Slashdot Mirror


User: ewanm89

ewanm89's activity in the archive.

Stories
0
Comments
914
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 914

  1. Re:Marlinspike's approach on Are Some CAs Too Big To Fail? · · Score: 1

    EFF's SSL Observatory already has spiders crawling and collecting SSL certs.

  2. Re:Marlinspike's approach on Are Some CAs Too Big To Fail? · · Score: 1

    No, if the ISP is doing MITM, they won't be MITM all those 50 too. So all you have to do is check those cert fingerprints to check the first connect for them.

  3. Re:same story as always with computer security... on Are Some CAs Too Big To Fail? · · Score: 1

    Or they don't even care to listen. Oh, and one CA is compromised then all HTTPS sites are compromised, not just those the CA is payed to sign, I'll let you ponder that one.

  4. Re:Confused... on Are Some CAs Too Big To Fail? · · Score: 1

    convergence/perspectives use multiple servers around the internet called notaries, when you connect to a site you also connect to these notaries and ask what they see for the site (this is in perspectives mode, notaries can do other things in convergence), now if they don't match with what you got then either you or they are being MITM attacked and therefore the connection is dropped with an error (in convergence the user can control just how much of a match is needed, 1, majority, consensus). The idea is that the attacker would have to MITM you and the notary (depending on match mode, 1 or more of them) at the same time. Not easy especially with multiple notaries placed around the world.

  5. Re:Alternative improvement idea on Are Some CAs Too Big To Fail? · · Score: 1

    Multiple path is done over SSL with certs to match against pinned in the browser. This is more a trust on first use, as is an exception for self signed. The only possible compromise time with this is that first connection to the notary (server for doing validation) or the self signed server.

  6. Already has happened on Are Some CAs Too Big To Fail? · · Score: 1

    I point out that Comodo are compromised twice recently, and not revoked by any browser. As Moxie pointed out in his blackhat talk.

  7. Re:Question on Pakistan Bans Encryption · · Score: 1

    yes, you could construct a pad to get any message you want out of it easy enough.

  8. Re:Question on Pakistan Bans Encryption · · Score: 1

    yes and no, no predictably different it will be within the variance of the random number generator, XOR stream encryption with a truly random pad is provably secure and this is one of the reasons.

  9. Re:Question on Pakistan Bans Encryption · · Score: 1

    no, that only works with a pseudo random number generator. Not a true random number generator.

  10. Re:Question on Pakistan Bans Encryption · · Score: 1

    please distinguish a truly random one time truly pad (XOR stream encryption) with just the data from the random number generator alone.

  11. Re:Security concerns on Pakistan Bans Encryption · · Score: 1

    well, I hope the Pakistan military isn't connected to the internet then. On another note I actually hope it is and I'm no-longer having any dealings in Pakistan if I can avoid it.

  12. Re:I've been pondering this since DX1 on Deus Ex Eyeborg Documentary Shows Today's Cyborgs · · Score: 1

    Yes, I never said they didn't. But like iron man, he would not even be alive without part of it. Not just a blind paraplegic.

  13. Re:I've been pondering this since DX1 on Deus Ex Eyeborg Documentary Shows Today's Cyborgs · · Score: 1

    Without the life support functions of his augmentations, he wouldn't have woken up at all.

  14. Re:they're afraid of OnLive? on GameStop Offers $50 Certificate For Coupon Fiasco · · Score: 1

    well, technically, they are making a client to do just that, in practice they are making it for android tablets specifically along with ipad client. Add to that the UK release next month and I guess they are already quite busy.

  15. Re:Any lawyers reading? on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    It was promised on Square Enix' press release on their website.

  16. Re:The legal ramifications, in a different article on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    no, but it does say it clearly on some other advertising material like the press release for the games release on the square enix website.

  17. Re:Can it even still be considered new? on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    Adding a bonus item as some kind of promotion is fine, although most shops would just tape it to the box, or have the checkout staff hand it over when putting it through. No need to open the packaging, here they are removing an item. Best to ban selling of items in a different condition to how it comes from the manufacturer then one wouldn't need separate laws for things like if selling food or medicine and I opened the boxes and added say cyanide.

  18. Re:Does anyone else smell that? That smell... on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    Or the disc itself

  19. Re:Does anyone else smell that? That smell... on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    Square Enix should have printed the code on the manuals!

  20. Re:So, Gamestop has agreed to EULA? on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    That's because the courts (IIRC in several separate countries) banned the by opening the shrink wrap you agree to the EULA you can't have read yet quite a few years ago. Some of the early ones were that bad. It's also why one has phrases like "except where permitted by local laws" dotted throughout such text.

  21. Re:Any lawyers reading? on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    Well, not necessarily, pro-bono or cheap for someone like the EFF on a nice high profile case is a great way to increase ones own profile.

  22. The real funny part on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    The PC Retail version is activated against a steam account just as if one went and bought half-life 2, counterstrike source, portal, cod: mw2... in a shop. So, all they've done is limited the use of one of 2 digital distribution methods included. This also begs the question though, why don't they give onlive codes to those of us who bought it on steam directly, or steam codes to those that bought it on onlive directly?

  23. Re:You've got to be kidding... on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    Well the square enix news release here: http://release.square-enix.com/na/2011/08/23_02.html mentions the free onlive coupons and I quote "Purchasers of the PC retail packaged version of DEUS EX: HUMAN REVOLUTION will be entitled to a free OnLive digital copy of the game..."

  24. Re:You've got to be kidding... on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    I think that's against the EULA, they are contracted to sell licenses of the game as specified by the publisher.

  25. Re:First! on GameStop Opening Deus Ex Boxes, Removing Free Game Coupon · · Score: 1

    OnLive allows one to stream and play a game running on there servers. This way you don't need high powered hardware and can play on virtually any device (as long s there is a client).