Slashdot Mirror


User: yuhong

yuhong's activity in the archive.

Stories
0
Comments
1,888
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,888

  1. Re:Excess ports on Via Launches a New Mini-ITX System · · Score: 1

    I see no reason it wouldn't be native, as all that legacy stuff is rolled into a single Super I/O chip connected to the LPC bus that is software compatible with the ISA bus and has been for a decade.

  2. Re:Ah on Inside the Duqu Worm's Source Code · · Score: 2

    From the original blog article:
    "Due to privacy reasons and protection of the identity of the victim, we cannot share the source .DOC file with other parties."

  3. It just failed by 52-46 on Senate Set To Vote On the Repeal of Net Neutrality · · Score: 1, Informative
  4. Re:Sucks to be you! on How Do I Get Back a Passion For Programming? · · Score: 1

    Yep, fear-based top-down command and control is another way to describe it.

  5. Re:NT4 was such an abomination... on MS Traces Duqu Zero-Day To Font Parsing In Win32k · · Score: 1

    BTW, GDI is no longer single threaded in Win7.

  6. Re:brb banging head against wall on MS Traces Duqu Zero-Day To Font Parsing In Win32k · · Score: 1
  7. Re:brb banging head against wall on MS Traces Duqu Zero-Day To Font Parsing In Win32k · · Score: 1

    Note here that MSDN has completely get rid of compatibility info for any Windows versions before Win2000. Look in the old Platform SDK for WinServer 2003 SP1 from 2005 for the true compatiblity info.

  8. Re:brb banging head against wall on MS Traces Duqu Zero-Day To Font Parsing In Win32k · · Score: 1

    And in particular it took until IE4 in 1997 before MS's own web browser supported embedded fonts.

  9. Re:How to deactivate custom fonts in a browser? on MS Traces Duqu Zero-Day To Font Parsing In Win32k · · Score: 1

    I think recent versions of Firefox uses the OTS font sanitizer which tries to prevent attacks.

  10. Re:brb banging head against wall on MS Traces Duqu Zero-Day To Font Parsing In Win32k · · Score: 1

    Well, when they designed ActiveX, they did realize that there would be security issues, which is why they created code signing and "safe for scripting" and "safe for initialization" etc... One of the problems however was that back in 1996 buffer overflows etc was not well-known security threats, which is now one of the biggest reasons why nowadays MS is adding kill bits in security updates.

  11. Re:Nearly as insane as executing code in images on MS Traces Duqu Zero-Day To Font Parsing In Win32k · · Score: 1

    Yea, partly because of the need to support old XP display drivers. The good news is support for that is eliminated in Windows 8, which may even allow the DWM to be part of the new CSRSS.

  12. Re:Nearly as insane as executing code in images on MS Traces Duqu Zero-Day To Font Parsing In Win32k · · Score: 1

    I once suggested to Larry Osterman of MS that this be done, now that there is a *separate CSRSS for each session* and has been since NT4 TSE. If one of them crashes, only the session is lost.

  13. Re:Seems Too Soon on Ubuntu 12.04 LTS Won't Fit On a CD · · Score: 1

    Someone already suggest for example to trim Mono.

  14. Re:Who generates 512-bit RSA keys these days? on Microsoft, Mozilla and Google Ban Malaysian Intermediate CA · · Score: 2
    Except it doesn't, as the bad cert was also "missing certificate extensions", which means it can be used for any purpose after the private key is factored out, and indeed from one of the articles:

    "I have been contacted by Entrust who say that two of the certificates issued by the Malaysian DigiCert Sdn. Bhd. were used to sign malware used in a spear phishing attack against another Asian certificate authority," reports Sophos' Chester Wisniewski.

  15. Re:Who generates 512-bit RSA keys these days? on Microsoft, Mozilla and Google Ban Malaysian Intermediate CA · · Score: 1

    This is probably why they are revoking trust for the *entire CA*.

  16. Re:Bust on HP Slate 2: Brilliant or Bust? · · Score: 1

    The funny thing is that Best Buy in fact is already doing something like this:
    http://arstechnica.com/gadgets/news/2011/11/the-hp-touchpad-has-reappeared.ars?comments=1

  17. Re:HOW the HELL on Duqu Installer Exploits Windows Kernel Zero Day · · Score: 1

    Yea, during year 2006, Office in fact was a big target of zero-day attacks, forcing MS to released Office 2003 SP3 in Sept 2007, and also MOICE around the same time which converts files to OOXML in a sandbox before opening it. Later MS introduced Office File Protection in Office 2010 and later backported this to 2003/2007 which validates Office binary formats before opening it.

  18. Re:Fallacy on Microsoft Tried To Buy Netscape: Suppose They Had? · · Score: 1

    I think the tipping point here was the intro of Netscape 2 in early 1996 which introduced frames, JS, etc which together was complex to implement.

  19. Re:not happy to ditch for windows 7 on 10 Years of Windows XP · · Score: 1
  20. Re:no one got fired buying intel on Smarter Thread Scheduling Improves AMD Bulldozer Performance · · Score: 1

    I am talking about the quad socket market only. I know that the dual socket market will be a different story because of Sandy Bridge-EP already.

  21. Re:Fallacy on Microsoft Tried To Buy Netscape: Suppose They Had? · · Score: 2

    It began in the days when HTML 3.0 was the standard. Here is a thread on this from when IE1 was soon going to release. Unfortunately, Netscape had a monopoly on web browsers, leading to 3.0's failure which in turn led to 3.2.

  22. Re:Fallacy on Microsoft Tried To Buy Netscape: Suppose They Had? · · Score: 2

    The funny thing is that HTML 3.2's tags came from IE1 in the first place, but excluded those tags not implemented in Netscape 2.0, like &ltFONT FACE=. In fact, the standard itself says it reflected the de facto HTML as of "early 1996".

  23. Re:They should spin off any quality they have left on HP Keeping Their PC Business · · Score: 1

    Personally I would suggest cleaning up the mess by Intel selling the Itanium division back to HP.

  24. Re:no one got fired buying intel on Smarter Thread Scheduling Improves AMD Bulldozer Performance · · Score: 1

    And AMD has also be trotting the death of the 4P tax on their blogs in the Opteron 6100 era, and there is no indication they will going to change that with Opteron 6200 anyway.

  25. Re:no one got fired buying intel on Smarter Thread Scheduling Improves AMD Bulldozer Performance · · Score: 2

    And slower will be I think solved with Interlagos, and Intel will have only Westmere-EX (Xeon E7) to compete since Sandy Bridge-EP is not even released yet. Now compare the already-released pricing of Opteron 6200 CPUs with Intel's current Xeon 7500/E7 pricing, and guess what will happen.