Slashdot Mirror


User: sqlrob

sqlrob's activity in the archive.

Stories
0
Comments
2,406
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 2,406

  1. Re:And that matters because...? on First Scareware For the Mac · · Score: 1

    It does, as does other comments I've made in these threads. It makes it easy to get a user to run something unknowingly. Especially if they modify Applications in the sidebar to point to ~/Applications and symlink across the apps that are normally there. *poof* Something that looks legitimate in "/Applications", but really isn't.

  2. Re:And that matters because...? on First Scareware For the Mac · · Score: 1

    How many times does this need to be repeated?

    Effective malware does not need special permissions

    Granted, higher permissions make it harder to remove and/or detect. But given the average user, that doesn't mean squat, they wouldn't notice it unless it was in their face, and even then it's a crapshoot. Until there's effective MAC that an average user can use (Leopard isn't it, SeLinux doesn't cut it for the average user), malware will continue to be a problem. Even then, social engineering will work wonders, it's just more dialogs to make them click through.

  3. Re:the shit hits the fan! on First Scareware For the Mac · · Score: 1

    Or a buffer overflow in Java that Apple had for more than a year after Sun fixed it.

  4. Re:the shit hits the fan! on First Scareware For the Mac · · Score: 1

    This is how I normally run. Unfortunately, it is buggy and still not completely effective. There are those user based locations I mentioned in other comments. Even worse, when you drag into /Applications, even after authenticating as the admin user, the permissions are for the current user with full access. So once it's installed, anything else running with your credentials can edit it.

  5. Re:the shit hits the fan! on First Scareware For the Mac · · Score: 2, Informative

    Depends on what version of OS X you're talking about. Drop something in ~/Library/Input Managers in Tiger and below, and every cocoa app is infected when you run it. Or put something in ~/Library/LaunchAgents and watch for Safari and inject code (non-root for PPC only,special group or root for Intel). Or rewrite plugins residing in ~/Library/Internet Plugins...

    With some more thought I can probably come up with a pile more.

  6. Re:the shit hits the fan! on First Scareware For the Mac · · Score: 1

    Did you read my comment? I did not say /Applications. I said ~/Applications

  7. Re:the shit hits the fan! on First Scareware For the Mac · · Score: 0

    But still damaging. A lot of what MyDoom did can be reproduced in a non-admin level account very easily.

    It's trivial to reinstall in OS to clean something. Recovering the data is the issue.

  8. Re:the shit hits the fan! on First Scareware For the Mac · · Score: 4, Informative

    It doesn't take special permissions to put stuff in ~/Applications. It's not done by default, but some users do do it, and Finder supports it.

    Or heck, just put it on the desktop where the user can click it. No special permissions needed. Most .Apps don't need an installer, nor need to be in /Applications.

  9. Re:Well if the blogger's aren't willing to act... on Long Term Effects of Gizmodo CES Prank · · Score: 2, Informative
  10. Re:Like it matters on Boot Record Rootkit Threatens Vista, XP, NT · · Score: 1

    There are more good guys, but are there more *qualified* good guys?

    How long was the zlib double free present? How long was the hardcoded password in Firebird?

  11. Re:Reminds me of Radio Shack on Sears Installs Spyware · · Score: 1

    They never required it. A simple "no" always worked for me.

  12. Re:In the USA medium ratings are NOT laws on Clinton Would Crack Down On Game Content · · Score: 1

    Incorrect. The rating enforcement for games is about the same as that for movies in theaters. Both are about twice as effective as rating enforcement for movies bought in stores.

    Given the enforcement rates, why aren't movies in stores being targeted?

  13. Re:Title is incorrect... on Clinton Would Crack Down On Game Content · · Score: 1

    OK, so the movie system (stores) has a higher failure rate than video games.

    Therefore, the movie system does it's job and game ratings are ignored. Care to explain that logic?

  14. Re:Hrm! on Clinton Would Crack Down On Game Content · · Score: 1

    Kindly point to the peer reviewed study that has withstood examination that shows video games to be a problem worth regulating.

    Not liking kids having them != kids being harmed by them.

    All the modern consoles have parental controls, and *gasp* parents can veto what their kids buy. Where does the 12 year old you're trying to protect get the money for a game, console, and TV as well as transportation to the store? If all that's done without parental involvement, there's bigger issues with the child than the game, and if it's with parental involvement, why is the law needed?

  15. Re:Hrm! on Clinton Would Crack Down On Game Content · · Score: 2, Interesting

    Sounds perfectly reasonable to me. A store selling 18+ games to twelve-year-olds should be punished.

    What about a store that sells unrated or R movies to children? All media or none, otherwise the constitutional bar isn't met.

    After all, this legislation is going to affect underage people, unlike Jack Thompson's ideas of banning such games for everyone.

    Chilling Effect. So yes, it does effect adults.

  16. Re:They got lucky on SquirrelMail Repository Poisoned · · Score: 1

    Or even better, the key is never on a networked computer, ever. That is a lot harder to breach, since it would require a physical compromise as well as a network. Things need to be layered as much as possible.

  17. They got lucky on SquirrelMail Repository Poisoned · · Score: 3, Insightful

    MD5 was on the same server. What prevented the attacker from changing that as well?

  18. Re:is this on Can Blockbuster be Sued Over Facebook/Beacon? · · Score: 1

    Hollywood Video has been dropping like flies here, so it's possible. They were founded the same year

  19. Re:Don't Use GPL Licensed Software on Verizon Being Sued for GPL Infringement · · Score: 1

    Like when TimeLine threatened SQL Server users? Sounds real safe.

  20. Re:A workaround? on MD5 Proven Ineffective for App Signatures · · Score: 1

    Here's an example with 12. Linked to from TFA even.

  21. Re:Crysis, Bioshock, Unreal Tournament III on Game Journalist May Have Been Fired Over Negative Review · · Score: 1

    Considering the DRM on Bioshock destroyed a friends install of Battlefield 1942, yes, the DRM needs to be mentioned.

  22. Re:Sony won't have to release source code to game. on PlayStation 2 Game ICO Violates the GPL · · Score: 2, Informative

    The company I work for has *ALL* licenses checked by lawyers. Open, closed, it doesn't matter. That cost is amortized across all purchased/obtained libraries.

  23. Re:What is it? on PlayStation 2 Game ICO Violates the GPL · · Score: 1

    At least a sack of flour doesn't $*@)$*( wander away

  24. Re:Pornographic games? on Study Finds Games Stores Still Selling to Minors · · Score: 1

    That would fall under the obscenity statutes. The type of media is irrelevant.

    And that's also one of the reasons why these game laws are unconstitutional. They must apply to all media or none.

  25. Re:Why do games have levels? on Why Do Games Still Have Levels? · · Score: 1

    Missions are not the same as levels.

    Jak and Daxter is completely seamless, no loading screens. Finishing missions will open new areas, but the entire old area is open at most points.