Slashdot Mirror


User: biftek

biftek's activity in the archive.

Stories
0
Comments
73
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 73

  1. Re:security vs sci-fi on Does 802.11n Spell the 'End of Ethernet'? · · Score: 1

    What the fuck does the (draft still?) 802.11n standard have to do with PCI standards?

  2. Won't AJAX textboxes kill this? on Encrypt and Sign Gmail messages with FireGPG · · Score: 5, Interesting

    I haven't used gmail that much, but I was under the impression that it saved drafts of what's in the composition textbox at intervals.

    That data would be all cleartext wouldn't it? Seems a tad risky to me.

  3. Re:Parent is not a troll... on China Crafts Cyberweapons · · Score: 1

    Yeah, mostly since it's not airspace, but rather space. Like, there isn't any air there. Duh :)

  4. Re:Its just not the same thing. on Does ZFS Obsolete Expensive NAS/SANs? · · Score: 1

    "Hundreds of gigabytes per second" sounds like it's either from RAM or you're talking out of your arse.

    Say a standard SATA disk might do 60meg/sec (could be a bit more, but I reckon that's probably ballpark), then 48*60 = 2.8G/sec. So around 2 orders of magnitude less.

  5. correction: s/local root/remote root/ (NT) on Apple Mac OS X Update For 17 Vulnerabilities · · Score: 1

    Mmm, hands not connected with head :)

  6. Re:Even still, Macs have no open ports by default on Apple Mac OS X Update For 17 Vulnerabilities · · Score: 2, Informative

    No, you're wrong. Bonjour (aka rendezvous aka mdns[responder]) listens on UDP port 5353 by default on a client install - that's how iTunes/iChat/AFP sharing find other computers. And guess what - it's one of the apps that has a local root exploit in this security update.

  7. Re:So, if I reaf TFA correctly: on MacBook Hacked In Contest Via Zero-Day Hole in Safari · · Score: 2, Informative

    The intent was always that the rules would be progressively relaxed - see http://www.securityfocus.com/archive/142/464216/30 /0/threaded from last month.

  8. Will Parallels work for multi-user systems? on Best Way to Image and Deploy Dual-Boot Macintosh? · · Score: 1

    Lots of people have suggested Parallels (with good reason), though I'm curious whether it can handle various different users logging in to a single Windows disk image (not simultaneously). AFAIK the logged in OS X user needs full permissions on the disk image, so that's a bit of a security issue. The alternative could be one image per user, though that would suck for maintenance and also disk space?

    Also for the people suggesting ASR for a dual-boot cloning solution - will that work with non-HFS partitions?

  9. And they didn't even mention Rendezjour? on Top 12 Operating Systems Vulnerability Survey · · Score: 1

    So, they had to explicitly enable all of ftp, samba, afp etc for OS X to get something to show, yet didn't even notice MDNS/Rendzejour (port 5353) open out of the box? Mongs.

  10. Tesla coils? on Hitachi's Tiny RFID Chips · · Score: 1

    You'd think that a tesla coil or something might be effective in disabling them? When the local science museum here (Scitech in Perth, Australia) first got their one (without a faraday cage) the cash registers in the store below all went on the blink...

    In short bursts they probably wouldn't be _too_ damaging to human health either

  11. Re:The Exploit on Solaris Telnet 0-day vulnerability · · Score: 1

    Nah, I think root's the only user that _won't_ work...?

  12. The Exploit on Solaris Telnet 0-day vulnerability · · Score: 3, Informative

    Since noone seems to have bothered posting it yet, "telnet -l -frandomuser randomsolarishost".

    So stupid.

  13. Re:This is fantastic on Windows Expert Jumps Ship · · Score: 1

    At least round here (Perth, Australia), in terms of Firewire cables Apple's ones _are_ superior. For the sole reason that they're about 3mm thick (~0.1" I guess?), as opposed to all the other ones you get that are at least twice that. Thinking design is useful :) But yeah. You can get what you pay for with any platform.

  14. Re:I have to say that one of those fixes is... on Apple Releases 31 Security Fixes · · Score: 1

    I take it you've never written C code to parse any file format....

  15. Re:Wireless is minimal on UK Schools Bans WiFi Due To Health Concerns · · Score: 2, Informative

    802.11-b/g operate on the same frequency as microwaves (i.e. in the microwave spectrum); a microwave is shielded by physical means (no, no magical force fields when you power it up), and if you toss a laptop inside (don't turn the microwave on!) you can still connect to it over wifi with good signal. The shielding lets more through than wifi.

    I just tried this, it didn't work. Full signal outside the microwave, absolutely none inside. Maybe you should check yours?...

  16. Re:I'm still waiting on Apple Unveils MacBook Pro with Core 2 Duo · · Score: 1

    Isn't that what the current iMacs have?

  17. Re:In related news... on Less Than a Minute to Hijack a MacBook's Wireless · · Score: 1
  18. Re:Ah. balance on Debian Locks Out Developers · · Score: 1

    Having implemented rudimentary PAM support for a SSH server, I'd have to say that I agree that PAM is somewhat horrible. It appears that it works great for it's original intended purpose of printf() at a login prompt, but not for much else without jumping through hoops.

  19. Does the Columbia River flood? on Google's Secretive Data Center · · Score: 1

    That could make things exciting...

  20. Re:They haven't heard of ssh-add -c? on Overconfidence in SSH Protection · · Score: 1

    It doesn't ask for a passphrase, just a yes/no answer. Not sure how the default X11 ssh-askpass thing treats it, but here with SSHKeychain I just press enter to confirm/esc to cancel.

  21. They haven't heard of ssh-add -c? on Overconfidence in SSH Protection · · Score: 5, Informative

    A few versions ago OpenSSH added a -c "Require confirmation to sign using identities" to ssh-add to take care of this. Or using something like SSHKeychain on OS X so it'll ask for confirmation for multi-hop auth, but not for connections direct from your trusted machine.

  22. Re:System should be safe on Mac OS X Struck By Severe Security Hole · · Score: 1

    There are unpatched local root exploits in 10.4.5 though.

  23. Admin rights not required, summary wrong as usual. on Ancient Flaws May Leave Mac OS X Vulnerable · · Score: 3, Informative

    Uhmmm. The submitter has missed the entire point of that exploit - admin rights aren't required, because the program checks for admin credentials with 'getenv("USER")' - ie "export USER=some_admin" is the exploit.

  24. Re:The big question: Is it made using XCode? on At Long Last, NeoOffice/J 1.1 Released · · Score: 1

    "made using XCode" is apple-speak for "compiled with GCC". Just add -arch i386 and it will likely work.

  25. Just get an old IBM keyboard - removable+clicky on Blank Keyboard · · Score: 1

    I've got an old several-kilo ibm keyboard, with great clicky switches and even better, the letters come off. IIRC I got 5 of them for ~$7.