Slashback: Zip, Language, Opportunism
Funny name, well-executed idea. YourMother writes "After almost 4 days of being offline, the social network Orkut is back online. The Orkut development team has been working nonstop since bringing it down on Sunday afternoon and quite a few new security features have been implemented to protect users information. Within the first 48 hours it was up, it gained almost 100,000 users, growing many times faster than other social networks like Friendster or Tribe. Did Google hit the social network bulls-eye?"
glinden points to a story with some more information about those security holes. "From the article, 'Sources close to Google suggest widespread XSS (cross-site scripting) hacks forced the closure of the service. It isn't clear how much personal data or communication was disclosed.'"
Playmate. Playmate, playmate playmate. An anonymous reader writes "A week after an appeals court ruling revived a Playboy Enterprises Inc. trademark infringement lawsuit against Netscape Communications Inc., the companies have reached a settlement in the case (See a ZDNet report) The terms of the settlement have not been disclosed. This puts an end to a closely watched case in the search engine advertising field. Several other lawsuits over misuse of trademarks in search engine ads are still in place. Google e.g. is embroiled in a lawsuit with Luis Vuitton regarding keyword-based ads in France and asked for a California court's ruling to back its trademark policy for AdWords after facing the threat of a lawsuit from American Blind & Wallpaper Factory Inc."
You have to admire such brave nomenclature. Michiel Frackers writes "Thanks for the link to my site, I got 3 gigabyte of traffic in a few hours! If I would have known, I would have written something in English. I have added an update about the Strangeberry product and its relation to Tivo at the URL you linked to.
I also included a link to my private blog (as www.frackers.com is more about my work in media & technology). Hopefully this clarifies some things for your readers, I did not intend to make this some kind of quest or game at all: it's just that I promised Arthur and his colleagues not to disclose what they are exactly doing, as you will understand."
And Anonymous joe writes with this link to an intriguing bit of Strangeberry speculation at the Register.
Nokia to port Python to Mobiles, not Perl An anonymous reader writes "Nokia was mistaken. In fact, El Reg reports that Python, not Perl, is the preferred language for scripting on its smartphone platforms. The availability of a Python implementation for mobile phones is part of a broader plan, including a JVM-based BASIC interpreter."
However, the Register article linked says that Perl is being considered, it's just that Python is being looked at as the primary language.
I wouldn't trust their pearls, either. Blade Leader writes "OCZ has issued a recall of OCZ Ultra 2 thermal paste after the Overclockers.com article on their lack of silver content. They blame the lack on their supplier, and claim they will be pursuing legal action."
A piece of history (or at least a piece of somethin' ...) Artemis writes "Searching along E-Bay and MikeRoweSoft.com I noticed that Mike Rowe has decided to sell the Microsoft Cease-and-Desist Letters and WIPO book he received on E-Bay. He is selling the WIPO book with the 25-page letter received from Microsoft's lawyers on January 14/2004.This inch-thick book contains copies of web pages, registrations, trade marks, other WIPO cases, emails between me and Microsoft's lawyers and much more. There are 27 annexes filled with information. This package also comes with the 25-page complaint transmittal coversheet that was sent with the inch-thick book."
What's wrong with gunzip, tar? whitefox writes "CNet News is reporting that PKWare & WinZip have settled their differences and will maintain Zip file compatibility for the foreseeable future with each supporting the other's security extensions. In addition, PKWare will include its SecureZip in the code it licenses to other software makers. This is good news in deed for users and developers alike!"
Everytime I search for electronics reviews or hardware reviews I get pages full of those stupid spam sites. What happened???
So are any of you guys members yet?
No-one I know has joined yet and I've not heard much on the net so are there really any members or is it just another conspiracy theory - ie you think it's good therefore you want to join?!?
Dupe. That's been done. I still don't know how to copy a zip file created by WinXP to a floppy disk. Any ideas? Trust Microsoft to screw it up.
PKWare deserves whatever bad happens to it. I remember when there was one standard compression: "arc". "PK" got caught pirating and selling the "arc" code, and rather than rectify matters, they created a perversely incompatible standard instead.
Will someone invite me...?
[blue] - The Ministry of Information approved this message...
What about this new type of matter? That's interesting.
Nice write-up on Netflix, but nothing really earth-shattering there either.
"I'd rather be a lightning rod than a seismometer." -Ken Kesey
Will the new "secure" zip format be published so other implementations can use it? There's the old pkzip "password" feature that infozip implments, that's deliberately weak because of the old export controls, but that doesn't count.
There is a bit of a chicken-and-egg situation about a meeting-place where membership is by invitation (can't you tell I'm not one of the exalted :-)
:-)
It would be interesting to see what the demographic of the initial seed population was - and to see whether that influenced the community over time... As any fule know, the initial conditions can have a profound impact on any time-dependent phenomena
Simon
Physicists get Hadrons!
if we're meant to disregard the message, how can we mod you up, because we won't read your message because of the "please disregard this message" message?
no im confused!
HEEEEEEEEEELP!!!!!!!!!!!!!!!1
Did anyone ever Translate the guys site about the Strangeberry?
[blue] - The Ministry of Information approved this message...
Doesn't he need those for something???
...who associates the name "Orkut" with the Hanna-Barbera Smurfs ripoff, "The Snorks"? ...I loved that show.
I read the description of Mike Rowe's auction on Ebay. He says that he is auctioning "the WIPO book with the 25-page letter I received from Microsoft's lawyers on January 14/2004," but then says, "I have two copies of these and I will be keeping one for my own personal memoirs." So -- is the subject of the auction a true original? Did Microsoft serve a duplicate set of originals on the same guy? Or is he just selling a copy that he made? If I bought that letter, I would want to see blue ink on the signature line.
I am sorry but zip is one of those things that has been around too long. Ace, rar, bzip2... now that's what M$ should support straight out of the box.
Wow. The highest bid on the cease and desist letter is currently $3,751.00. Not bad.
find / -name "*.sig" | xargs rm
Is 7-Zip.
What's wrong with gunzip, tar?
Have you ever tried to extract a single file from a gzip'ed tar archive? It's not possible without unpacking everything and throwing away the bits that you don't want.
Nokia to port Python to Mobiles, not Perl
Yay! This makes *much* more sense. Python rocks and is perfectly suited for portable devices on small devices, hence the successful PalmOS port.
Orkut - Funny name, well-executed idea.
Urm.. it's been a very badly executed idea if they've had to shut it down already because of hacking. Then there are the disgruntled reports from users that think it's completely pointless. It's only popular because Google is - they could have sneezed and everybody would have noticed.
I thought OrkUT was a reference to the Uruk-Hai of Utah (yes, the place where they are allowed to marry more than one goblin)
He received them in duplicate, and he's only auctioning one copy. That said, I'd auction 'em both; the price is at $3,751.00 with more than seven days remaining!
You can't judge a book by the way it wears its hair.
They haven't let me in, so I suspect the answer is yes.
OK, So we are deciding that running interpreted languages on a byte-code interpreting virtual machine is a good use of a phone right?
I need to go write a JVM in BASIC now (if it hasn't been done already) so that when I have kids, they can see what games under 6000fps look like.
Sigs? We don't need no stinking sigs!
I ran out and bought a full box of silver-less paste at CompUSA (and yes, I got the CompUSA) label on it. My attorney is filing a "false advertisement" suit against them on Monday. I figure if everyone else can get "sue happy" then so can I. Maybe I'll get to retire early.
As I have some karma to burn, I will ask this question that has been running in my head for a while now. I might look like an idiot, but what is a Slashback?
Write boring code, not shiny code!
I don't see how Python figures into this. Surely they aren't going to layer a BASIC interpreter on top of Jython on top of the JVM. That seems like a horrendously poor use of resources for an embedded system with limited power and hardware volume.
I am becoming gerund, destroyer of verbs.
It should have never been implemented with lossy compression.
hi guyz :D
i am really cool lol
plz invite me kthx
3>3>3>3>3>3>3>3>
What is XSS (Cross-Site Scripting), and what about it can be used to compromise site security?
Schwab
Editor, A1-AAA AmeriCaptions
When are we going to be able to read /. on our mobiles? /. seems to be everyone (ok, all the /. readers') favorite way to waste time, and what better than to be able to waste time all the time, even when you're not at a computer? If any /. editors are reading this and want to try out some software to help in the task, please drop me an email.
I can already see the tons of spam sent out with the "Invitation to Join Orkut" header. If the Orkut hype reaches moderate levels, a lot of people will open the email. Combined with the nasty worms of the last week, many people will open attachments.
Thanks Orkut. Thanks Spammers. Thanks Russian spammers posing as script kiddies.
As amazing as it sounds, Google don't really pay that much attention to web technologies. They may have some pretty impressive clustering, database and analysis technologies, but the way they apply web technologies such as HTML and HTTP is lacking.
For a start-off, their website isn't even valid HTML. If they moved some of the presentation details to CSS, they could lop a massive chunk of bandwidth off their bill and take some of the load off their servers and speed up access to their site. I don't know what they are paying at the moment, but it's bound to be significant.
Their spidering technologies only half implement HTTP. For instance, they ignore the content-type header, favouring the file extension instead. The only other software that I have heard of being that broken in terms of HTTP is Internet Explorer.
Their ranking algorithms pay a little attention to the HTML structure (e.g. they rank keywords in <h1> elements highly), but then they comlpetely ignore other significant markup, or screw it up, like definition lists.
So they didn't understand the rules for escaping special characters in HTML. It doesn't come as a surprise, cross-site scripting attacks bite many people who haven't paid attention to the HTML specifications.
It's a shame, because so many people bend over backwards to get ranked highly in Google, that if Google actually tried to use HTML and HTTP properly, it would cause loads of people to write higher-quality HTML overnight.
In a strange twist of irony, he states that he will not accept bids from zero feedback bidders, yet he himself has zero feedback. Sorry bud, but I don't buy from zero feedback sellers, although serious sellers may email me with their intentions...
i can't believe you'd deal with a lawyer just to get money.
1) Annoy Microsoft (or other high-profile company).
2) Get sent a cease-and-desist letter.
3) Sell it on E-bay.
4) PROFIT!
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
Why exactly do we want proprietary encryption in an open file format? If people encode with pkzip, it will require a commercial product to read. PK is simply doing this to try to eliminate the free competition. Since PK created the zip format it really can't be called a standard, but it has became one. Winzip's, being open source, can be implemented everywhere... but there is no guarantee that the file is encoded in that format. Since they will read each others' files, users will see no difference.
Upon clicking the link, you're taken to a page where you're told to get a friend to invite you.
And with no way to search to see if one of your friends is a member, just so you won't know to be offended if someone you thought was a friend was on the inside and hasn't invited you.
That's wrong, and makes me not even INTERESTED in becoming a member of Urkut!
That is, of course, until one of your friends invites you to click into the clique. That's when the test of your character will take place.
I am unfamiliar with eBay. If a significant chunk of eBay users won't do business with users with zero feedback, how does a bidder or seller become no longer zero feedback?
I don't know about Orkut, it somewhat feels clinched together and I miss a true focus on what TO DO there - just like friendster. I like "business social networks" such as Ryze and openBC much better because they try to concentrate on a specific audience and cater to their specific needs.
Ryze seems to be lost in a tide of MLM scamsters, though. You cannot escape those loons there, MLM everywhere even if the Ryze AUP says otherwise. At least on openBC, they actually kick spammers and MLM recruiters from the system. I also like that openBC is a European site. It somehow feels like they really thought on how to make it attractive for non-American users, as well. Ryze is very poorly designed compared to that.
I miss such features in Orkut. Their growth is impressive, but what for if there is no actual use for it?
no text! I've tried to post articles and they always get rejected - then i post something and someone else get's the credit for it! grrr
If you cannot keep politics out of your moderation remove yourself from the Mod Lottery.. NOW!
As the Register article suggests, preventing piracy with DRM would be one of the concerns if Netflix were to launch an online video-on-demand service. But let's think about this for a minute. People can already rent the physical DVDs and rip them to a digital format. Is making the files available for direct download any more dangerous?
In fact, it's less dangerous, if anything. If you rip a generic DVD and share it on Kazaa, etc., it's completely untraceable back to you -- anyone could have ripped that DVD. However, an online video-on-demand service could embed some sort of unique watermark in the file to identify the customer, so that they could be held responsible for any illegal copying (as with the recent Oscar screener fiasco).
In their fear of online piracy, the MPAA/RIAA/etc. have forgotten that
Cheers,
IT
Power corrupts. PowerPoint corrupts absolutely.
it didn't support spanning. Also the recovery record option in winRAR is handy for those who fancy themselves unlucky.
And, to get philosophical -- is it really possible to meet people online? Can you really have "met" somebody ... whom you've never met before???! I just don't get the point of these "friend networks," at all.
Breakfast served all day!
Think about it - can you afford not to invite the Fnkmaster into your Orkut family? I didn't think so... don't be afraid... push that invite button...
Posty Firsty?
Java already (sic) "runs like interpreted basic on an 8bit micro". A java implementation of interpreted basic makes me want to cry....
--
"we live in a post-ideological world..." - Billy Bragg.
A giant sociology research project where a small community is created from scratch, then allowing other members enter only by invitation the entity who commissioned the research could observe how, at which speed, in what geographical direction the circle grows, also depending on other social or economical factors.
The results could of course be used in many ways.
Maybe he made a copy himself. So what? Suppose he copied it five or ten times. That's a limited edition set of five or ten prints, mint condition. And it's not like these are pictures of, say, Campbell's soup or anything.
In Soviet Russia message disregards you!
Could someone please try to explain the point of web based "social networks" (I know the point of real world social networks)?
http://yetanotherpoliticalrant.blogspot.com
http://wap.slashdot.org/
- Tjp
I am in wallow with my inner money grubbing capitalistic pig. ... Oink!
The .tar.gz and .tar.bz2 formats are "solid" archives: they enchain the files into a single archive, the .tar file, and then compress that as a whole. This allows them to achieve better compression because they can compress redundancies between files as well as within them. Zip, OTOH, is what I call a "segmented" archive: the files are individually compressed and the compressed images are enchained.
Solid archives can be smaller than segmented, but are more difficult to manipulate after the fact:
- To extract a single file from a solid archive, you have to read everything in the archive, at least up to the file you're extracting. A zip file has a directory at the end that quickly locates the desired file.
- To add, delete, or replace files in a preexisting archive, you have to decompress the whole thing, manipulate the files, and then compress the whole thing again. It can be done, but it's slow and can take up lots of disk space. Zip can do these things directly, leaving unaffected files unchanged.
- Finally, solid archives are more fragile than segmented ones. If a solid archive is damaged, everything from the point of the damage onward is lost. With zip, however, only the files at the damaged portion are lost, and subsequent files are still recoverable.
IIRC RAR can generate either a solid or a segmented archive.Zip, furthermore, has a feature that can preserve arbitrary file metadata such as NTFS file permissions. Tar, OTOH, is meant for Unix, and can only preserve metadata relating to Unix.
There's no technical reason that you couldn't create a .zip.gz or .zip.bz2 file, getting a solid archive that preserves all the metadata, but alas, you'd probably confuse most people doing that :-(
Ooh, moderator points! Five more idjits go to Minus One Hell!
Delendae sunt RIAA, MPAA et Windoze
Dozens of invitations are already up for sale on
E-Bay and can be had quite inexpensively, it would appear.
// TODO: Insert Cool Sig
I think I blew one away thinking it was spam
I'm not sure what will become worthless first...the WIPO book or SCO stock but either way this just has to be the biggest waste of money I've ever seen!
I didn't read the article to see if a link was there but here it is again
-Pat
1. Supposedly violate Microsoft's Trademark
2. Sell cease and desist on Ebay
3. ???
4. Profit!
Dude, if you join and invite me, I will paypal you $1. Then, when I go to work tomorrow, I will be all like, "Yeah, I'm on Orkut" and all the geeks at work will be like, "Dude, you are the alpha geek. Let us in!" and I will be all like "No way! You guys are lame!" and they will be all like, "Dude, you totally suck, now let us in" and I will be like ... well, you, like, get the point. 'Cause cliques are like, totally.
;=)
It will make my Friday. I'd buy that for a dollar!
7-zip achieves such good compression in part by losing information. Try compressing a directory tree with same-named files in different directories and you'll see what I mean.
Hanna-Barbara had another show called The Snorks. That's probably what you're thinking of.
yes, i'm in. shoot me an email and you can be too.
got biv?
A couple of days ago, the following message showed up on Friendster:
We're working on it!
We wanted to let you know what we're working on here at Friendster. As many of you have pointed out, site performance for Friendster isn't exactly where any of us would like for it to be. Rest assured. Site performance is our number one priority.
The team here is also working on making changes to the system to meet the needs of our growing community, including new and improved features. We're not ready to show and tell yet. But we'll let you know as soon as we are.
In the meantime, you can help us by sending your suggestions for how to make things better at feedback@friendster.com.
got biv?
What's wrong with:
to extract a file, or
if you want to view it?
the growth in cynicism and rebellion has not been without cause
Ok IANAPG (I am not a programming god) So maybe I don't know wtf i'm talking about...
.mp3 file and a .cdg file.
.mp3 and .cdg into 1 .zip file.
.mp3 file into winamp. I used the infozip static DLL and hacked away at the VB source project. I made something ugly that works well.
Anyways..
alt.binaries.sounds.karaoke..
SYSNOPSIS
I've been getting into karaoke on the PC for the last year or so. I'm going to explain it for the benifit of the folks that don't know what im talking about.
Karaoke has a special format called CDG. It's some weird kind of subcode in the audio data that can be read by compatible CD drives. The CDG data is used to display the lyrics on screen, sort of like a 320x240 BMP slide show, but with 64 pallete cyclable colors.
They subcoded it so you could put a CD in a normal player and still get sound (without the lyrics/pictures)
Well fast forward to 10 years past CDG creation. Some clever people figured out how to not just rip the audio data, but the CDG data as well. In order to play MP3+G karaoke you need 2 things, a
Unfortunatly the CDG files are very large. Mostly it's just redundant data, so zipping it results in very nice compression. To make it easier on your fat table, you put the
So basically, there's all these karaoke zip files being created with 2 or 3 different versions of zip, all incompatible with one another.
I wrote a crappy, lame, yes lame, really fucking lame VB bastardization for unzipping these files to a temp directory, and cue'ing the
Until I run into those zip compatibilty errors. My winamp ends up with "Pkzip 2.1 file, PKzip 2.0 support only" showing up in it's playlist instead of the karaoke song I was hoping for.
Anyways, I just wanted to make a on topic post, and the only thing I can say about it other than explaining my situation is to say "THIS IS ANNOYING AS HELL!" Why can't the 2 zip giants get along?
As the poster implied, extracting, adding, and removing individual files from a .tar.gz/bz2 archive is significantly slower than with a .zip archive (particularly as the archive becomes larger).
.zip file read/write, providing dynamic compression... I'd actually like to see that in linux (as a pluggable kernel filesystem, accessible from the command line)... I know mc provides something like this with its own pluggable vfs, but its use is thus limited to mc.
.tar.gz/bz2 has going for it is that it is a *nix standard and has higher compression.
Theoretically, with the right vfs interface, you could mount a
The main thing
Basically, the trade-off is size (tar.gz/bz2) vs. flexibility/speed (zip).
Buy Steampunk Clothing Online!
I just finished sending out a note to our users telling them to stop using the .zip extension since the latest version of mydoom can now randomize the file name with the .zip extension. .zip joins the ranks of .exe .com, .bat, pif... At 2,400 rejects today on a 1,000 user mail server it's not worth the resources to scan or defang (with Sanitizer) and pass them on to the mail box.
Somewhere buried in the bowels of eBay's user agreement, it says you have to be 18 to sign up for an account. I personally think this kid is a sleazeball, he'd fit in perfect at the RIAA. He has no problem with taking what someone else created and claiming it's his own, then cashing out when the cards are in his favor.
What was it that Wil Wheaton said about kids that let fame go to their heads? I forget, but I'm sure it will happen to this brat - the real world has ways of deflating a bloated ego.
---
DRM is like antifreeze, to the MPAA/RIAA it's sweet, to the consumers it's poison.
Jeez, why can't you solve your problems instead of just making new ones ?
Like the knee-jerk port blockers who just made everyone use port 80 for everything, this isn't a solution. It just means that people will start sending the files with NO extension, just the file name; mail handlers will develope enough to detect that and let winblows users click to open; and then a virus will come alone that doesn't use an extension in it's file name.
After that, you will ban attachements all together. Your users will switch to sending files through one of the IM programs, and then a virus will use that means of spreading, and you'll ban that too.
Here's a fucking idea. Find a way to have computers that do what YOU AND YOUR USERS WANT, and not what some pimply faced teenager a continent away thinks would be funny.
From the ebay listing:
Sorry, I will not be accepting bidders with 0 feedback. If you have 0 feedback and are serious, please contact me via the contact seller link at the top of this auction so that I may verify your intentions.
P.S. Mike Rowe has zero feedback on Ebay and created his account on 26 January.
JET Program: see Japan, meet intere
...he has no idea what he is talking about
You see, it is 'obvioussly' the interperter and no the program, and not the sensors.
Those who sacrifice security to condemn liberty deserve to repeat history or something. - Benjamin Santayana
Looks like there's pending patents for the PKWARE format even though it's completely straightforward. It includes both password-based symmetric encryption, and public-key encryption using x509 certificates. There's a no-royalty license that I didn't bother to read but it looks like for the public-key format, you're only allowed to decrypt encrypted files under the license, not encrypt new ones. If they're going to use x509 certificates I don't understand why they didn't stick with s/mime format.
You know, I just thought of a neat new way to harvest email addresses ...
Those who sacrifice security to condemn liberty deserve to repeat history or something. - Benjamin Santayana
All I ask in return is that you set me up with your sister. She should be between the ages of 18 and 28 and living in London, England.
Seriously, why pay for an invite when all you have to do is pimp out your sibling. Think about it, people. You know how to contact me.
In fact, I know you are.
Need I say more? Better compression that Zip. For those of you who will talk about 7zip; 7zip is too slow compared to winrar, almost 4 times slower while having 5-10% better compression, which is not worth it. You have to compromise between time and compression ration, WinRAR is a good bet.
Invitation only? Hah... these are a bunch of people who didn't get into the country club and just want to feel special...
They probably think that people will end up being envious of an Orkut card... like it means diddly squat..
I bet they all vote Democrat, too...
And geeks support this?
>why can't you solve your problems
Uh I just did, you obviously have never seen a Company brought to it's knees by a worm - the cost in time and $ is such a waste.
>and then a virus will come alone that doesn't use an extension in it's file name
True, but thats future, Could the fact that Windoze needs file extensions to run be the achilles heel to the regular virus ?
> ban attachements all together
Thats already happening for some.
Encryption of files and archives using 5 different methods: Blowfish (128-bit), DES (64-bit), Triple DES (128-bit), AES 128-bit, and AES 256-bit.
That, plus all this here would be why I use Power Archiver.
Dude, with the XSS bugs in Orkut, joining Orkut is the equivalent of getting your email addresses harvested.
There are no trails. There are no trees out here.
I would join Orkut if the text in the jpg on their home page had the grammatically correct sentence "Whom do you know?"
But alas.
Yoda
-Clio
Karma: Bad (mostly from not giving a fuck)
Blog: http://clintjcl.wordpress.com
Dammit, me too! If a woman seems interested in me, I start thinking, "OK, what's wrong with her?" Doesn't happen that often, though.
one hundred twenty
is just enough characters
to write a haiku
1. Set up social-networking site
2. Let no one in
3. Once everyone is talking about it ask for $1 per invite via PayPal
4. Profit!
Any sufficiently advanced man is indistinguishable from God
and there's still six days to go!
who the hell would pay that much for this shit?
it's probably not that hard to get your own C&D from microsoft.
?Who controls the past now, controls the future.
Who controls the present now controls the past.?
Really?
I thought that you and Edna Crabapple had something going on.
Those who sacrifice security to condemn liberty deserve to repeat history or something. - Benjamin Santayana
Hmm... what is the advantage of the orkut system over say chatting to your mates in a private chan on IRC, or on MSN, or posting on a forum?
The world would be a better place if...
I really wouldn't worry about it, you could always sue him...