Slashdot Mirror


User: jehreg

jehreg's activity in the archive.

Stories
0
Comments
53
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 53

  1. Openswan project directly affected on What is Responsible Disclosure for Security Flaws? · · Score: 5, Interesting

    The Openswan project is directly affected by this this month. We were contacted by an agency and asked to sign a non-disclosure agreement, following which they would tell us of a possible vulnerability in our code. This non-disclosure would prevent us to release details of the vulnerability until such time as the rest of the "group" would be ready for it to be announced.

    In the case of an Open Source product, we cannot even do a "stealth" fix; we have to describe what each patch does when we commit it to CVS. That would make the vulnerability public and would be a no-no to this agency.

    In essence, the agency could decide which bug we could fix and which ones we could not.

    I see this as the equivalent to blackmail: Sign our non-disclosure and we will give you a possible vulnerability; don't sign it and you will look bad when the vulnerability is made public.

    I am a CISSP, and quite willing to hold on the patch until others can fix their code if the allowed time is reasonable, but the non-disclosure is broad and has no time limitations... So what the heck should we do ?

  2. Owl on OSS Web-based File Management? · · Score: 1

    Have a quick look at http://owl.sourceforge.net/ , it might be just what the doctor ordered.

  3. Re:Polish on Users as Innovators - Why Open Source Works · · Score: 2, Insightful

    Structured QC/QA team. That's what makes or breaks a FOSS project.

  4. Re:This is not a new record. on Epson's 12 Gram Flying Robot · · Score: 3, Funny

    Great, you just slashdotted a hamster...

  5. Re:It does matter... on Gentoo 2004.2 Released · · Score: 2, Informative
    I did the switch last night.

    • /etc/init.d/xfs stop
    • /etc/init.d/xdm stop
    • emerge unmerge xfree
    • emerge xorg-x11
    • cp /etc/X11/XFConfig-4 /etc/X11/xorg.conf
    • /etc/init.d/xfs start
    • /etc/init.d/xdm start

    And I run nvidia too; no need to remerge nvidia-kernel. I did remerge nvidia-glx, just in case, but you should not have to.

  6. Re:Quiet! on BayStar Cashes Out of SCO Stock · · Score: 1
    Actually no, shorting means that you borrow someone's stock and you sell it right away with the promise that you will eventually buy some stock and give the stock back to whoever lent his to you. Of course, if the company goes bankrupt, you never have to purchase the stock back...

    So, if everyone shorts that means a huge amount of selling, bringing the price down. If enough shorting happens and the stock is low enough, it becomes a self-fufilling prophecy.

  7. SHORT SCO!!! on BayStar Cashes Out of SCO Stock · · Score: 0

    Time to short SCOX. We are pretty sure this is near the end, so let's drive the price of the stock to the bottom. Call your brokers :-)

  8. Up 107 days... on Kernel Exploit Cause Of Debian Compromise · · Score: 5, Funny
    kc grub # uptime 17:21:06 up 107 days, 22:45, 1 user, load average: 0.35, 0.82, 0.47

    Great..... there goes my uptime.....

    If I have to reboot more than once per year, I'm switching to Windows.

  9. Re:What you can do about it on Congress Expands FBI Powers · · Score: 2, Funny

    v) If all else fails, vote with your feet. Canada is close by.

    As a Canuck speaking: "EX-cellent..."

  10. Bittorrent ?? on Superball! · · Score: 4, Insightful

    Special kudos to the first that makes a bittorrent available of the 117documentarypremium2.mov file.

  11. Re:VoIP DDoS on Free VoIP for Dartmouth Students · · Score: 2, Funny

    Wouldn't that be "IP over Voice", or IPoV ?

  12. Re:For Gentoo on New ssh Exploit in the Wild · · Score: 1
    Well, sure, 3 hours later....

    What was I supposed to do during those 3 hours? Wait? :-)
    Pat

  13. For Gentoo on New ssh Exploit in the Wild · · Score: 5, Insightful
    Just go to your net-misc/openssh directory:
    • cp openssh-3.6.1_p2.ebuild openssh-3.7_p1.ebuild
    • emerge --update openssh
    The emerge will fetch the file and complain that there is no digest.
    • ebuild openssh-3.7_p1.ebuild digest
    • emerge --update openssh
    Just tested it here, worked fine.
    Pat
  14. Re:BT link? on Myst Online Trailer · · Score: 3, Informative

    Yeah, but you need a gentle soul to be able to d/l it first and then create a BT seed for it. Publishers tend to not know about BitTorrent yet, so they typically don't use it.

  15. BT link? on Myst Online Trailer · · Score: 4, Interesting

    Any BitTorrent available, or is it already to late for even that?

  16. Re:Good idea on Windows Is 'Insecure By Design,' Says Washington Post · · Score: 1
    I already have a wall covered with silver AOL CDs ...

    You've been on Trading Spaces(tm) ??

  17. Re:no, EMACS causes CTS on Computers and Carpal Tunnel Syndrome Studied · · Score: 1
    (in next week's exciting episode: "Perl and your spermcount - the shocking truth")


    Awwww crap.

  18. Re:Old Hat on Airships Tested As Two-Way Telecom Beacons · · Score: 2
    That wind problem has intrigued me for the longest time....

    It makes no sense to me why they would not have a wind sensor and winch the balloon down as the wind gets stronger. Have a concrete holding area with no top, and winch the balloon into it. It won't get damaged or lost this way. As soon as the wind has died down to a reasonable level, release it back into the air.

  19. It's all about scale. on IAB Recommends Larger Web Advertising · · Score: 3, Funny

    Well, I recommend bigger fonts, larger web pages, and waaaaaaay higher resolution.... to compensate.

  20. Demonstrating the concept of 'annoying' on HOWTO: Annoy a Spammer · · Score: 5, Funny
    If they go to trial, have the defence lawyer ding a bell at random intervals during the whole process of the trial. At some point the judge will want to kill the lawyer, thereby demonstrating that the defendants (the slashdudes) have been rendered insane by the annoyance of receiving massive amounts of unsolicitated "dings".

    When the judge finally screams "Will you stop that ?!?", have the lawyer look the judge straight in the eyes and say calmly: "No."

    Ipso facto.

  21. Europa on FatWallet Strikes Back Using DMCA · · Score: 1

    Cool, I didn't realize we had a colony there...

  22. Isn't this a dup as well ? on Spam Archive opening FTP service December 4 · · Score: 1, Troll

    Is there so little happening in the news, or did we hit some bizarre wormhole, and we are now going back in time ?

    At this point, I think that in the last 2 days over 70% of the stories have been dups.

  23. Obligatory running gag... on Linux Chosen for IBM's New Supercomputer · · Score: 0, Redundant

    Wow! Imagine a Beow SMACK!

  24. Jeez, I'm 35 and learning... on Generation Wrecked · · Score: 2
    I've had an epiphany 2 months ago. I realized that the financial advise I had been given for the last 5 years, was basically ensuring me that I would retire poor.

    I am now learning like crazy.

    First thing I learned: Do not confuse your job with how you create your wealth.

    Check out my diary to see what I am changing in my life.

  25. How about Tape drives ? on 320GB Hard Drives announced · · Score: 2, Insightful
    This is getting ridiculous....

    How do you backup 320Gigs ??

    A cheap tape drive on Ebay use DDS-2 tapes; that's 4Gigs max. Am I supposed to purchase 100+ tapes if I want a full backup and 7 days of incrementals ?

    At $5 per tape, that's another $500+, plus the time it's gonna take to swap these puppies in the drive.

    "Just buy another drive and RAID them..." Yeah, right. I got a few RAID horror stories for ya. "Well, who cares, you aren't running productions-grade stuff at your house..." Well, 320 Gigs of data takes a *long* time to accumulate, even with rips and all. Losing that would take you a good amount of time and bandwidth to accumulate again.

    This is the case of one technology pushing itself out of usefullness.