Slashdot Mirror


FREAK Attack Threatens SSL Clients

msm1267 writes: For the nth time in the last couple of years, security experts are warning about a new Internet-scale vulnerability, this time in some popular SSL clients. The flaw allows an attacker to force clients to downgrade to weakened ciphers and break their supposedly encrypted communications through a man-in-the-middle attack. Researchers recently discovered that some SSL clients, including OpenSSL, will accept weak RSA keys–known as export-grade keys–without asking for those keys. Export-grade refers to 512-bit RSA keys, the key strength that was approved by the United States government for export overseas. This was an artifact from decades ago and it was thought that most servers and clients had long ago abandoned such weak ciphers. The vulnerability affects a variety of clients, most notably Apple's Safari browser.

89 comments

  1. Is there any way to block the use of old ciphers? by msobkow · · Score: 1

    I know you can configure some options for PGP to block the use of insecure ciphers, but is there any way to configure a Linux/Debian box so that it refuses to accept insecure ciphers by default? Not just for the browser, but globally for all SSL connections.

    --
    I do not fail; I succeed at finding out what does not work.
  2. FREAK by pushing-robot · · Score: 1

    Factoring Attack on RSA-EXPORT Keys

    Why do people go to the trouble of making an acronym if they're going to screw it up anyway?

    --
    How can I believe you when you tell me what I don't want to hear?
    1. Re:FREAK by gstoddart · · Score: 2

      Or, you know ... Factoring-attack on RSA-Export Keys.

      Seriously, there's a lot of different ways to do an acronym (or a backronym as this likely is).

      My suggestion? Get over it.

      --
      Lost at C:>. Found at C.
    2. Re:FREAK by halivar · · Score: 1

      Yeah, shoulda used Friggin' Radical Exploit Attacking Keys.

      If you are a GO or NGO in need of creative backronyms, I can be purchased for moderately wasteful sums of cash.

    3. Re:FREAK by OverlordQ · · Score: 2

      So the arconym is FARK? Sponsored by Drew.

      --
      Your hair look like poop, Bob! - Wanker.
    4. Re:FREAK by TechyImmigrant · · Score: 2, Funny

      Factoring Attack on RSA-EXPORT Keys

      Why do people go to the trouble of making an acronym if they're going to screw it up anyway?

      Factoring Attack on Rsa-exporT keys?

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
  3. 512 should still be too high a bar... by Anonymous Coward · · Score: 0

    Oh, there's a full-on MITM attack going on to facilitate this in the first place. Gotcha.

    1. Re:512 should still be too high a bar... by jhantin · · Score: 1

      MITM positioning is a prerequisite, but that's not hard if you run a Wi-Fi hotspot. This is a bid-down attack, tampering with initial negotiation to limit the cipher suite and strength to something more breakable without raising alarms.

      If you can additionally prevent the use of PFS cipher suites so the 512 bit key is used for pre-master secret encipherment, you need only break the static 512-bit key once to read all the traffic protected by it.

      --
      ...when you're writing a game...tweak the difficulty of "Easy" to something [your mother] can cope with. -- onion2k
    2. Re:512 should still be too high a bar... by compro01 · · Score: 2

      512 bits isn't a very high a bar anymore.

      It took 6 months and 8000 MIPS-years to factor RSA-155 back in 1999.

      According to Dhrystone, the CPU in the computer I'm typing this post on could do those 8000 MIPS-years in roughly 3 weeks and you could probably knock that down to less than a day if you brought the GPU into the matter, let alone something with some real oomph.

      --
      upon the advice of my lawyer, i have no sig at this time
  4. Re:Is there any way to block the use of old cipher by Anonymous Coward · · Score: 0

    Build a custom kernel that doesn't support those ciphers?

  5. Safari browser? Hmm by Anonymous Coward · · Score: 0

    Never been too much concerned about this until lately with the SuperFish thing with Lenovo. Another way to circumvent security. Not a fan much of Safari and if you look at the stats it appears not a lot of Apple fans even enjoy Safari all that much. I recently started trying out the new Safari in Yosemite which actually has some good performance and has added a couple nice features. Since Safari is using WebKit engine I wonder if Chrome is affected by this SSL issue? I know Google had talked about shoring up SSL versions and eliminating the weak ones.

    1. Re: Safari browser? Hmm by Billly+Gates · · Score: 1

      Google forked their own version of SSL called Googlessl. My guess is chrome would use this.

      The big question is Googles implementation based on openssl or libressl? The bug might still be there if former

    2. Re: Safari browser? Hmm by Anonymous Coward · · Score: 0

      Chromium uses libssl from NSS (i.e. Mozilla):

      http://www.chromium.org/developers/design-documents/network-stack#TOC-SSL

  6. Who gives a shit anymore by Anonymous Coward · · Score: 0

    Computer technology is untrustworthy anyway, chock full of back doors by anybody who is involved in making the hardware, the software and the services. Nobody wants "their" things to be used by someone they don't agree with unless they can betray them as they see fit. Security is theater, a trick to make you entrust your secrets and your belongings to a machine that is built and programmed to serve a different master.

    1. Re:Who gives a shit anymore by Opportunist · · Score: 1

      Because there's still a difference if the local police department has a key to your house or whether the lock is easily picked with a coat hanger without leaving any traces of trespassing.

      You see, it's not ONLY the government that's out to get you.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:Who gives a shit anymore by AHuxley · · Score: 1

      It adds to the history of cryptography. The issues did not stop with an early cell phone, new hardware at an embassy in the 1970's or early banking codes.
      Generations have been told to use, supplied with or trusted brands. The more weak tame code that is found, the more people can talk about how.

      --
      Domestic spying is now "Benign Information Gathering"
  7. The real story is by bulled · · Score: 1
    As Matthew Green points out:

    This might be academic if it was just a history lesson — but for the past several months, U.S. and European politicians have been publicly mooting the notion of a new set of cryptographic backdoors in systems we use today. This would involve deliberately weakening technology so that governments can intercept and read our conversations. While officials are carefully avoiding the term “back door” — or any suggestion of weakening our encryption systes — this is wishful thinking.

    1. Re: The real story is by ZeroWaiteState · · Score: 1

      Actually, the reason "export strength" RSA even exists is because of U.S. law classifying long-key RSA the same as military hardware. In other words, you could be sent to prison for selling it outside the U.S. If the FBI/NSA had their way back in the 1990s, everyone would be using this weak kind of "security" today.

    2. Re: The real story is by bulled · · Score: 1

      AFAICT that is the point that Mr Green is making. If you let policy purposefully weaken security, it will eventually be exploited. "Nobody but us" is a fallacy.

  8. Damn you Putin! by WillAffleckUW · · Score: 1

    Just because the NSA is trying to weaken encryption standards, why do you have to pile on too!

    --
    -- Tigger warning: This post may contain tiggers! --
  9. Firefox OK, Chrome needs fixing by SIGBUS · · Score: 4, Informative

    I tried the test on up-to-date Firefox (36.0) and it's immune, but Chrome on Android (40.0.2214.109) is vulnerable.

    --
    Oh, no! You have walked into the slavering fangs of a lurking grue!
    1. Re:Firefox OK, Chrome needs fixing by jo_ham · · Score: 2

      Also interesting to note here that according to Slashdot, it's official that Safari is more notable than Chrome.

      Must be market share or something.

    2. Re:Firefox OK, Chrome needs fixing by Anonymous Coward · · Score: 0

      Now if only Mozilla would start doing security updates for the ESR versions. I mean like 3.5, 10, 17, etc.

  10. Re:Is there any way to block the use of old cipher by slashdot_commentator · · Score: 1

    You could implement your own version of the SSL libraries that don't implement "weak" encryption protocols. When confronted by a client/server session that tried to default to the vulnerable mode, the client would get a "no failover" error message. The homebrew version would be no help in "forcing" a secure SSL session, and the browser/server would not be standards "compliant". Oh well. Oh, it would have to be a browser with available source code; hello firefox, goodbye safari.

    --
    There is no America. There is no democracy. There is only IBM and AT&T and DuPont, Dow, General Electric, and Exxon
  11. Heh by waspleg · · Score: 1

    âoeIn practice, I donâ(TM)t think this is a terribly big issue, but only because you have to have many âoeducks in a rowâ: 1) find a vulnerable server that offers export cipher suites; 2) it should reuse a key for a long time; 3) break key; 4) find vulnerable client; 5) attack via MITM (easy to do on a local network or wifi; not so easy otherwise),â said Ivan Ristic of Qualys.

    (Unless you're the NSA, then you have more MITM "opportunities" than you have people to exploit them...automation coming soon...)

  12. Re:Is there any way to block the use of old cipher by chill · · Score: 3, Interesting

    Yes. http://www.openssl.org/docs/apps/ciphers.html

    The question is does OpenSSL accept the weak ciphers as a downgrade bug even when EXPLICITLY DISALLOWD.

    I haven't seen answered in any of the linked articles so am digging/testing.

    After the last couple of bugs my organization set the explicit cipher/algorithm/has acceptable list. The export ciphers were excluded on purpose from our list.

    SSL Labs https://www.ssllabs.com/ has a recommended list buried in their documentation somewhere.

    --
    Learning HOW to think is more important than learning WHAT to think.
  13. Arstechnica post fake Apple/android security alert by lippydude · · Score: 2

    "The so-called FREAK attack - short for Factoring attack on RSA-EXPORT Keys - is possible when an end user with a vulnerable device - currently known to include Android smartphones, iPhones, and Macs running Apple's OS X operating system - connects to an HTTPS-protected website configured to use a weak cipher that many had presumed had been retired. At the time this post was being prepared, Windows devices were not believed to be affected, and the status of Linux devices was unknown"

  14. Re:Is there any way to block the use of old cipher by chill · · Score: 3, Informative

    Answering myself to preserve the thread.

    It looks like the export cipher suite must be enabled for this to work. So if you didn't turn off old, busted ciphers then you're potentially vulnerable.

    Meh. Set your approved cipher suite and be done with it.

    --
    Learning HOW to think is more important than learning WHAT to think.
  15. LibreSSL / OpenBSD vulnerable as well? by thatseattleguy · · Score: 2

    So would clients built using the SSL libraries from the (stripped-down, un-borked) version of SSL that the OpenBSD team recently did - LibreSSL - vulnerable as well?

    1. Re:LibreSSL / OpenBSD vulnerable as well? by Anonymous Coward · · Score: 1

      No. LibreSSL deleted all the EXPORT stuff. Not vulnerable.

    2. Re: LibreSSL / OpenBSD vulnerable as well? by Anonymous Coward · · Score: 0

      once again openbsd is at the forefront of security and was not vulnerable. good work theo de raadt.

    3. Re:LibreSSL / OpenBSD vulnerable as well? by Anonymous Coward · · Score: 0

      Even with all the Export stuff thrown out, do they explicitly check that the key being offered is not a weak "export grade" RSA key? If I understand the problem correctly, those keys are compatible with "real" non-export RSA, and the attacker convices the Server to generate an export grade key, although the client supports proper RSA, i.e. the client does not even have to support export RSA, only the server has to have it as an option for the attack to work.

  16. Re:Is there any way to block the use of old cipher by Anonymous Coward · · Score: 0

    With Google Chrome you might be able to cover them all with a command line switch like this:
    --cipher-suite-blacklist=0x0003,0x006,0x0008,0x000b,0x000e,0x0011,0x0014,0x0017,0x0019,0x0026,0x0027,0x0027,0x0028,0x0029,0x002a,0x002b

    REF:
    1. http://peter.sh/experiments/chromium-command-line-switches/#cipher-suite-blacklist
    2. http://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#tls-parameters-4

  17. Ciphersuite Negotiation by TechyImmigrant · · Score: 1

    Ciphersuite Negotiation is a liability. A good security protocol will not have it. It is empirically impossible to get right.

    Pick one set of algorithms, good enough for the lifetime of the device or system and any changes are done by replacing the single static suite on both ends, say once per decade. Make the whole thing so utterly simple to implement that it would be hard to get wrong.

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    1. Re:Ciphersuite Negotiation by Opportunist · · Score: 2

      One set of algorithms, good for the lifetime of the device... hmm... you mean, like, say, SSLv3 until about 6 months ago? If we hadn't found POODLE, it would still meet all criteria for a good, secure algo for the foreseeable future. At the very least for the lifetime of any device build within the last year (until about 6 months, of course).

      There is no such thing as "guaranteed to be secure for the lifetime of a device". All it takes is to find a fundamental flaw in the algorithm (like, well, POODLE) and what was supposedly bulletproof for the next few decades crumbles like a house of cards the next day.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:Ciphersuite Negotiation by TechyImmigrant · · Score: 1

      I mean like crypto algorithms with lots of security headroom. 256 bit keys and no known attacks, or equivalent security. DJBsque Edwards curve ECC to minimize the implementation errors that keep cropping up. No X.509 because it's seems impossible to implement securely. And on an on.

      TLS is not fit for purposes. We should stop pretending and replace it. That's what I'm working on.

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    3. Re:Ciphersuite Negotiation by Whip · · Score: 1

      No negotiation, replace the suite on both ends once per decade.

      So, what... the Internet gets together and decides that January 1 of every year ending with '0' we'll upgrade every server, client, and embedded system in the world to the latest security protocol while disabling the previous decade's? And people whose systems are out of support or can't be patched (which would only be, what, 80% of the current internet?) are just SOL?

      I think I see some flaws in your plan.

    4. Re:Ciphersuite Negotiation by TechyImmigrant · · Score: 1

      One of the problems with TLS is we keep adding better ciphers, but the old weak ciphers hang around and implementation errors leave us vulnerable to downgrade attacks. A big problem with negotiable cipher suites is the inability to retire old ciphers. We might like to think it can be done, but it isn't a solved problem and TLS is a prime example of that failure.

      But crypto has moved on a long way and we have a lot more of the basic crypto functions coming with mathematical proofs of the hardness bounds of attacks, which was simply not true when those older ciphers, hashes and macs were published.

      I would prefer negotiation to be in terms of algorithm parameters we can negotiate on the fly, such as the number of rounds on the cipher, or the amount of entropy fed into a sponge construction. It's easy to increase an iteration count. It's hard to add a new algorithm to a device after it's been built. These methods come with their own problems, but they're a heck of a lot less of a problem and a heck of a lot more solvable than ciphersuite negotiation, which has failed year after year.

      There is a reasonable physical arguments that even with quantum computers that can do what people claim they can do (not likely) that it is impossible to brute force anything above O(2^360). So lets accept that we can pick a secure key size, pick it and focus on the parameters we can alter over time, rather than those that we cannot. Also focus on things that are implementable by any reasonable programmer or circuit designer. It's incumbent on any crypto system designer to fight against complexity at all costs. Complexity will undermine your secure algorithms and protocols in ways you cannot control.

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    5. Re:Ciphersuite Negotiation by Anonymous Coward · · Score: 0

      There's a problem with that: we have no idea how to make a secure cipher. Sure, we're pretty sure AES is secure, but we were pretty sure DES was secure, too. We simply lack the mathematical tools to prove that a given cipher actually provides those 720 bits of security or whatever you think is necessary for quantum computer resistance, so if we choose a single cipher, we might latter find out we were wrong.

      That said, TLS's cipher choice options are a mess. One improvement would be for servers to have default cipher lists that only accept settings considered secure, even if it locks out older clients. TLS should be secure-by-default and weakening of that security should be something that requires special settings on the server and/or client.

    6. Re:Ciphersuite Negotiation by kesuki · · Score: 1

      "One set of algorithms, good for the lifetime of the device..."

      well the easy way to do that is set the device lifetime to 5 seconds. it takes 6 seconds to look up a rainbow table.

    7. Re:Ciphersuite Negotiation by TechyImmigrant · · Score: 1

      I keep seeing people declare TLS's cipher choices to be mess and propose cleaning them up somehome. Look deeper. The problem is not adding things, it is retiring things. If you can't retire algorithms, you can't clean up. If you can't clean up, then negotiation is bad.

      So you have to live with your initial choices. Make them well.

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    8. Re:Ciphersuite Negotiation by Opportunist · · Score: 1

      Again, any algo considered secure today may be rendered useless by a discovery tomorrow. That's the nature of cryptography. Time and again we have seen that what we considered "unbreakable" (within reasonable time) offered some side channel attack or an implementation flaw (or worse, as in SSL3, a design flaw that CANNOT be patched) that turned it into a useless waste of computing cycles.

      You cannot "promise" that whatever protocol, implementation or procedure you offer will be secure for the next X days/weeks/years with absolute certainty. Hell, given what went down within the last 12 months, anything could blow up tomorrow.

      But until it does, it is secure. Security is a bit like a scientific theory. Sound and solid and true and real... until someone comes in and proves it wrong.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  18. Chrome needs fixing, Chromium doesn't by Anonymous Coward · · Score: 0

    Fun thing is that Chrome (40.0.2214.115) is vulnerable, Chromium (38.0.2125.122) is not. At least on OSX.

  19. OpenSSL and export suites by yuhong · · Score: 1

    What is sad is that OpenSSL disabled the EXPORT1024 ciphersuites in 2006. If you don't know what these are, in year 1999 the US government raised the limit to 56-bit encryption and 1024-bit RSA. They were described in https://tools.ietf.org/html/dr... . And for the record it was in year 2000 that the restrictions was removed for "retail" software.

  20. Re:Arstechnica post fake Apple/android security al by Anonymous Coward · · Score: 0

    Why did they stop at one nested acronym? Why not shorten it even further to "F - short for the so-called FREAK attack - short for Factoring attack on RSA-EXPORT Keys", and while we're at it shorten "Android smartphones, iPhones, and Macs running Apple's OSX operating system" to "A's"?

    I sure hope there are patches coming soon; wouldn't want anyone to inadvertently get F'd in the A's!

  21. And this, kids, is why you configure your servers by Opportunist · · Score: 3, Insightful

    Because clients are run by idiots. Sorry, but it's true.

    Clients are run by people who look at the funny acronyms and you can watch their eyes glaze over. If they know anything about it, they will know that there are keys and these keys depend on how big the number next to them is. That there are symmetric and asymmetric keys and that 512bit can be a LOT if it's symmetric and insignificantly little if it's asymmetric is already something you won't be able to teach them.

    So configure your servers, people. Configure them to ONLY accept sensible ciphers. Yes, that means that people with Internet Explorer 5 might not be able to use your page. Then inform them to fucking get a browser that was made in this millennium! These people are a security risk and bluntly, if you want to do business with them, you do not want to do business with me.

    Or at least I don't want to do business with you!

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  22. Re:Is there any way to block the use of old cipher by Reemi · · Score: 3, Informative

    I extensively make use of this site for cypher selection:
    https://wiki.mozilla.org/Secur...

    There are 3 levels of configuration proposed which you can use as a starting base for your own selection. The EXPORT cyphers are explicitely marked as 'Mandatory discards'. Any serious website running with these cyphers should be fined for exposing their visitors.

  23. Which ones? by twocows · · Score: 1

    I didn't see it mentioned in the article or summary which ones are affected. All I saw is "including OpenSSL." How about an actual list of affected software? Or maybe I'm just blind and missed it, but I don't think so.

    1. Re:Which ones? by AHuxley · · Score: 1
      --
      Domestic spying is now "Benign Information Gathering"
  24. Re:And this, kids, is why you configure your serve by Anonymous Coward · · Score: 0

    These people are a security risk and bluntly, if you want to do business with them, you do not want to do business with me.

    Or at least I don't want to do business with you!

    Yes, I'd want to do business with them, because they're the majority. If you don't want to do business with me because of that, then so be it. They win, you lose.

  25. So many affected countries by Anonymous Coward · · Score: 0

    Check out the breakdown of the affected countries.

    https://infogr.am/https_sites_that_support_rsa_export_suites

  26. Re:Is there any way to block the use of old cipher by X0563511 · · Score: 1

    You could theoretically do some packet inspection on the handshake and send a spoofed RST if you see something during the exchange you don't like.

    I've only ever dug into the certificate exchange portion of the handshake. I'm assuming the cipher negotiation is also in the clear.

    --
    For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
  27. Re:Arstechnica post fake Apple/android security al by Anonymous Coward · · Score: 0

    I'm AC so I can't mod your comment +5 Funny but I thought that was pretty good.

  28. Re:And this, kids, is why you configure your serve by Anonymous Coward · · Score: 0

    Then you're part of the problem.

    If vendors didn't pander to people running IE 5 then they would sack the fuck up and call their nephew to spend 5 minutes installing Teamviewer and Google Chrome.

    People who refuse to run modern shit on their hardware may be the majority, but only because assholes are willing to bend over backwards selling them "lazy" as a commodity.

  29. Re:Is there any way to block the use of old cipher by petermgreen · · Score: 2

    The SSL implementation is NOT part of the kernel.

    --
    note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
  30. Re:Is there any way to block the use of old cipher by petermgreen · · Score: 1

    Just configuring openssl is not enough. Theres at least THREE different SSL libraries in common use on linux and the chances are you have applications using all of them.

    --
    note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
  31. Re:The real problem... by Eosi · · Score: 1

    Says the AC who is too Chicken to post under his name. Seems that its people like him that are the real problem. Just sayin

  32. Re: Is there any way to block the use of old ciphe by chill · · Score: 1

    I was thinking server side, for the web server. But yes, you need to ensure every service you provide that uses TLS is properly configured.

    I'm not sure how much this would impact something like SMTP-S or IMAPS, since the connection duration on those types of service is so short.

    The big target is going to be web servers.

    --
    Learning HOW to think is more important than learning WHAT to think.
  33. Re:And this, kids, is why you configure your serve by Anonymous Coward · · Score: 0

    Internet Explorer 5 has not had a sizeable market share since 2002.

  34. Re:And this, kids, is why you configure your serve by jafiwam · · Score: 1

    Then you're part of the problem.

    If vendors didn't pander to people running IE 5 then they would sack the fuck up and call their nephew to spend 5 minutes installing Teamviewer and Google Chrome.

    People who refuse to run modern shit on their hardware may be the majority, but only because assholes are willing to bend over backwards selling them "lazy" as a commodity.

    Not sure what the GP is going on about.

    In my observations, retiring Windows XP drastically reduced the number of issues from "my stuff doesn't work, it's new, I bought it 10 years ago, why not?" complaints.

    There was a small cadre of folks re-installing XP on new machines (I did it too) because there wasn't a reason not to. After Nosebleed and Hearbeep (or whatever) happened last year I shut off old ciphers on all my stuff. And know what? NOBODY NOTICED. I get an occasional hit from China or other shitholes I don't care about trying it, and they often come along with other probes so it's not real traffic.

    So the point is, GP isn't correct when he's talking about his "majority," there is no such group. They're gone. The idea that there is a technically adept person running old shit because it still works, who also doesn't know it's risky, and also can't afford to upgrade to new shit is a Venn diagram with three unconnected circles on it.

    Go ahead and run what you want as a hobby if you get fulfillment from it. If your hobby puts you at risk, or can't be used somewhere, tough shit.

  35. Is this really an issue? by thegarbz · · Score: 1

    It's a downgrade attack that uses ancient old ciphers. Can we assume that any site that is vulnerable to FREAK is also vulnerable to other downgrade attacks and generally is likely to use old and insecure ciphers?

    I mean if you score an A on ssllabs tests which already penalise you for weak ciphers it shouldn't be an issue right?

  36. LibreSSL FTW by Anonymous Coward · · Score: 0

    It appears Theo de Raadt and crew have done it again -- proven their security audits and staunch view towards security does, indeed, work. Makes me glad to be an OpenBSD fan.

  37. Safari completely broken? by Anonymous Coward · · Score: 0

    I played the videos at the smacktls website, got no audio, so I don't know that there was audio, but I didn't get any audio.

    It seems that both tests on Safari that they presented, while not blocked by Safari - the user got warnings telling them there was a problem (potential fake website, https didn't show green, etc. - and XSS attacks). Seems that, unless there was further explanation that they installed some plugin/extension in Safari, that it is not completely broken. The warnings should keep users from continuing and just quit their browser at that point (ok, not the ID10T users, but...). So, unless further explanation was given over audio - it doesn't appear that Safari is completely toast.

    And that does bring up the question - should their be "training wheels" on the browser - NEVER allowing you to continue despite repeated warnings (one of the tests they showed came up with multiple warnings about XSS attacks on the page/login)? And if that's so, how do I remote into a Windows TS (ok, not a browser, but..). It seems the majority of Windows network admins don't know how to properly configure certificates (or simply don't or can't buy them), so they wind up either not signing or self-signing them, thus, anytime you access those systems, you get warnings about going into that particular Terminal Server. So, you either ignore it and do your job, or you don't and don't get work done.

  38. TLS by ledow · · Score: 1

    Sigh.

    So, as I understand it, the current situation is:

    - We can't allow use of RC4 because it's weakened significantly.
    - If we disallow RC4, we open ourselves up to BEAST in practical terms.
    - We need to move towards PFS and TLS 1.2 but the major libraries don't support it in major stable versions and/or we break an awful lot of the world's clients in doing so.
    - A lot of the chain certificates out there are still using only SHA1 which makes them weak.
    - And now we have to start worrying about clients that allow downgrade attacks on the connection.
    - We can't use OpenSSL at the moment because all the interesting new features (TLS 1.2, etc.) are only in Beta.
    - We can't use LibreSSL at the moment because it isn't available in many mainstream distros.

    Seems to me like we really need a massive revamp of security here and ditching old clients entirely.

    Almost every site on the Qualsys Labs tests rates B at best now because of the current situation (from which they recognise there is no practical escape even though it should probably rank them all lower): https://www.ssllabs.com/ssltes...

    I think it's time we just ditched everything and provide a way for browser security to be pulled out of the browsers entirely and made independently upgradeable, so you can browse a modern TLS 1.2 site with a browser that's a few weeks old.

    1. Re:TLS by thegarbz · · Score: 1

      It's not as bad as you think it is.

      -RC4 is weak, but the BEAST attack is mostly resolved on clients, and SSLLabs doesn't even penalize you for it anymore.
      -TLS1.2 and lack of PFS only really breaks IE at this point, and not the latest version either. In many cases you can sleep at night. Not implementing PFS still doesn't open you up to the major attacks on SSL that are presently out there and will allow IE to work.
      -Chain certificate issues are administration problems, and there's no reason not to re-issue your certificates with a stronger signature right now. It doesn't affect clients.
      -Not entirely sure about FREAK but from my understanding is the downgrade attack drops you back to export only ciphers which really should be restricted for use anyway. I don't think a default installation of Apache / OpenSSL will make you vulnerable to this downgrade attack as I hope the weak ciphers are rejected. I'm still digging up more info about it.
      -OpenSSL supports TLS1.2 just fine and has for a while now.
      -LibreSSL isn't available in mainstream distros true, but I would caution against jumping on the bandwagon until the code has been properly re-factored tested and shown to be reliable. The old, never buy version 1.0 of a product rule applies here.

      If you abandon older versions of IE you can get an A+ rating on SSLLabs and support all other major browsers. Also again based on my limited understanding that you can specify a cipher order so just because you support IE doesn't mean you don't get PFS and TLS1.2 with a browser that supports it. That only affects clients that connect in an obsolete way. Some of those clients have other internet breaking features like the inability to support virtual hosts with SSL. The only other problem then is a downgrade attack, and even then you can only downgrade to a certain point and if the server doesn't accept vulnerable ciphers then even with the attack you're not in too bad of a shape.

      This is just my understanding of the issues. Please correct me if any of this is wrong, I'm by no means an expert on this.

  39. Re:And this, kids, is why you configure your serve by Anubis+IV · · Score: 1

    Users who are stuck using browsers that are incapable of applying more up-to-date ciphers are nowhere close to the majority. They're over an order of magnitude away from being the majority, in fact.

  40. FREAK Attack tool by Anonymous Coward · · Score: 0

    You can use this tool to check your webserver: http://www.freakattacktest.tk

  41. Couple questions... apk by Anonymous Coward · · Score: 0

    "A) You look like a crazy spammer with your insane formatting, massive hyperbole, and numerous comments that seem to be frothing at the mouth. It's no wonder Palant stopped responding to you." - by Anubis IV (1279820) on Wednesday March 04, 2015 @11:42AM (#49180959)

    BS: Palant HAD to run http://ask.slashdot.org/commen... since AdBlock doesn't do a FRACTION of what hosts can and for FAR LESS resources consumed... period/fact!

    ---

    "I know that reading my single sentence is asking a lot of you, but you might be advised to read it a bit more carefully next time before you make multiple comments, each of which has dozens of lines of inapplicable text that look to have been written by a madman." - by Anubis IV (1279820) on Wednesday March 04, 2015 @11:42AM (#49180959)

    Madman? At least I can REMEMBER what I said that week or not, unlike yourself... lol!

    Also - What doesn't "apply" on the topic @ hand in what I wrote too, boy?? I am *NEVER* off topic on hosts (I only respond to "Almost ALL Ads Blocked" fanboys like you, trolling shill that YOU ARE, undoubtedly Mr. Palant himself, right??)

    ---

    * NOW: I know that in the PAST you have noted hosts (I keep you as a hosts user I know of in fact - but you said you noted them there... where????)

    APK

    P.S.=>

    "TL;DR: Read more carefully, use both, and stop posting tirades. We'll all be happier, you included." - by Anubis IV (1279820) on Wednesday March 04, 2015 @11:42AM (#49180959)

    Well, UNLESS you can PROVE what I asked for from YOU above, by showing us, that you indeed noted hosts in that article or even that week? You're FULL OF IT & can "EAT YOUR WORDS", boy - I didn't see it, & looked over your post history... apk

    1. Re:Couple questions... apk by Anubis+IV · · Score: 1

      For others joining, apk is referring back to this single-sentence post of mine and the ensuing thread.

      Anyway, I have some time to kill and karma to burn.

      AdBlock doesn't do a FRACTION of what hosts can and for FAR LESS resources consumed... period/fact!

      I agree entirely that extensions are far less efficient than hosts. I'm inclined to disagree that the extensions do less hosts, but it's not a point worth arguing for me. What's more important is that, as I already said in response to you, this isn't an either/or. Use both, since each of them does stuff better than the other. Hosts can't do everything that ad-blocking extensions can, and ad-blocking extensions can't do everything that hosts can. Simple as that.

      At least I can REMEMBER what I said that week or not, unlike yourself... lol!

      I remember what I said. I'm unclear both why you'd suggest I can't or why it's in any way relevant.

      What doesn't "apply" on the topic @ hand in what I wrote too, boy?? I am *NEVER* off topic on hosts (I only respond to "Almost ALL Ads Blocked" fanboys like you

      You do realize that you're entirely off-topic right now, don't you?

      The reason you were off-topic with your original attack on AdBlock is because I wasn't defending AdBlock to begin with. On the contrary, the original post I made was advocating that people abandon AdBlock. You apparently saw "AdBlock" and assumed I was a fanboy, despite my explicitly encouraging people to ditch it.

      As for your request that I provide proof, I'm not sure what it is that you're referring to. I'm more than happy to "eat my words" when I'm wrong, since it means that I will know better in the future, but I never suggested I had proof of anything related to hosts. The only evidence I noted at any time was the evidence that uBlock is more efficient than AdBlock. That's it.

      Hosts is significantly more efficient than either of those extensions, of course, but it works best when it's paired with them, rather than against them.

  42. You're avoiding the question by Anonymous Coward · · Score: 0

    " I use both uBlock and a custom hosts file, and I'd encourage others to do so as well" - by Anubis IV (1279820) on Thursday February 19, 2015 @01:37PM (#49089289)

    See subject: Where'd you mention HOSTS specifically in that thread before that WAS MY QUESTION. I looked at your post history that week & you never did!

      Answer it - after all, you DID say this too there also:

    "TL;DR: Read more carefully, use both, and stop posting tirades. We'll all be happier, you included." - by Anubis IV (1279820) on Thursday February 19, 2015 @01:37PM (#49089289)

    Don't give me orders, boy... @ least NOT UNTIL YOU HAVE DONE BETTER than myself, & by that? See next below also as you MAY LEARN SOMETHING that proves your statements wholly incorrect:

    "since each handles various things better or differently than the other. For instance, hosts are more efficient and can prevent the ad server from ever getting my request, which addons sometimes can't do, but it can't remove the element from the page where the ad would have showed, whereas an addon can." - by Anubis IV (1279820) on Thursday February 19, 2015 @01:37PM (#49089289)

    I don't NEED an addon for element blocking: Opera 12.17 does that via rightclicks on pages, & has for like, forever!

    "Hosts files are also a bit more hands-on in keeping up-to-date than addons" - by Anubis IV (1279820) on Thursday February 19, 2015 @01:37PM (#49089289)

    YOU had better learn to read more closely, per YOUR ORDERS YOU TOSSED MY WAY ABOVE QUOTED - hosts are a SNAP to maintain & keep up to date courtesy of "yours truly" -> http://start64.com/index.php?o...

    (Now, since you're such a 'great critic' & you like to give orders? HAVE YOU DONE BETTER YOURSELF?? Hell no!)

    APK

    P.S.=> Bottom-Line (after you told me to read closer quoted above especially): Don't EVER tell us you noted hosts before that quote above of yours in that very thread, when you NEVER once did... apk

    1. Re:You're avoiding the question by Anubis+IV · · Score: 1

      (Sorry for the delay...was out of town this weekend and just got back)

      Oh, is that all you were asking? The simple answer is that I didn't say I used hosts prior to my first response to you. My original post was constrained to the topic of ad-blocking extensions, hence why I didn't mention the fact that I also use hosts to complement the extension(s), and hosts hadn't come up otherwise at any time recently, so you're correct about it not being in my recent comment history. I don't know why you think that I was claiming I had noted it recently, nor do I understand why whether I did or didn't would even matter.

      ...

      If Opera can do that out of the box, great! That said, I was pointing out that hosts itself can't do it, and Opera doesn't disprove that. Moreover, not everyone uses Opera, and those of us on other browsers still need to have a way to take advantage of the feature since hosts can't do it for us...hence our use of extensions to complement hosts. But if Opera fills that need for you in place of using an extension, by all means, go for it and enjoy the lack of extensions. I have no issues with your approach, though it isn't one that I will follow, since I'm not a fan of Opera for my own use.

      ...

      And thanks for the link! Let me know when it works on other OSes, since I don't use Windows at home. In the meantime, I will point out that, from what I can tell, it appears that it's still a bit more work than the all-in-one-fully-automated packages that modern ad-blocking extensions offer, since it requires some configuration and setup that will put off quite a few people, whereas many of these extensions don't require any sort of setup or configuration. Even so, apps like yours help to make hosts MUCH more manageable and MUCH more approachable for people who aren't used to mucking around in their computer's innards, so kudos to you for putting that together.

  43. Don't tell me "read more closely" then by Anonymous Coward · · Score: 0

    "Oh, is that all you were asking? The simple answer is that I didn't say I used hosts prior to my first response to you" - by Anubis IV (1279820) on Sunday March 08, 2015 @11:44PM (#49212639)

    See subject: You screwed up & never said you use hosts once there (prior to your saying you did AFTER you gave me guff telling me to "read more closely")...

    ---

    "I was pointing out that hosts itself can't do it" - by Anubis IV (1279820) on Sunday March 08, 2015 @11:44PM (#49212639)

    Hosts unquestionably DO MORE THAN ANY SINGLE BROWSER ADDON OUT THERE, & for less resources consumed by FAR (vs. Almost ALL Ads Blocked).

    More work? Hey - AT LEAST HOSTS DO WORK fully, unlike "almost ALL ads Blocked"...

    Yes, Opera 12.17 is excellent & does click on content (like ads or images for example) & let's me selectively BLOCK portions of sites.

    ---

    " apps like yours help to make hosts MUCH more manageable and MUCH more approachable for people who aren't used to mucking around in their computer's innards, so kudos to you for putting that together." - by Anubis IV (1279820) on Sunday March 08, 2015 @11:44PM (#49212639)

    It works. Better than ANY OTHER like it in fact (being pure 64-bit & also offering speedup of websurfing via hardcoded favorite sites @ the TOP of hosts so they resolve fast,faster than remote DNS, & in doing so, also securing users vs. DNS security issues by avoiding it where they spend MOST OF THEIR TIME ONLINE too...)

    APK

    P.S.=> Hosts work on most every platform & porting my app? Cake. Delphi does MacOS X, iOS, Android, + yes, Windows - a Linux port's cake too: Lazarus IDE + FreePascal are an ALMOST EXACT CLONE of Delphi & would be easy too - only diff between Windows is mounted device vs. drive letters (easy) & the code for *NIX sockets vs. WinSock2 is abstracted away for it already (so sockets diff are no issue either)... apk

    1. Re:Don't tell me "read more closely" then by Anubis+IV · · Score: 1

      See subject: You screwed up & never said you use hosts once there (prior to your saying you did AFTER you gave me guff telling me to "read more closely")...

      I think I understand the confusion now. The "read more closely" comment wasn't related to my using hosts. As you correctly said, you couldn't possibly know that I used hosts until I said so, and I said I used it in the same comment where I said "read more closely". The "read more closely" comment was in relation to the fact that you posted an attack on AdBlock in response to my initial post, presumably because you thought my initial post was a defense of AdBlock (which it wasn't), which I believed was the result of your not having read my initial post carefully enough. That's all.

      Hosts unquestionably DO MORE THAN ANY SINGLE BROWSER ADDON OUT THERE, & for less resources consumed by FAR

      We can both agree that hosts is very good at doing what it is designed to do and that it's more efficient at doing what it's designed to do than extensions are. Hosts is a purpose-built tool at a lower level that does a specific set of tasks extremely well. Extensions and add-ons are tools that do a huge variety of tasks reasonably well. Arguing that hosts is both more efficient AND more capable is like arguing that a traditional GPU is both more efficient AND more capable than a traditional CPU, even though they are intended for different purposes.

      It works. Better than ANY OTHER like it in fact [...]

      That's great. I just wish your app worked for me. I'm sure I could port it if I wanted to, since I have network programming experience at much larger scales than this (my grad research involved distributed, massive-scale web crawlers), but it's not an important enough issue for me to set aside the time necessary. I'm happy to just intermittently update my custom hosts file manually until a fully-automated solution arrives that works for me.

  44. Argue with this then by Anonymous Coward · · Score: 0

    "Arguing that hosts is both more efficient AND more capable is like arguing that a traditional GPU is both more efficient AND more capable than a traditional CPU, even though they are intended for different purposes." - by Anubis IV (1279820) on Monday March 09, 2015 @03:55PM (#49218133)

    Hosts DO more, & what they do the SAME, hosts do more efficiently.

    * There's NO arguing it - it's not even an argument, due to what's in my 'p.s.' below...

    (Hosts work anywhere pretty much, on ANY webbound application... adblock doesn't).

    APK

    P.S.=> ALL documented to what I stated here (from reputable sources & valid tests) http://ask.slashdot.org/commen... as well as a list of what hosts DO, above & beyond "Almost ALL Ads Blocked" (crippled by default since it sold out to GOOGLE), more efficiently... apk

    1. Re:Argue with this then by Anubis+IV · · Score: 1

      If we're constraining your assertion to ad-blocking addons, then I'd be willing to concede that they may indeed be both lesser-featured and less efficient (I'm not willing to do the research necessary to ascertain whether it's true or not). Even so, I still contend that some have features that hosts lacks, and that as a result they remain useful as a complement to hosts.

      If we're talking about addons in general, as your assertion was originally phrased, then no, hosts does not do more than any addon. Off the top of my head, I'd say it's fairly safe to assume that Greasemonkey, for instance, does far more than hosts ever will. But that's an unrelated discussion, or at least I hope it is.

  45. Hosts do more than adblock for less by Anonymous Coward · · Score: 0

    Hosts do more than adblock for less resources per http://ask.slashdot.org/commen...

    * Prove that wrong? THEN, you have a VALID point...

    (Can't be done... too many almost all ads blocked fans have tried & failed here for years on that account).

    APK

    P.S.=> Plus, Yes - I've already DONE the research (it's in those links in fact from valid reputable enough sources) & so I simply designed the BEST TOOL THERE IS for hosts file mgt. (since there's little question of what's in the list in that link above being correct)... apk

    1. Re:Hosts do more than adblock for less by Anubis+IV · · Score: 1

      I'm simply asserting that hosts and ad-blocking addons do different things and that they're best used together, rather than to the exclusion of the other, but that where their features do overlap, I readily agree that hosts is more efficient. I'm fairly certain that's already a valid stance, and if we can't agree on it, I'm not going to argue it further.

      Likewise, I'm not going to argue about which of them "does more". I don't know how you'd objectively quantify that, nor do I see why that matters at all, nor do I have any interest in arguing it with anyone. Yes, you have a list of a lot of things that hosts can do. I'm sure someone else has a nice list of everything that ad-blocking addons can do. And I'm equally sure that we can pad both lists by splitting up items and rewording them a bit. Seeing which list has more items in it is a pointless and subjective exercise, since I'm only interested in using a subset of those features anyway, and don't care in the least which of them "does more".

      All I care about as a user is if the addons can do something I want to do that hosts can't do (they can) and if hosts can do something I want to do that the addons can't do (it can). As such, I'll continue using both.

  46. No argument possible: Hosts do more 4 less by Anonymous Coward · · Score: 0

    See subject & this link + the list in it http://ask.slashdot.org/commen...

    "I'm not going to argue about which of them "does more". I don't know how you'd objectively quantify that, nor do I see why that matters at all, nor do I have any interest in arguing it with anyone." - by Anubis IV (1279820) on Wednesday March 11, 2015 @03:12PM (#49236003)

    You can't argue in favor of "Almost ALL Ads Blocked" vs. that list of things hosts do, for less, that adblock can't.

    "Yes, you have a list of a lot of things that hosts can do. " - by Anubis IV (1279820) on Wednesday March 11, 2015 @03:12PM (#49236003)

    It's SO nice NOBODY can prove it wrong... TRUTH is like that.

    "I'm sure someone else has a nice list of everything that ad-blocking addons can do." - by Anubis IV (1279820) on Wednesday March 11, 2015 @03:12PM (#49236003)

    Where is it then? I'll tear it in 1/2 vs. hosts too... or, as I did with specific content blocking, how Opera (or other browsers) can do that MINUS "Almost ALL Ads Blocked" as I did earlier in this exchange.

    "And I'm equally sure that we can pad both lists by splitting up items and rewording them a bit. Seeing which list has more items in it is a pointless and subjective exercise, since I'm only interested in using a subset of those features anyway, and don't care in the least which of them "does more"." - by Anubis IV (1279820) on Wednesday March 11, 2015 @03:12PM (#49236003)

    Go for it - I'll rip it, and you, in 1/2 - easily.

    APK

    P.S.=> How you could be SO obstinant & run from facts I put out, I will NEVER know, or understand... apk

    1. Re:No argument possible: Hosts do more 4 less by Anubis+IV · · Score: 1

      You can't argue in favor of "Almost ALL Ads Blocked" [...]

      Let me stop you right there.

      You keep repeating that quote over and over again as if it's something I said, yet never once did I say or argue that. Stop putting words in my mouth. If you'll cease treating me as an antagonist and will stop constructing straw men arguments for a moment, you'll find that we already agree on almost everything and have been from the start.

      It's SO nice NOBODY can prove it wrong... TRUTH is like that.

      I agree. Your list is valid. I never argued otherwise. That's also why I never directly addressed it, since there's no point in addressing topics that we agree on.

      Where is it then?

      Darned if I know, and darned if I care. As I said before and as I'll explain in more detail below, those sorts of lists are useless for the discussion we're having.

      I'll tear it in 1/2 vs. hosts too... or, as I did with specific content blocking, how Opera (or other browsers) can do that

      You pointed out an alternative solution that works in one browser. That's great for some people, not all. Having alternatives is certainly a good thing, but it's not the complete solution you make it out to be. You've failed to provide me with an alternative that provides those features in Chrome, Firefox, Internet Explorer, or Safari, all of which are more widely used than Opera. As such, add

      How you could be SO obstinant & run from facts I put out, I will NEVER know, or understand

      I'm obstinate about refusing to accept absolute assertions regarding subjective matters. I don't disagree with you, but I don't agree either, because I think there is no basis for agreement or disagreement.

      My current problem is that you're saying, "X does more" and are using that itemized list of features as the basis for your assertion. The thing is, I bet we could double the length of your list without too much difficulty if we got a bit more specific about some of the things it does. And it'd all still be perfectly valid and accurate. Wouldn't you agree?

      Likewise, any list that exists for the other side could be increased or decreased in a similarly arbitrary manner without making it untrue. As a result, arguing that "X does more than Y" on the basis of such lists is a meaningless argument, since we could easily consolidate or split up items in those lists to inflate/deflate the number of items present, while all of it is still accurate and true.

      Until you can provide an objective basis for asserting that one "does more" than the other, I can neither agree nor disagree with that assertion. THAT'S what I'm being obstinate about.

  47. I had to put YOUR WORDS in your mouth by Anonymous Coward · · Score: 0

    See subject: You couldn't even remember NOT noting hosts in our exchange originally!

    * Hosts work on ANY browser (or app) on a PC operating system - not just "some" as you said...

    APK

    P.S.=> In the end, you're NOT denying hosts are more efficient & do more than "Almost ALL Ads Blocked" by FAR, + for less resources consumed - that's ALL I really needed to see or hear... apk

    1. Re:I had to put YOUR WORDS in your mouth by Anubis+IV · · Score: 1

      I had to put YOUR WORDS in your mouth

      Except that they weren't my words. I can speak for myself.

      You couldn't even remember NOT noting hosts in our exchange originally!

      Sure I could...once I understood that that's what you were asking, but it took two or three posts before I even understood what you wanted. Once I did, I realized I had miscommunicated earlier, so I clarified what I had said.

      Hosts work on ANY browser (or app) on a PC operating system - not just "some" as you said...

      I did not say it only worked on some. In my very first response I even listed hosts' ability to work across browsers and services as one of its major benefits.

      My only claim regarding browser-specific functionality was related to features that hosts doesn't even try to do, such as the specific content blocking that Opera supports. I said that addons are useful to people who want those features, since hosts don't provide them, and not everyone uses a browser that has them built in.

      [...] you're NOT denying hosts are more efficient & do more than "Almost ALL Ads Blocked" by FAR, + for less resources consumed - that's ALL I really needed to see or hear... apk

      I neither deny it nor accept it. To me, it's like saying that a car does more than a computer...maybe it's true, but how would we objectively measure that? A list of features is a subjective metric.

      I will agree with you, however, just as I have from my very first response, that where their features overlap, hosts is more efficient.

      P.S. I don't know if I've ever been asked to defend so many things I didn't say. Just to make it clear where I have been standing all along...
      1) Where their features overlap, hosts is more efficient than addons.

      2) Hosts does things addons don't do, and addons do things hosts doesn't do.

      3) Hosts works across all browsers and services, addons don't.

      4) Addons are easier to maintain and use than hosts.

      1-3 are readily apparent facts, so I'm confused why we haven't reached agreement, and #4 is a matter of opinion.

  48. No, these ARE your words quoted by Anonymous Coward · · Score: 0

    "a modified hosts file when I'm at home in Safari on my Mac, I haven't seen an ad in months, let alone one following me around." - by Anubis IV (1279820) on Thursday December 06, @06:28PM (#42210239)

    See subject & that quote of yours (you omitted noting that as I said you did) - so again, I just HAD to put YOUR WORDS in YOUR MOUTH, this round, to clarify that YES you use hosts files (& yes, you omitted stating that in our original "debate" where YOU RESORTED TO CALLING ME 'crazy' etc. (which is a sign of losing a valid debate on YOUR part...)).

    APK

    P.S.=> I've seen all I needed to from you & have it quoted for future reference IF it's ever needed again in my favorites/bookmarks... it's all I wanted anyways (with name tossers like yourself) so you can "eat your words" IF you EVER try it again... apk

    1. Re:No, these ARE your words quoted by Anubis+IV · · Score: 1

      To me, this was never a debate at all, since we're on the same side: people should be using hosts, and tools like the one you make are beneficial in helping people to use hosts more easily.

      I'm just sad you haven't realized we're on the same side yet and have continued resorting to antagonistic approaches towards me. I mean, what would I "EVER try" again: telling people to ditch AdBlock because it's inferior to alternatives? Because that's what started this whole discussion.

  49. Antagonistic? That's YOU pal, not I... apk by Anonymous Coward · · Score: 0

    "A) You look like a crazy spammer with your insane formatting, massive hyperbole, and numerous comments that seem to be frothing at the mouth" - by Anubis IV (1279820) on Wednesday March 04, 2015 @11:42AM (#49180959)

    What's that you said now vs. YOU tossing names @ me?

    APK

    P.S.=> You're unbelievable... apk

    1. Re:Antagonistic? That's YOU pal, not I... apk by Anubis+IV · · Score: 1

      That wasn't intended to be antagonistic towards you, though I can certainly see how it would be taken that way since it was expressed rather rudely of me, so I do apologize for that. What I was trying to convey is that you're undermining your own arguments with your style of posting. It was your way of expressing your idea that I took issue with, not you.

      When I saw your original response to me, I read a few of the bolded phrases and came to the incorrect determination that it was a spam post from one of the numerous spammers Slashdot has. It wasn't until your second post that I realized you were a normal person who was actually trying to make a point. That's why I said it looked like it was from a crazy spammer. I continue to stand by what I said (though not the way I said it), since I still believe that your formatting is undercutting the message you're seeking to convey to others.

      The reason why I referred to you as being antagonistic towards me is because of things like your continued use of "boy" as a derisive term aimed my way, as well as a case or two where you've chosen to engage in baseless ad hominem attacks against me.

  50. When you can prove my points wrong? by Anonymous Coward · · Score: 0

    Then you've made a valid point vs. tossing names my way vs. http://ask.slashdot.org/commen...

    * I've been VERY successful in HOW I do things in the past - hence WHY I don't have to be somebody's "wageslave" anymore & run my own successful business for a decade++ now in fact - can YOU say the same?

    (So, don't *TRY* to tell me "how it's done", until YOU HAVE DONE BETTER yourself. Then, perhaps I'd listen but not until then).

    As far as calling you 'boy'?

    There's NO QUESTION that You began the name tossing, not I (calling me "crazy spammer" etc.) so when in ROME, I do as the romans do & speak in a language they understand since you have NOT shown me otherwise from YOUR end.

    APK

    P.S.=> That "spam" bullshit is just that - PURE bullshit (& that is all you've got apparently)... apk

    1. Re:When you can prove my points wrong? by Anubis+IV · · Score: 1

      I didn't call you a crazy spammer. I said you looked like one with the way you formatted your post, and I stand by that claim. You're welcome to disagree or disregard what I've said.

      As for your points, I already said I agreed with all of them...

      It's SO nice NOBODY can prove it wrong... TRUTH is like that.

      I agree. Your list is valid. I never argued otherwise. That's also why I never directly addressed it, since there's no point in addressing topics that we agree on.

      And I really did dismiss your original post as a spam post, just based on the way it was presented. It really wasn't until your second post that I realized you weren't a spammer. Whether you believe that or not is entirely your choice, but it is the truth. Take it into account or don't. It's just an anecdote, after all.