Slashdot Mirror


User: LordLimecat

LordLimecat's activity in the archive.

Stories
0
Comments
10,208
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 10,208

  1. Re:What is this IE you speak of? on Microsoft To Stop Enabling 'Do Not Track' By Default · · Score: 3, Informative

    Firefox doesnt look so hot when you look at the number of CVEs, particularly remote code execution:

    http://www.cvedetails.com/prod...
    http://www.cvedetails.com/vers...

    It beats IE 11 by a small margin in RCEs, but loses in total vulns. Its really not that great of a browser, lacking common security mechanisms like plugin isolation.

  2. Re:Quick, get damage control out here on China's Foreign Ministry: China Did Not Attack Github, We Are the Major Victims · · Score: 1

    Comparing the US's propaganda to China's is truly absurd. We have free media here (albeit with their own agenda); China's papers are all in the pocket of the CPC.

    Find me a national publication in China that is critical of the ruling party. I can find hundreds here in the US that openly criticize Obama, Congress, and SCOTUS.

  3. Re:Typical of USA regime to blame China on China's Foreign Ministry: China Did Not Attack Github, We Are the Major Victims · · Score: 1

    Well, we all know how much power DC has over Baidu and the border routers in China.

  4. Re:DDoS solved in IPv6 on China's Foreign Ministry: China Did Not Attack Github, We Are the Major Victims · · Score: 1

    If you dont understand networking, its probably best not to wax snarky.

    For the record; layer 3/4 typically doesnt handle authentication.

  5. Quick, get damage control out here on China's Foreign Ministry: China Did Not Attack Github, We Are the Major Victims · · Score: 3, Interesting

    One wonders if we'll be seeing the return of the 50 Cent Party in this thread.

  6. Re:not the problem on Micron and Intel Announce 3D NAND Flash Co-Development To Push SSDs Past 10TB · · Score: 1

    He could have gone with the Samsung "Pro" drives, which have held out to 2PB of data writes before croaking; they at least pretend to not be consumer drives.

  7. Re:not the problem on Micron and Intel Announce 3D NAND Flash Co-Development To Push SSDs Past 10TB · · Score: 1

    I might suggest that you need to not be expecting a consumer SSD to hold up to an enterprise workload.

  8. Re:And it does... what, exactly? on Google Quietly Launches Data Saver Extension For Chrome · · Score: 1, Funny

    Would it kill you to read the article? Its not even that long.

  9. Re:Proxy! WTF? on Google Quietly Launches Data Saver Extension For Chrome · · Score: 1

    ALL of my browser activity through Google?

    1) No, SSL and incognito not included.
    2) It does what just about every other "data saver" of this type have always done (BES compression, Opera data saver, I believe safari has an example as well)

  10. Re:not the problem on Micron and Intel Announce 3D NAND Flash Co-Development To Push SSDs Past 10TB · · Score: 1

    What are you doing that's writing ~100-200TB / year?

  11. Re:not the problem on Micron and Intel Announce 3D NAND Flash Co-Development To Push SSDs Past 10TB · · Score: 1

    For a do-nothing pc you should be using any of the hundred sub-$60 128GB ssds.

  12. Re:Linux? OS X? Chrome OS? Nope. OpenBSD! on NJ School District Hit With Ransomware-For-Bitcoins Scheme · · Score: 1

    SELinux stops all memory exploit mechanisms? Thats AMAZING.

  13. Re:Linux? OS X? Chrome OS? Nope. OpenBSD! on NJ School District Hit With Ransomware-For-Bitcoins Scheme · · Score: 1

    TIL OpenBSD has built in anti-trojan tools, and the ability to secure browsers from their own memory corruption holes! WOW!

  14. Re:I wouldn't mind the NSA so much if... on NJ School District Hit With Ransomware-For-Bitcoins Scheme · · Score: 1

    The NSA is a spy agency. You want the FBI, who actually does go after these things.

  15. Re:it could have been an accident on Germanwings Plane Crash Was No Accident · · Score: 2

    I think his point is that there could be alternate reasons why the door would not open besides the position of the switch. Malfunctions, whether mechanical or electrical, CAN happen and HAVE happened.

    They are rare, but he is correctly noting that we're speculating here.

  16. Re:Check their work or check the summary? on No, It's Not Always Quicker To Do Things In Memory · · Score: 1

    String += String

    Im in a 200 level java class. We're just learning inheritance. I could have told you why thats a bad way to do things.

    Do people not study what arrays are and why its expensive to continually append to them anymore?

    Maybe these folks need to go back to basics.

  17. Re:goddamnit!!! on Hack Air-Gapped Computers Using Heat · · Score: 2

    And you've provided no evidence or analysis why you're supposed mitigations are an insurmountable defense; at best they're only a stop-gap.

    In THEORY breaking most encryption is just guessing the right 2048-bit code. At best, increasing the length from 1024 to 2048 is just a stopgap.

    In reality, some attacks are so esoteric and hard to pull off (famous example: hard drive magnetic domain remnant detection) that they are not a real-world threat. MAYBE they could adapt this, but it already requires
    A) a machine connected to the internet that is compromised (!)
    B) an AIR-GAPPED, high-security machine directly adjacent to it (!!!)
    C) That that air-gapped machine be compromised as well (!!!!!)
    D) Sensors in both machines sensitive enough to detect incredibly minor fluctuations in temperature (given that a steady stream of air will be flowing through)

    The proper security procedure is to analyze the chance of the risk, the annualized loss expectancy, etc, and then come up with mitigations. Ok, let me give this a shot.
    1) DONT GET YOUR AIRGAPPED MACHINE INFECTED
    2) probably dont stick it directly adjacent to non-airgapped machines

  18. Re:Or... on Dueling Home Automation Systems at SXSW (Video) · · Score: -1, Offtopic

    Neither does soapboxing on slashdot.

  19. Re:Check their work or check the summary? on No, It's Not Always Quicker To Do Things In Memory · · Score: 4, Interesting

    Tl; DR:

    They used python and java. Sort of hard to develop a meaningful thesis on general programming when you're that far up the abstraction stack. Who knows, maybe python and Java suck at memory management (GASP).

  20. Re:As a recent buyer of a mid-2014 MBP on Apple Doubles MacBook Pro R/W Performance · · Score: 1

    Your existing m.2 SSD is on a slot with 1GB (8gb) of bandwidth. I really dont think you're going to be maxing that out with any non-enterprise SSD, so you're probably OK-- and even if you somehow did, I seriously doubt you would notice.

  21. Re:goddamnit!!! on Hack Air-Gapped Computers Using Heat · · Score: 3, Insightful

    So I fail to care about which term is used, it is a security breach and one of the worst kind

    Except it will only work in the most esoteric scenarios with laboratory conditions, sure. 2 PCs, with side-vent cooling and no cold aisle, and a distance of 15 inches?

    Somehow I dont think this will threaten air-gapped secure networks. Those are going to have steady cold air coming in the front, and exhausting out the back; if theyre dumping significant heat through the side of the cases you're doing it wrong.

  22. Re:If the browser authors spent more time... on Every Browser Hacked At Pwn2own 2015, HP Pays Out $557,500 In Awards · · Score: 1

    Showing a static page involves rendering what amounts to a specialized form of code. Even browsers without javascript like Lynx have code execution CVEs-- and thats a browser that isnt even being fuzzed that hard.

  23. Re:Build it yourself -- from source on Every Browser Hacked At Pwn2own 2015, HP Pays Out $557,500 In Awards · · Score: 1

    Its not NIX enough, according to the posts I've read, it doesnt count.

  24. Re:Build it yourself -- from source on Every Browser Hacked At Pwn2own 2015, HP Pays Out $557,500 In Awards · · Score: 2

    I love seeing history repeat itself.

    Years ago, it was OSX that was impenetrable. "Find us an active exploit or virus", they said, "and dont give us any of that market share nonsense". All the while the clues were there, with OSX getting exploited in seconds at Pwn2Own when actual cash and computer swag was on the line.

    Here again, we have an OS with a minute market share boasting about its impenetrability and lack of exploits. I might propose that a great deal of the lack of exploits is the lack of any real incentive to go after such a tiny group of OSes which are invariably set up by fairly skilled IT persons.

    Develop a BSD distro with a desktop environment and a modern web browser, and set it out for a million end users to use with a $50k cash prize for the first exploit, and you'll be paying out in a day, tops.

    The amount of arrogance in some of these "My *Nix is best" threads is staggering. There is NOT code out there that is significantly more complex than Hello World that is bug free.

  25. Re:If the browser authors spent more time... on Every Browser Hacked At Pwn2own 2015, HP Pays Out $557,500 In Awards · · Score: 2

    Your post displays an astonishing level of both confidence and ignorance. Find me a piece of software half as complex as a browser (which has the unenviable task of running arbitrary code from untrusted sources in a secure manner) that doesnt have any CVEs and I'd happily retract my statement.