Slashdot Mirror


User: Tony+Hoyle

Tony+Hoyle's activity in the archive.

Stories
0
Comments
5,728
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 5,728

  1. Re:The sky is not falling. on CCC Create a Rogue CA Certificate · · Score: 1

    "Therefore, the only certificates that are problems are ones where someone has already launched this attack. We know it's happened once, but that list is probably pretty small. And, there's a good shot that the bad guys haven't done it at all."

    He's wrong, and has completely failed to understand the significance of this. He seems to think that it requires the CA to sign these certificates or something.

    As long as there are *any* MD5 CA certificates in the browser then the bad guys can duplicate it and generate valid certificates for *any site on the internet* - including your bank. Man in the middle attacks just got a hell of a lot easier. Phishing attacks just got a hell of a lot easier.

    Vulnerable CAs include Thawte and RSA, which means this is pretty damned big.

  2. Re:CA's using MD5 on CCC Create a Rogue CA Certificate · · Score: 1

    Find these in the browser and delete them.

    *No* certificate issued by these providers is secure. If your bank uses them, then tough.. your bank has a problem and they should have bought their certificate from a competent provider.

  3. Re:its only the CA's that use MD5 so the question on CCC Create a Rogue CA Certificate · · Score: 1

    Any CA that still uses MD5 should be removed from the list of trusted CAs in all browsers, with immediate effect.

  4. Re:Don't most ISPs already have tiered service pla on BBC's iPlayer Chief Pushes Tiered Charging For ISPs · · Score: 1

    Because they're horribly oversubscribed. Because they have no decent support. Because they have the audacity to actually charge *per month* for IP addresses so to replicate my current 16 IPs would jack the price up to £42 per month (making them simultaneously the most expensive and cheapest ISP.. a neat trick).

    And your £18 a month contract is a minimum 12 months. Costly when you want to change, or even just move house. Many, like myself, won't even consider such a contract.

    To get decent, reliable broadband costs money.. Or you can go cheap and get an ISP that slows down to 1/10th of their maximum speed at what they laughingly call 'off-peak'.

  5. Re:Don't most ISPs already have tiered service pla on BBC's iPlayer Chief Pushes Tiered Charging For ISPs · · Score: 1

    BT are rolling out ADSL2+ slowly and it's already in major cities. These things take time.

    If you think virgin media is actually fiber I've got a bridge to sell you.

  6. Re:BitTorrent & p2p? on BBC's iPlayer Chief Pushes Tiered Charging For ISPs · · Score: 1

    They now use a flash based client that does all the above on multiple platforms, and have no dependency on Windows.

  7. Re:I already pay my tv licence on BBC's iPlayer Chief Pushes Tiered Charging For ISPs · · Score: 1

    You do need a license for live broadcasts... the watch live pages (eg. http://www.bbc.co.uk/bbctwo/watchlive/) state clearly "Don't forget - to watch TV online as it's being broadcast, you still need a TV Licence.".

  8. Re:USB != serial on DIY USB Servo-Guided Water Gun · · Score: 1

    Yeah at no point do they say USB - which would be a more complex project (although I guess USB serial controllers are fairly cheap these days).

  9. Re:Is this legal? on Amateurs Are Trying Genetic Engineering At Home · · Score: 1

    Limiting access to any virus or bacteria that's in the environment is rather hard. The results of a fuckup could be rather fatal...

  10. Re:That's good, but. . . on Notebook Sales Outpace Desktop Sales · · Score: 0, Redundant

    Laptop optical drives are pretty standard and can be swapped out easily enough.

  11. Re:New security process on Microsoft Extends XP To May 2009 For OEMs · · Score: 1

    2008 is nice because it's done right.. nothing is running and you get a bare OS which runs fast and does what you want it to do. If you want dekstop eye candy or (shudder) multiple 'indexing' services scanning your hard drive constantly you can add those if you want to, but it's not there by default.

    I'd say 2008 is a even better than 2003 as a dev environment.

    Vista, however, I just can't get on with. I ran it for several months and it self destructed so badly it needed reinstalling 3 time during that time... if I never see it again it'll be too soon.

    So it's not the core of Vista that's the issue (same kernel), it's the rest of the crap.

  12. ipv6 on Security Flaws In Aussie Net Filter Exposed · · Score: 4, Interesting

    I bet the filter isn't ipv6 capable... I just can't see the lawmakers being that tech savvy.

    That could be just the boost the protocol needs, in Australia at least.

  13. Re:without any humans ever having been involved on Using Speed Cameras To Send Tickets To Your Enemies · · Score: 1

    In the UK at least the camera is the start of an automated process an no human is involved in the ticket generation (or indeed the entire process if you just admit guilt and send them the money).

    We have a bizarre legal situation with the cameras..

    1. The camera is pretty much always taken as absolute proof
    2. It's illegal to refuse to divulge who was driving, or if it was you, admit it.
    3. The information in (2) is a legal admission of guilt.

    So you have a legal (and potentially criminal) process where it's illegal not to admit guilt.

  14. Re:I'd ignore the Europeans too on NIST Announces Round 1 Candidates For SHA-3 Competition · · Score: 5, Insightful

    What is the point if they only got one submission for the Hash contest? Doesn't that make it the automatic winner?

    Not if it isn't shown to be secure. If needs to be tested first.. it may be they have no winner.

  15. Re:I doubt all newspapers are... on Are Newspapers Doomed? · · Score: 2, Informative

    http://www.wired.com/techbiz/media/news/2003/11/61165

    And that's 2003... it's got worse since.

  16. Re:...but then reality sets in on Scientists Hack Cellphone To Detect Diseases · · Score: 1

    Quite aside from the fact that in 90% of hospitals it's not permitted to use mobile phones anyway.

  17. Re:Stupid idea on New Contest Will Seek the Best "I'm Linux" Video · · Score: 4, Interesting

    I don't know.. "Life without walls"?

    If there are no walls, who needs Windows?

    Great catchphrase...

  18. Re:Script on New Contest Will Seek the Best "I'm Linux" Video · · Score: 1

    For the linux guy it would be hey presto, a box of seeds and a baby chicken appear, and he has to get farming.

  19. Re:Well... on Diskeeper Accused of Scientology Indoctrination · · Score: 3, Funny

    Llamas?

  20. Re:European prices on EA Is Now Officially On Steam, Spore Loses SecuROM · · Score: 1

    By conflating the issues it also omits the fact that spore is only released on the US store, as the press release makes absolutely clear.

    European users are still forced to use securerom.

  21. ..and switch wifi off (which is even more power hungry, btw.). 3G is only more power hungry in weak areas (since it'll try to find the weak 3g antenna rather than the more powerful 2g one).. in an area of good reception it makes no difference.

    But cellphone antennas are already pretty power efficient compared to driving the display, backlight etc... and let's not even get started on the GPS. You aren't going to get multiples of battery life just from this invention.

  22. Re:Come on, it's british on Simulations May Explain Loss of Beagle 2 Mars Probe · · Score: 2, Interesting

    Name a one thing british ever made right.

    Australia.

  23. Re:Common Sense on Study Says Cosmic Rays Do Not Explain Global Warming · · Score: 3, Informative

    Melting glaciers won't cause a sea level rise unless they're sitting on land.. think archimedes.

  24. Re:Aha! on Safari and Chrome: Tied For the Worst Password Manager · · Score: 2, Funny

    Confess! Or I'll shine this Maglite in your face again!

  25. Re:I don't get it on Vista To XP Upgrade Triples In Price, Now $150 · · Score: 4, Interesting

    Anything that requires a control panel - they need a rewrite because of UAC (control panel applets can't elevate).
    Anything that uses the system registry. Microsoft 'helpfully' redirect it. Ditto Program Files.
    Several APIs no longer behave as they were documented in XP. This is a real git as it introduces hard to find bugs.

    The one thing about porting projects is you quickly realize how buggy vista is.. You could't pay me to install it again (it's banned on the network anyway because it did something stupid to the routers).