Slashdot Mirror


User: SirNAOF

SirNAOF's activity in the archive.

Stories
0
Comments
79
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 79

  1. Change management gone wrong on Ask Slashdot: System Administrator Vs Change Advisory Board · · Score: 1

    This sounds like change management gone wrong.

    The idea of change management is to ensure that changes are tracked, but this sounds like bureaucratic crap. Setup WSUS so you can track what patches are applied where, and then talk to the CAB to approve monthly (or whatever schedule) patches en-masse. Otherwise you'll end up not patching, and that's an even worse result.

    I don't mind change management when it's done with some amount of sanity.

  2. Not an entirely new idea... on Verifying Passwords By the Way They're Typed · · Score: 3, Interesting

    I reviewed a company's offering a few years ago that was recording the relative timing between keystrokes when you entered a password. Any subsequent attempts had to match that relative pattern in order to be verified.

    It failed miserably.

    I had a demo with the company. They showed me a nice fake online banking login screen. They then told me the name and password and said "Go ahead and try to login." I did so. And it let me right in. The woman giving the demo couldn't believe it. I took a screenshot and sent it to her as verification. Sure enough, their system did not stop me from logging in.

    So she reset the password to something else, ran through a couple of calibration runs to make sure she could login, and then again gave me the password. I once again logged in immediately.

    Once more she changed the password, and again asked me to try it. I couldn't login. So I tried a few more times, and on the third try I was once again staring at fake bank accounts.

    I realized two things from this demo. First, its easily breakable by a human with comparable typing skills to the victim when the password is known. Second, the only thing this (particular product) could defeat was an automated system attempting to login. ...I don't think that review ever got published...

  3. Incorrect headline on VirtualBox 2.1 Supports 64-Bit VM In 32-Bit Host · · Score: 1

    Headline should read "VirtualBox 2.1 Supports 64 Bit VM in 32 Bit Host Operating System".

    Big difference between a 32-bit host and a 32-bit host OS.

  4. ZFS not ready for prime time on Sun CEO Says ZFS Will Be 'the File System' for OSX · · Score: 4, Informative

    ZFS is not ready for prime time - at least not on Solaris.

    I setup ZFS on some SAN storage in a new system. The internal boot disks were mirrored UFS. When one of the HBAs fried, the SAN storage disappeared - and the system panic'd.

    Every reboot thereafter stopped in a panic. The ZFS subsystem panic'd the system at every boot when it couldn't find all its volumes. After calling Sun support, I found out that they need to do a massive code redesign to catch that issue, and it wouldn't be out for at least 6 months.

    I'm sure ZFS will be great - once they clean up these type of showstopper bugs.

  5. Re:Kiss of Death on CMP Acquires Black Hat · · Score: 2, Informative

    I've been annoyed with CMP recently, and I only freelance for them on occasion.

    People coming/going for various reasons (I've heard more than I remember, but some were just fed up with the way things were going), shuffling things around, losing paperwork...

    Like I said, only a freelancer, but still annoyed with how they do things.

  6. Re:Annoying ads on DoubleClick Warns Against Ad-Blocking Browsers · · Score: 1

    Amen.

    Ads are fine, if they aren't intrusive. Once they overtake the content of the page, its time to go.

  7. Re:Is There a Place for a $500 Ethernet Card? on Is There a Place for a $500 Ethernet Card? · · Score: 1

    Yup.

    Been there, seen the destruction. Video cards smoke really well...

  8. Re:No child left behind? on Hand-made Web Server, Built From 200 TTL Chips · · Score: 0
    then again, most people on /. are stupid college kids who think programming 101 is the axis of computer knowledge and and have no idea what and edge trigger even is.
    Sad but true.
  9. Re:just wait... on Little Interest In Next-Gen Internet · · Score: 1

    If he's a network security engineer, shouldn't he realize that NAT actually hides the real source of some network threats?

    If everyone has a real IP, problems are much easier to track down.

  10. Re:In-line SPAM filtering - never hits your server on Reviewing Anti-Spam Offerings · · Score: 1

    Things I've learned about outsourcing spam filtering...

    Number 1 - Too many missed messages. I've been adding domains to the block list for a year now. I still get more spam messages.

    Number 2 - Poor configuration options. The only things I can change is the "aggressiveness" in 4 or 5 catagories (bulk email, porn, attachments, etc), or adding addresses/domains to a white/blacklist. Spam Assassin lets me change scores for different things, which is very nice.

    Number 3 - Dependance on offsite server. Generally not a big deal, with redundancy and all, but occasionally it happens. And it blows.

    For the record, my experience is with Postini. It wasn't my choice, but I still use that account anyway. My work account, using Spam Assassin, lets no spam through, and has only the occasional "false positive" (meaning it caught it according to my rules because a valid sender did something dumb, like send HTML mail).

  11. Re:Illegal, right? on Ten-disc 'Matrix' DVD Box Set Planned · · Score: 1

    We've all heard this before. It's not a "legal" DVD player, blah blah blah.

    If I spend the $15 - $20 on a DVD, I'm going to play it on whatever I damn well please.

  12. Re:Is it just me, on Linux Kernel 2.6.7 Released · · Score: 1

    Well, that's the way it happens when you replace the VM system in the middle of a "stable" release. I know people who still run 2.2 because of that.

  13. Read it the right way... on CNN Notices that WiFi is Insecure · · Score: 0

    "Meanwhile, average users are no longer tech savvy."

    No, this doesn't mean that the average users were at some point tech savvy. It just means more idiots are buying them.

    More open networks for the rest of us, I guess.

  14. Re:Hmm, doesn't seem very unusual. on Ongoing Linux/Solaris Compromise Epidemic · · Score: 1

    Your recommendations are the same things we tell our users.

    People will still attempt to get simple passwords through the password checker just because they don't want to remember something hard. Some people are so stupid they use variants of their usernames.

    Unfortunately, there is little admins can do with stupid users beyond explain to them why they're stupid and try to convince them to change their ways.

  15. Re:Too young? on A Babe in Tuxland · · Score: 1

    I will admit that I enjoy surfing around and watching TV, but there's only so much of that I can handle. I need to go outside, breathe fresh air, feel the sun, to DO something.

    Although there are a lot of things that you can do online, there are many, many things that you just can't do without leaving the dimly-lit basement and going outside.

  16. Too young? on A Babe in Tuxland · · Score: 3, Insightful

    As wonderful as it is to see a young child able to use Linux, is it really necessary for children use computers? They are wonderful tools, and there are many games for young children that help them learn, but really, couldn't the parents teach the children just as well?

    The real problem is when parents let their children sit in front of a TV or computer all day. There's a lot more to life than just staring at screens.

  17. Re:XFree86 on X.Org Foundation Releases X11R6.7 X Window System · · Score: 1

    I see how that's an issue now, thanks to the other replies.

  18. Re:XFree86 on X.Org Foundation Releases X11R6.7 X Window System · · Score: 1

    Got it. Now I see.

    And, quite frankly, I find it stupid. But, whatever. I only write things for myself, and thus I don't worry about licensing.

    If I ever do release anything, I'll have to look into licenses more. I don't like that piece of the GPL.

  19. Re:XFree86 on X.Org Foundation Releases X11R6.7 X Window System · · Score: 1

    Thank you for that explaination. Short, sweet, and to the point.

    Now, the question I have to ask is this: How can the GPL apply to "an entire work"? If I write something, only the part that I'm writing (or modify) should be under the GPL. If I write something and link to another non-GPL library, and I follow all requirements of the license said library is under, why should the GPL suddenly apply to it? Just because I want to link against something under a different license shouldn't mean that suddenly that other thing is under the GPL. That's not right.

    That doesn't make any sense whatsoever. Just because I link against your BSD licensed library doesn't change the license for your library.

    I'm going to have to go read the GPL more carefully before I say much more. However, if this is the case, then I can understand how Microsoft can claim that it's a 'viral' license.

  20. Re:XFree86 on X.Org Foundation Releases X11R6.7 X Window System · · Score: 1, Insightful

    So the entire argument is about being forced to give credit where credit is due?

    That's fucking awesome.

    Nothing is stopping me from using XFree86 on my debian box, so if they decide to stop using it, I'll just compile it myself.

    So long as minor issues like this are blown out of proportion, people are going to shy away from Linux. It's a shame, too.

  21. XFree86 on X.Org Foundation Releases X11R6.7 X Window System · · Score: 3, Interesting

    I just read over the XFree86 license versions 1.0 and 1.1. I see the difference, but why is this seemingly minor change causing such a huge commotion with the major distributions?

    Of course, some of us care more about the fact that it is still free (as in beer and in speech) than the exact wording of the license.

  22. Too bad... on UK Government to Tax Linux? · · Score: 0, Troll

    Too bad we can't moderate the articles...

  23. DDoS == Slashdot on SCO Offers $250K Bounty for MyDoom Author's Arrest · · Score: 5, Insightful

    They don't want to get DDoSed on the 1st, so they decide to give out a huge reward.

    I bet they didn't think about the number of people (not just from Slashdot, but everywhere) that were going to DDoS them just by reading their press release...

    Yet another showing of intelligence from SCO.

  24. Re:Excuse me? on Linus Speaks Out, Calls SCO 'Cornered Rat' · · Score: 1

    Thank you.

    I must have misread it. My apologies.

    But it still doesn't claim it's a last ditch effort. This was not the only course of action. It was just the easiest.

  25. Excuse me? on Linus Speaks Out, Calls SCO 'Cornered Rat' · · Score: 3, Funny

    "...he admits that the company was failing and the Linux-related lawsuits were a last-ditch effort to prevent bankruptcy."

    I'm sorry, I just don't see that. Nowhere in that article did I see an admission that it was a last-ditch effort to prevent bankruptcy. I see him talking about "protecting UNIX IP rights"...I'm not even touching that part.

    Let's let people read the article and draw their own conclusions instead of making some up to make Darl sound worse. He can do that all on his own.