Slashdot Mirror


User: BlueFall

BlueFall's activity in the archive.

Stories
0
Comments
79
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 79

  1. Re:Here I was thinking about boobies on Gates Says No to Implants · · Score: 1

    Manssiere!

  2. Re:Essential links.... on What to Expect from Linux 2.6.12 · · Score: 1

    NB: Note that this long and tedious post deals with IBM's Trusted technology only; I'm afraid I know very little about Microsoft's Palladium, which by all accounts was even worse :)

    Just as a nitpick, this is not IBM's technology, but that of TCPA/TCG. IBM is one of the first to include this technology in their systems and thus probably wants to make sure that the actual capabilities are well-known.

    BTW at some point, Palladium (aka NGSCB), was proposed to include a secure path to the monitor and keyboard (and possibly other io devices). This feature could be actually very useful in preventing local snooping.

  3. Two completely different issues on Morphing Code to Prevent Reverse Engineering? · · Score: 4, Insightful

    It sounds to me like the author of the article is talking about two completely different issues. The first is code decompilation and static obfuscation. The second is about runtime obfuscation.

    In theory, if you don't run the binary you have, you don't need to worry about it modifying itself. The same techniques that work on obfuscated byte code now should work on the the binary. Now if you were trying to reverse engineer a program by running it and tracing it, that's where PSCP seems like it would help.

  4. Easier to DOS on "Port Knocking" For Added Security · · Score: 1

    This introduces several additional points of failure in every connection. For example, suppose you had a 5 port knock before connecting to your final real port. If any one of these fails to reach the end point, you're denied service. Thus, if I have the ability to stop some of your packets from coming through, I only have to stop one packet per connection attempt -- a new low bandwidth DOS.

    Even if there's nobody malicious in between you and the server, you need to make sure that 5 packets get through in sequence. That's not terribly easy.

  5. Re:Run around on Digital Camera Image Verification · · Score: 1

    Seems like the biggest problem with the camera is that it is basically a digital signing oracle for whoever holds it.

  6. How does this relate to 1.7a? on Mozilla 1.6 Released · · Score: 1

    I downloaded source the other day and it claims to be version 1.7a. Does anyone know how this relates to this release?

  7. Re:Shoehorning CVS to work with good dev practices on Pragmatic Version Control Using CVS · · Score: 2, Interesting

    Does Subversion really handle the repeated merge problem now? I have heard that Arch does do this and I don't really know about bitkeeper. I'd say that this is my personal biggest beef with CVS (aside from its ridiculously inefficient storage scheme).

    Last time I checked, repeated merge was a post-1.0 issue, but for me, it's the only reason not to move to Subversion.

  8. Re:Similar techniques are in use already on Javascrypt · · Score: 2, Interesting
    That's cool to know, but I don't think that this is true:
    And in the event that someone compromises a secure server, your password wouldn't be available to the attacker, only the hash.

    If you look at the code on the site, they have a 'challenge' value that is appended to the hash of the password, so to calculate the challenge response you need both the 'challenge value' (a.k.a. a nonce) and your password. The server needs the same thing. I think that this same technique is used in APOP.

    The only way that they wouldn't need some shared secret is if you used some sort of asymmetric signing protocol, but then key distribution is a problem...

  9. Better performance numbers? on GBDE-GEOM Based Disk Encryption on FreeBSD · · Score: 2, Interesting

    There are some nice ideas and good thinking here, but does anyone have a link to more interesting performance numbers? I'm curious how well this would work on a workload that was both intense and non-sequential.

  10. Viewtiful Joe on GameCube Production to Halt · · Score: 1

    I don't have a GameCube, but I was really tempted to get one when I saw the Viewtiful Joe teasers. Maybe that'll help sales. Or better yet for me, maybe Capcom will release the game on Playstation2...

  11. Case in point... on Should You Hire a Hacker? · · Score: 3, Interesting

    The government hires ex-criminals to fight crime with great success -- just look at She-Spies! ;-)

  12. Misleading headline on Cryptographers Find Fault With Palladium · · Score: 4, Insightful

    The headline of this story is misleading. Some people disagree philosophically with Palladium's goals, not its technical merits. It just happens that these people are famous cryptographers. At the moment, the technical details seem sparse, so we'll just have to wait until they are released (if ever) to see if the goals that are mentioned are actually met.

  13. False advertising? on Blackboard Campus IDs: Security Thru Cease & Desist · · Score: 2, Insightful

    IANAL, but could someone sue the company for false advertising? If they say their product is safe and secure, but you feel it isn't and you are a user, then shouldn't your be able to bring a case against them? At that point, you have to present evidence for your claim and (assuming the court records aren't sealed) the exploit becomes public record.

  14. Why waste the heat? on Sandia's Laptop Heatpipes Closer To Market · · Score: 2, Funny

    Why can't the heat be used to recharge the battery and give it a longer run time? Seems like this just throws away energy...

  15. Trust on Bootable Business Card Distro Needs Testing · · Score: 3, Insightful

    I'm not terribly sure I'd trust an application given to me on a business card by someone I don't know, much less something that boots.

  16. Re:That title-- on Speex Joins Xiph To Bring Free VOIP To The Masses · · Score: 2

    Reminds me of "Bart vs. Australia"...

    "Yahoo Serious Festival"

    Lisa: I know those words, but that sign makes no sense.

  17. Stealing, eh? on MIT Steals Comic Book Character · · Score: 2

    Is it just me, or does the character look like half of all the manga/anime characters?

  18. Re:Dear Senator on FEC Permits Anonymous SMS Spam · · Score: 2

    How would you know that it was really Senator Jacka$$? They don't even have to put their name on the message now.

    OTOH, it probably is Senator Jacka$$. It's always Senator Jacka$$. Blast him and his SMS spam!

  19. Obligatory on Broadband To Hit The South Pole · · Score: 0, Redundant

    1. Run a broadband connection to the South Pole.

    2. ????

    3. Profit!

  20. Re:Hmm, not terribly impressed... on New DOOM III Shots · · Score: 3, Insightful

    Nope, you're not alone. I can't understand why so many people go nuts over screenshots like these. As long as I see lines and corners where I should see curves, I won't be impressed.

    I'm not saying the games aren't fun, but for me, the graphics don't seem to be any monumental improvement, even over a few years ago.

    My 2 cents.

  21. My Dinner with Andre! on IMAX Develops Movie Transfer Technology · · Score: 2

    My Dinner with Andre! It really deserves the big screen for all the action. Like when the waiter comes with the wine!

  22. World Trade on Talk To a European Patent Examiner · · Score: 5, Interesting

    Do you feel pressure from the US and other countries to approve software patents? I know many corporations will withhold business from countries that don't have "support" for this sort of thing, so is there a big national-level economic incentive in software patents?

  23. Useful subject on Teaching BattleBots in High School · · Score: 2, Funny

    And when the apocalypse comes, this will become even more practical!

  24. Why I use Linux on A Linux User Goes Back · · Score: 4, Insightful

    I use Linux (and various kinds of Unix) for the interface. I detest the mouse. Clicking all over the place is much too slow for my tastes. Clicking alternated with typing is even worse.

    Tab completion is one of my favorite interface inventions ever.

    Just my opinion.

  25. So many questions... on New Alloy Stronger Than Fe And Ti · · Score: 5, Informative

    There are so many questions being asked here about details... The company website has much more information than this article. Go to the source.