Slashdot Mirror


User: ls671

ls671's activity in the archive.

Stories
0
Comments
2,940
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 2,940

  1. Re:Nothing: It's full of holes on White House Proposal Urges All Federal Websites To Adopt HTTPS · · Score: 1

    Indeed, from a server admin perspective, my server is safer if it only runs http. https/TLS is meant to prevent user that have access to the traffic to sniff it which is a different topic. I am not sure if the president is aware of this but hey, I hear plenty of things like that every day.

  2. Re:Rules for some, or everyone? on White House Proposal Urges All Federal Websites To Adopt HTTPS · · Score: 1

    I already installed STARTTLS on Mrs. Clinton mail server last week.

  3. Re: NMAP on Ask Slashdot - Breaking Into Penetration Testing At 30 · · Score: 1

    You need a WAF these days. I use mod_security. It can save your arse from zero days sometimes.

  4. Re:NMAP on Ask Slashdot - Breaking Into Penetration Testing At 30 · · Score: 1

    this scales much better:
    $IPTABLES -I INPUT -m set --match-set ipbl src -j DROP
    $IPTABLES -I FORWARD -m set --match-set ipbl src -j DROP
    $IPTABLES -I FORWARD -m set --match-set ipbl dst -j DROP
    $IPTABLES -I OUTPUT -m set --match-set ipbl dst -j DROP

    add an ip to ipbl set:
    ipset add ipbl ${IP}

    don't forget to block all ipv6 traffic if you don't need ipv6:
    ${IP6TABLES} -I FORWARD -i eth0 -j DROP
    ${IP6TABLES} -I INPUT -i eth0 -j DROP
    ${IP6TABLES} -I FORWARD -o eth0 -j DROP
    ${IP6TABLES} -I OUTPUT -o eth0 -j DROP

  5. Re:I want a picture on Al-Shabaab Video Threat Means Heightened Security at Mall of America · · Score: 2

    Can they mount Linux partitions on these mount points?

  6. Thank you on An Evidence-Based Approach To Online Dating · · Score: 1, Funny

    Thank you, Thank you.

    I do not know how to thank you enough for this advice, I am going to make use of it from now on.

  7. have attached more than 300 feet of cable... on ISS Crew Install Cables For 2017 Arrival of Commercial Capsules · · Score: 1

    Yeah, we need cable TV in every suite for those high paying commercial customers.

  8. Re:3D print the gun, on Crystal Pattern Matching Recovers Obliterated Serial Numbers From Metal · · Score: 2

    There is a legislation coming up forcing all 3d printers to incorporate a serial number in all 3d printed guns.

  9. Re:I think you miss my point on Also Hackable: Drive-Through Car Washes · · Score: 1

    I didn't know caves had basements, I am still trying to imagine it.

  10. Re:Better Than His Usual Slop on Jamie Oliver's Website Serving Malware · · Score: 1

    That's a good one! ;-)

    I am a French chef from France and it dates back to around 1500; we used to say that all an English chef could cook was oxtail and the like. Of course, this is full of BS but hey, this constitute sane competition.

     

  11. Re:Ain't surprised on Jamie Oliver's Website Serving Malware · · Score: 1

    yes but it is much easier to to it with mod_security, as mentioned in my OP, for my users and to make sure we ain't serving any.

  12. Ain't surprised on Jamie Oliver's Website Serving Malware · · Score: 1

    This doesn't surprise me. I run modsecurity WAF and iptables, yes I know but iptables does the job for now, with custom rules and logging policies and it is amazing to see how many so called legitimate sites have been owned.

    I used to contact site admins and participate in exchanges of offending IPs but I gave up a long time ago to run my own countermeasure system.

    Boy we went a long way since the beginning with regards to that.

  13. Re:I didn't see any mention of efficiency. on Linux Controls a Gasoline Engine With Machine Learning · · Score: 3, Informative

    Here the goal is to make the engine spend as much fuel as possible, hence the term "chaotic combustion". The system can maintain the engine in a "chaotic combustion" state in real time ;-)

  14. Re: Slowing DOWN????? on Extra Leap Second To Be Added To Clocks On June 30 · · Score: 1

    1) be ready when your watch shows 00:00:00
    2) wait until it shows 00:00:01
    3) press button
    4) now watch shows 00:00:00

    elapsed time: 1 second

    did you ever own a watch?

  15. Re:Slowing DOWN????? on Extra Leap Second To Be Added To Clocks On June 30 · · Score: 1

    > So, what do you intend to do during that extra second added to that day? Well, you may want to fix your systems.

    Nah, I am just going to going to set my watch during that extra second.

  16. Re:Thats why I keep my money in petro-dollars. on Hackers Steal $5M In Bitcoin During Bitstamp Exchange Attack · · Score: 1

    I prefer to always carry a safe file in my pockets. I allowed me to open a few.

    https://en.wikipedia.org/wiki/...

  17. Re:huh? on Why We're Not Going To See Sub-orbital Airliners · · Score: 2

    I don't think he is. The Concorde had a weakness that was discovered only in one of the last flight.

    https://en.wikipedia.org/wiki/...

  18. Re:fail on Why We're Not Going To See Sub-orbital Airliners · · Score: 1

    Right, just attach the suborbital planes in pair with a rope to some space elevator like device and have one take off as the other land. Problem solved.

  19. Re:Summary without technobabble on Bots Scanning GitHub To Steal Amazon EC2 Keys · · Score: 1

    >Thirdly, "bought" 30 million certs?

    Oh and yes, that's why we were both laughing our hearts out and calling shenanigan at the same time. As I wrote in my OP, I would have been glad to generate those certs for them for 10,000$ instead of the 30,000,000$ they spent. But hey, a buck a piece for certs is a great deal, isn't it?

    The usb key solution was suggested as well but the conclusion was that dumb users would lose their usb keys and that it would become too costly to manage.

    In the end, we seem to be doomed unless we educate people.

  20. Re:Summary without technobabble on Bots Scanning GitHub To Steal Amazon EC2 Keys · · Score: 1

    I agree it is currently. It is funny although what a little education could do but most of the times, educated people are less easy to profit from. Therefore, marketing guys will rarely suggest educating people as a solution.

  21. Re:Summary without technobabble on Bots Scanning GitHub To Steal Amazon EC2 Keys · · Score: 1
  22. Re:Summary without technobabble on Bots Scanning GitHub To Steal Amazon EC2 Keys · · Score: 1

    In the end, education and instant knowledge is needed.

  23. Re:Summary without technobabble on Bots Scanning GitHub To Steal Amazon EC2 Keys · · Score: 2

    I entirely agree but for some, namely the ones who still use symmetric keys, this has become an old school thought.

    In Canada, the government bought 30 millions certificates for all its citizens in oder to authenticate for government on line services for a buck a piece. Total: 30,000,000$

    I would have been glad to provide it to them for 10,000$ and guess what? All privaye keys were kept centrally ;-) Us, old school guys just couldn't believe it.

    The big thinkers/marketing guys decided that it was just to complicated for citizens to manage and keep their secret key in a secure location.

  24. Re:something new. on What Language Will the World Speak In 2115? · · Score: 1

    Very nice thoughts. Just to let you know, English ain't my mother tongue.

  25. Re:Chinglish on What Language Will the World Speak In 2115? · · Score: 1

    It would still be English, it is how it evolved.