Slashdot Mirror


User: Lennie

Lennie's activity in the archive.

Stories
0
Comments
3,689
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 3,689

  1. Pretty sure they can do it on FBI Telling Congress How It Hacked iPhone (theverge.com) · · Score: 1

    Pretty sure they can do it:

    http://blog.trailofbits.com/20...

  2. Re:Hillary and Bill also, so what's the point on Trump Gives Displaced IT Workers Attention, and He's Not Alone (computerworld.com) · · Score: 1

    "Same thing with illegal immigrants. Trump never said 'All illegal immigrants are murderers, rapists and drug dealers'. "

    He said: some are good people.

    Some in my book means: not many.

    So basically he said: they are almost all bad people.

  3. If I remember correctly:

    The design by Intel was supposed to be something at least Intel could check if Intel built the CPU's correctly, so they could have an extra layer of certainty.

    But a white hack hacker came up with a way to produce the RNG/CPU in such a way to fool the inspection methods.

    Thus Intel can't as easily check if what they are producing is actually correct.

  4. I doubt it.

    Google, Microsoft and Facebook also built their own servers, they aren't selling them.

    These are servers built for specific (set of) tasks.

    I would rather see them join the open compute project (where you already have some of the designs from companies like Facebook and Microsoft):
    http://www.opencompute.org/

    Obviously, they could do both. But selling open source hardware that would be weird for Apple, I think ?

    Anyway, other companies do sell hardware from opencompute designs.

  5. Re:Congrats Slashdot! on How Far Have We Come With HTTPS? Google Turns On the Spotlight (networkworld.com) · · Score: 1

    I understand your point now. But that's a lot of trouble to go through and it would take a lot of requests to identify a single user. There are much easier and more stealthier ways to do that.

  6. Re:Congrats Slashdot! on How Far Have We Come With HTTPS? Google Turns On the Spotlight (networkworld.com) · · Score: 1

    How are they cookies ? How does the server learn what the client/browser knows ?

    The client/browser doesn't send what the it knows to the server and AFAIK there is no Javascript API or similar to check it from within the page.

  7. Re:Congrats Slashdot! on How Far Have We Come With HTTPS? Google Turns On the Spotlight (networkworld.com) · · Score: 1

    Obviously at first visit the CA-system still applies, so the certificate was/were issued based on some verification process. So that is a form of out-of-band communication channel. It's the most used channel on the Internet right now. This is just an improvement.

    What a lot of attackers want to prevent is detection and with this system in place, the risk of detection also becomes much higher.

    Anyway, you can also get your site added to the lists that are included in browsers. Chrome and Firefox use that too (obviously in case something breaks it's much harder to change them): https://src.chromium.org/viewv...

    I agree DANE/TLSA is a great solution. But it will take time to before most (if not all) networks at least don't break DNSSEC.

  8. Re:Technology and Australia on Stephen Elop New Chief Innovator For Australia's Telstra · · Score: 1

    Andrew was forced to do it, because nobody else in the world had the same problem. Australia is just that bad.

    Here is an old talk from him:
    "So the core of rsync is this algorithm that I call the rsync algorithm. And it solves this problem, the remote update problem. Now the remote update problem is basically: you have two computers connected by a very high latency, very low bandwidth link... a typical Internet link, at least if you're in Australia. So, a piece of wet string, a really pathetic link... and you've got two files."

    http://olstrans.sourceforge.ne...

    If you prefer to hear him talk about rsync instead of reading, there are recordings of that talk as well. I'm sure you can search for it.

  9. Re:Congrats Slashdot! on How Far Have We Come With HTTPS? Google Turns On the Spotlight (networkworld.com) · · Score: 3, Interesting

    You know what is good about HTTPS these days:

    - HTTP/2 using HTTPS is faster than HTTP/1.x without HTTPS and it's getting easier to deploy it. For example by using the H2O webserver ( https://h2o.examp1e.net/ ) as a proxy, it comes with built in SSL/TLS library for easier deployment and support for replicating sessions.

    HTTPS itself is becoming easier to deploy and manage:

    - HTTPS doesn't need a dedicated IP-address any more (older browsers/operating systems had problems with the HTTPS equivalent of 'virtual hosts'):
    https://en.wikipedia.org/wiki/...

    - certificates are available for free with an automatic request and renewal system. So no more messing around, you can automate it. -> with Let's encrypt Beta: https://letsencrypt.org/ and for example with acmetool: https://hlandau.github.io/acme....

    There are finally ways to fight the silly CA-system, not completely, but things are improving.

    For regular visitors on a site you can add headers which will prevent an other CA issuing a rogue certificate for your site.
    https://developer.mozilla.org/...

  10. Re:Crypto? on Paris Attacks Would Not Have Happened Without Crypto (arstechnica.com) · · Score: 1

    If the US won't stop meddling in other countries business then I can keep blaming them for these kinds of things.

  11. Re:Crypto? on Paris Attacks Would Not Have Happened Without Crypto (arstechnica.com) · · Score: 1

    Yep, that was what I meant.

  12. They are probably using deep packet inspection and some configuration recipe provided by the manufacturer. It will probably take them a couple of years to figure out they can block on the SNI.

  13. Re:Crypto? on Paris Attacks Would Not Have Happened Without Crypto (arstechnica.com) · · Score: 0

    Islam ? You mean funny way to spell: US of A.

  14. Re:Missed the Boat? on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    Luckily I'm from Europe, I don't remember any problems with law here.

    We'll have to see if cryptocurrencies will be different. Wouldn't be surprised if some laws will be applied at some point.

  15. Re:Missed the Boat? on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    Judging by how Bitcoin is doing right now, maybe it will be other cryptocurrencies and not Bitcoin.

    But definitely I see blockchain technology, even if only at the backend of the banking system.

  16. Re:ATTENTION: Editor shortend my question - here's on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    That would have been a more clear question.

  17. Re:The big banks are getting on the bitcoin wagon on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 2

    The banks will not be doing Bitcoin, they are staying as far away from that as possible.

    They'll adopt blockchain technology all right, but I'm not so sure they'll adopt a new currency. Maybe some kind of coin only used between banks.

  18. Re:Exchanges Can Buffer You From Fluctuations on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    Storing money at an exchange, yeah, that seems like an awesome idea.... (mt gox)

  19. Re:Go back in time on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    1. energy costs are different in different regions, I think what he means is: he is in a region where energy isn't cheap enough
    2. some people still mine it when at a slight loss, because they expect the price to go up

  20. Re:Go back in time on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    That is stupid, the Internet wouldn't be in such wide spread use if it was patented.

  21. Re:Privacy with bitcoin is a work in progress on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    Dash seems like a pretty good implementation of coin-join, directly build into the coin.

  22. Re:Boat still hasn't left port on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    I think it not only happens when they don't have money to spend, but also when they don't want to spend.

  23. Re:Boat still hasn't left port on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    No just means you are early after the comment was posted, the moderators aren't magic. It's at 4 now.

  24. Re:Missed the Boat? on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    Dash (an alt-coin/other cryptocurrency) also has an instant send built into it.

  25. Re:Missed the Boat? on Ask Slashdot: Time To Get Into Crypto-currency? If So, Which? · · Score: 1

    The Internet was associated with porn at first too, still it got used by everyone many years later.