McNaughton
------ Live simply so that others may simply live.
I'm no military expert, but it seems to me that hardware optimized for converting data into 3D images (console games) is NOT the best harware to use for converting 3D images into models of the real world (optical recognition/computer vision systems mentioned above). What good is rapid pixel fill rates, texel rates, polygon rates etc. when you're not trying to generate pictures, but rather decompose pictures into atomic components, which is pretty much the reverse process. So either a) I'm an idiot. b) The "miltary experts" are idiots, or c) Jim Miklaszewski and the MSNBC editorial staff are idiots. Which is it?
"Freedom means freedom for everybody" -- Dick Cheney
Last time I looked the amazingly user-friendly Windoze also presented an identical list, but when I tried to pick my monitor it insisted I insert a disk which I did not have (I then picked generic and it worked).
They used water to extinguish the fires, not explosives. There was a PBS special or something on it and the quote I remember was "throw enough water at ANY fire and it will eventually go out."
Wasn't it the U.S. that put Sadam in power to start with.
Define for me please what a rogue nation is exactly. One that does not abide by U.S. desires? Technically, all nations are "rogue" in that they are all sovereign...rogue implies that there is some international government dictating thier actions. (The U.N. doesn't count, because it rules by consent: you don't /have/ to be a member).
Iraq, lest you forget, invaded another sovereign nation with every intention of keeping it. Overwhelming force from a large coalition of nations forced them to abandon Kuwait. Not content to have their parade rained on, the Iraqis systematically set fire to many of the oil fields in Kuwait. These require explosives to quench -- not a simple task.
But then, you also forget that Iraq didn't always used to be the "bad guys". Prior to the whole Kuwait thing, we had actually told (our close ally) Saddam Hussein that we (the U.S.) would look the other way when Iraq moved to retake the disputed territory that Kuwait held at the time. We told them to go ahead and take it. This was taken, however, by Saddam Hussein to mean we wouldn't care if he took /all/ of Kuwait...which was a mistake. If Hussein had bothered to notice that Bush's ranking in the opinion polls in the U.S. had been slipping, he might have forseen that his actions provided a convienent excuse for Bush to try to make himself look good...
The only reason Hussein was ever vilified was because the Bush family was getting antsy about thier chances for re-election.
We won't even go into the Bush family's ties with the Texas (vs. Iraqi) oil industry...
Since Saddam was, unfortunately, not removed from power during the war, it is not unreasonable to assume he might be a little bitter. Imposing an embargo helps contain him and his ability to threaten other nations. No it isn't perfect, but it is certainly better than letting him freely buy any military hardware he needs.
He wasn't removed from power because of treaties the U.S. is party to that prevent us from directly interfering with another /sovereign/ nation's government.
Iraq has shown the capacity to use weapons of mass destruction (nuclear / biological / chemical), just ask some of their own people. Additionally, it has shown it has, and is willing to use missiles to attack other nations (Scuds on Israel during the Gulf War).
Hiroshima. Nagasaki. Don't forget the U.S. is the only nation to have ever used atomics on another nation. Don't see any embargoes being put on us...because we won. These embargoes have nothing to do with Hussein or what he's done: they are not punishment; they are poltics. Cheap Oil. Texas versus OPEC. We are trying to force Iraq's oil prices down, at the expense of the civilian population.
enough rambling. I await your repsonse. =)
have fun
dongoodman
as a user, i think i may have found a solution to the whole apt-get vs. rpm argument that has been boiling over for ever so long. this package management system could possibly change the world:
*.tar.gz
FluX
After 16 years, MTV has finally completed its deevolution into the shiny things network
"It is seldom that liberty of any kind is lost all at once." -David Hume
of course not. But they could give it a good go. Unfortunately they would be stuck on a command line because when the question comes up "What are the vrefresh and vsync rates for your monitor?" they would have no clue. Am I the only one who doesn't immediately scramble for the monitor manual on the first day that I buy a new monitor and write these numbers above the screen? WTF is with that?
How we know is more important than what we know.
Granted, I only tried cooker quite a while ago, but it seemed to me to be incredibly broken.
:)
:) Even so, I've only had one major break since I've started running it. Lemme see if I can remember what broke ...
:)
As I recall, dependancies were often very innacurate, packages had not been completely compiled(as in they didn't have all the binaries/libraries the package should have), and three out of every ten moderately complex programs segfaulted.
Now, that was quite a while ago
Right now I'm using the bleeding edge version of Debian. Called Sid, standing for Still In Development, it's not suggested for casual users. It's not even suggested for enthusiastic users. It's only for people who are familiar with system recovery
Damn, can't remember. Something to do with KDE2, though, I'm pretty sure.
Ah well
Dave
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
Iraq, lest you forget, invaded another sovereign nation with every intention of keeping it. Overwhelming force from a large coalition of nations forced them to abandon Kuwait. Not content to have their parade rained on, the Iraqis systematically set fire to many of the oil fields in Kuwait. These require explosives to quench -- not a simple task.
Iraq has shown the capacity to use weapons of mass destruction (nuclear / biological / chemical), just ask some of their own people. Additionally, it has shown it has, and is willing to use missiles to attack other nations (Scuds on Israel during the Gulf War).
Since Saddam was, unfortunately, not removed from power during the war, it is not unreasonable to assume he might be a little bitter. Imposing an embargo helps contain him and his ability to threaten other nations. No it isn't perfect, but it is certainly better than letting him freely buy any military hardware he needs.
One of the biggest complaints I hear is that the Iraqi people are starving -- the oil for food program doesn't work. On closer examination you'll find that Iraq is rarely selling up to its capacity under this program because Saddam refuses to rebuild / upgrade / maintain his oil refineries. He would rather redirect this money to his elite forces. So don't you dare accuse Americans of "starving poor Iraqis". Their own government got them into this situation and keeps them in it.
Don't get me wrong - in no way am I condoning the actions of loose cannons like Oliver North or other corrupt individuals who were in power positions in the U.S. Criminals should be punished. But you are trying to make an embargo sound criminal, when in fact it IS the punishment. Don't confuse the two.
Those people who moderated posts up must be in the majority. It probably wasn't obvious to them, because they modded it up. Since they're a good crossection of the majority, that probably means that the majority doesn't think it's obvious, and it then became worth saying :)
Dave
P.S.: I don't mind constructive critisism - no need to post anonymously when replying to one of my posts.
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
That SELINUX bug is already fixed ... go to http://www.nsa.gov/selinux, go to download page, and there's new stuff...
Off the mailing list:
Date: Tue, 2 Jan 2001 17:28:48 -0500 (EST)
From: pal@epoch.ncsc.mil (Pete Loscocco)
To: selinux@tycho.ncsc.mil
Subject: Updated release
Sender: owner-selinux@tycho.nsa.gov
An updated release of Security-enhanced Linux that corrects some of the minor problems in the original release has been posted on the NSA web site (www.nsa.gov/selinux).
Changes include:
- moving the numbers of the new system calls to avoid conflicts
- fixing the buffer overflow problem discovered in the find_default_type function in libsecure
- removed extra ';' in policy grammar
- minor adjustments in kernel/flask/Makefile
...
"Buffers can be overflowed, and by overwriting critical data stored in the target process's address space, we can modify its execution flow. This is old news. This article is not much about how to exploit buffer overflows, nor does it explain the vulnerability itself. It just demonstrates it is possible to exploit such a vulnerability even under the worst conditions, like when the target buffer can only be overflowed by one byte."
-- first four sentences of The Frame Pointer Overwrite, Phrack 55
So lets see.. to make an exploit all we need to do is get root and modify that /etc/security file...
You don't need to write the file. In theory, if you can read that byte, you know the know the incorrect address at which code will be executed. When the program that you're exploiting takes input from you, give it input that puts the code you want executed in the location in the buffer that will be jumped to.
So, no, it's not trivially exploitable. But, no, it's probably not something to be summarily ignored.
Mandrake is very up to date, as said above, but another thing that should be noted is that apt-rpm has the ability to only install packages that are signed. this should cut down in the bad quality issue substiantially.
-- Who is the bigger fool? The fool or the fool who follows him? --
Mandrake is up-to-date in Cooker. Would they release Cooker? Will Cooker eventually be on CD as Mandrake 8 or somesuch? That's the question.
The entire point of 'apt' is two things:
1) Easy installation of package x.
2) Easy upgrade of package x to the latest version.
In order for the easy installation of package x, it has to be available in a place where 'apt' can find it. You mentioned that you'll only be able to download packages that are signed? Does that mean Mandrake will devote 3-4 developers, full time, to package all the various 10000+ utilities/applications/etc that are available for Linux? That's where my doubts lie. Debian's package maintainers do have the time an efforts - there are hundreds of them, all working on their own little packages. So, sure, if you can only download signed packages the quality can have some guarantee, but that's only if the package you want is available from a certified source(like your distribution maker's computers). But as soon as they don't have something packaged, all that guarantee goes out the window. If it was there in the first place.
As far as easy upgrades, it doesn't matter that Mandrake has Cooker. Ever tried to get a Cooker RPM to work on a regularily installed Mandrake 7.1 distribution? Never went well for me. So not only do they have to have it packaged, but it has to be packaged for all the various versions of their distributions.
A lot of work.
Dave
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
Thanks, you hit the nail on the head with that one :)
:) I'd rather contribute my fair share of effort than pay. Feels better that way :)
And Eazel will eventually be charging for their services, keep in mind. Of course you're willing to pay, so that's all right
Dave
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
Guilty myself as well. Tsk, tsk. Here it is:
Hellmouth Part 7
I've been using Debian for too long. Somebody told me to get a life, so in my infinite* wisdom, I tried the following:
.*life
apt-get install life
and then it told me that it couldn't find one. So I thought that any life could do, so I tried:
apt-get install
and it gave me two options (calife and xlife). I couldn't decide what kind of life I wanted, so I just forgot about it. It's too hard to get this life. (Oh wait. Maybe they meant like a LIFE not as in a program called 'life'). Hmm. Odd.
* Infinite = limited.
----
Toora Loora Toora Loo Rye Aye
There must be an Iraqi moderator on the loose tonight...
Just a bit of background:
;). Well, that's a lie. I got to the "fdisk" part of the install, and promptly lost 230M that I never got back :)
Four/five years ago I installed Linux on a *huge* 730MB hard drive(yeah, nifty, eh?
A year or two ago, I installed Caldera 1.3. Then I installed Caldera 2.2. Then I installed RedHat version 5.2, then Mandrake 6.2, then Red Hat 6.2, and now Debian. In each case, I had the distribution installed for a minimum of a month or two.
So, while I'm no guru, I have used a reasonable number of Linux distributions(and I'm not counting the dozens of "mini-distributions" that I've tried out and tweaked[plug: ramf, available at ftp://ftp.ibiblio.org/pub/linux/system/recovery , is my current favorite]).
Anyways, you can add all the automation to package management you want, but it all comes down the the package maintainers. Generally, when you're using Debian packages made by Debian maintainers, a certain quality can be expected. Packages will be dependant on what they need - and they will suggest packages that allow for full functionality. You can be reasonably sure that you'll get a man page for most commands, even if it's a simple "please refer to online documentation available at: http://www.foobar.com/foo/bar.html".
So, while I'm glad that other distributions are adopting 'apt', and the ability to automatically install packages and automatically update ones available, it will all come down to maintainer commitment. Commitment to quality, commitment of time. Red Hat, Mandrake, and friends usually don't update packages after a distribution has released. Sure, if there's a security bug found, they'll release an update, but that's pretty much it. I was never able to go to Red Hat's site and download the latest set of GNOME packages for my Red Hat 6.2 install.
However, when you run the Debian 'testing' or 'unstable' distributions(neither are as bad as their names suggest), when a new app is released, it'll generally be packaged and available through regular Debian mirrors within a few weeks. The Debian 'stable' distribution is targetted at a different audience, and is updated much less frequently.
Ok, so, enough of this. My point is that unless these distribution makers are willing to invest considerable time and money in keeping their packages up-to-date and well done, then 'apt' is probably just overkill.
Dave
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
Barclay family motto:
Aut agere aut mori.
(Either action or death.)
The article say there are no export controls on toys. Anyone know the details on this law? Just seems kinda strange. Does this include software?
Maybe a couple years ago before the relaxed controls on encryption a PGP game should have been marketed.
Jason
apt-get install common.sense
Well, I'm still waiting for
apt-get install athlon-1GHz
Hmmm... doesn't seem to work - Must be a bug. I'll see what I can do... look out for my patch (any day now...)
I have seen people buy other such stories on slashdot (some that didn't even have real articles ;) ).
I am more woried about soccer moms and deadbeat dads that vote than the geeky slashdot users (some or most of which are to young to vote or maybe just too apathetic... or... all of that could just be my view of things...)
I think it would make an interesting game... maybe a quake mod.
-I just work here... how am I supposed to know?
As a friend of mine pointed out, the funniest thing about the U.S. government wanting to put export control on PS2s, is that the machine is Japanese.
I found the article to be poorly worded. The author, I assume, intended to express that the PS2 is more powerfull than many home computers, not the Playstation.
Also, telling people that a Gameboy has more computing ability than all of what sent the Astronauts to the moon is a bad example. It is apples and oranges.
People would assume from that article that Sadam could take a Gameboy, put the right cartridge in it and fly to the moon.
-I just work here... how am I supposed to know?
Hussein does not suffer due to lack of food, medicine, or a real economy. In fact, embargoes like this only serve to make the dictator stronger. It's very easy to point a finger of blame at the US for all of Iraq's problems. Creating an embargo weakens the public and allows the dictator to villify the developed nations (read USA), further securing his base of power.
If free-trade is supposed to lead to the democratization of the whole world, then what's wrong with Iraq?
Jeremy McNaughton
------ Live simply so that others may simply live.
Are you serious? The Communist party is the only legal party. Castro is president for life. So they held local elections...big deal. There were local elections in the Soviet Union, too. Check out the Amnesty International annual report on Cuba
sig:
sig:
See the "..for smart people" banners Wired runs here? Look elsewhere guys.