Slashdot Mirror


User: roju

roju's activity in the archive.

Stories
0
Comments
479
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 479

  1. Re:Okay now... on Michael Robertson Says Root is Safe · · Score: 1
    Just so we get the tone of this conversation right, I'm enjoying this exchange. It's causing me to evaluate my assumptions and to question my beliefs (well, my beliefs wrt linux security).
    You haven't presented anything better that you can do as root. There might be more ways to do the same thing, but that isn't any better.
    It is possible, as root, to load code at runtime into the kernel that is totally invisible to anyone poking at the computer. It is NOT possible (within some epsilon of NOT, anyway) for an arbitrary user to hide running code from root, without first gaining root.

    My SOP for dealing with weirdness is to log into a console and run top as root. If I always ran as root, the spykit could be completely invisible. If I typically ran as user, then I'll see something weird.
    What if they changed the LD_LIBRARY_PATH?
    They can't change root's LD_LIBRARY_PATH. That's the whole point of having multiple users.
  2. Re:Oh Canada! on Canadians May Face 25% Download Tariff · · Score: 1
    How are is it being fair to everyone? If you buy a blank CD-R and just make a back-up of your personal computer files, why in the world should you have to pay an "artist" tax on that?

    Because some actuary somewhere did the math, figured out the percentage of blank CD-Rs used for piracy, and computed an effective rate. At least, that's how I imagine it went. Much like insurance.

    That said, I'm no fan of the levy.
  3. Re:As a canadian... on Canadians May Face 25% Download Tariff · · Score: 1

    As a Canadian, hose numbers are certainly not reasonable. If a levy on downloads was deemed necessary (which I don't think it is), the levy for downloads should at least be close to that on physical purchases. For instance, if we currently pay a 0% levy on buying a music CD, something like 1% on downloads might be reasonable. 40%, not so much.

  4. Re:Maybe NOT a 40% price increase? on Canadians May Face 25% Download Tariff · · Score: 2
    Nope, you're thinking of the net. The gross is their take before expenses.
    Before tax or other items have been deducted. After the deductions, the amount is described as "net".
    www.btplc.com/Siteservices/Servicesforinvestors/Gl ossary/Glossary.htm
  5. Re:I don't think this applies to me. on Canadians May Face 25% Download Tariff · · Score: 1

    Uploading music that you don't have permission to upload is NOT legal in Canada. For instance, see Russell McOrmond's post to pcmag. Russell is super active trying to make Canadian copyright law sane, for instance, he runs Digital Copyright Canada, who recently had their Petition for Users' Rights submitted to parliament.

  6. Re:Okay now... on Michael Robertson Says Root is Safe · · Score: 1
    But you ignored my point. I wasn't arguing that it was necessary to be root in order to spy on someone. It's just that it's possible to do a better job as root. Security isn't about absolutes, it's about taking precautions. Just because I have a lock on my door, doesn't mean no-one can break into my house. However, it makes it less-likely.
    For instance, a regular user has no way to run a process without it appearing in the process list.
    They could replace the program that a user uses for listing processes though.

    No, they can't. Well, that's not quite what I mean. They could alias ps to /home/foo/.trojan/ps, for the low-priv user. Thing is, when Joe User calls his nerdy cousin Dwight up because his computer is slow as shit, and Dwight comes over and logs in to the console as root, typing /bin/ps aux is going to show the trojan running.
  7. Re:I don't agree, but... on Michael Robertson Says Root is Safe · · Score: 1
    If you're not talking about a server or other shared/critical environment, then the only things of any real value on the machine are the user's own files. Root or not, they can toast them. Lindows, in case you hadn't noticed, is *not* aimed at servers...

    Now, if I'm running as some random user, I'd fear rm -rf $HOME. However, I'd be able to download some software and say to it "find all deleted files on this partition and make them come back."

    If I'm running as root, the attacker could do something like dd if=/dev/urandom of=/dev/hda and then my chances of getting any data back are pretty much toast.
  8. Re:"Local escalation" fallacies. on Michael Robertson Says Root is Safe · · Score: 1
    Yes, 99% of my machine will not be affected. But guess what? I'm still losing that text document, which, to me is a hell of a lot more important than losing /bin/ls (which I can just reinstall).

    If you aren't running as root, when you see:
    rm: Permission denied: /dev/hda
    rm: Permission denied: /dev/hdb
    rm: Permission denied: /dev/hdc
    ...
    scrolling up the screen, you can pound ctrl-c and pray that you stop things before any damage is done. And then you can reboot, without worrying that you're missing essential system files.

    OTOH, if you were running as root, you'd HAVE to reinstall, or at least put a lot of effort into recovery.
  9. Re:Okay now... on Michael Robertson Says Root is Safe · · Score: 1
    Spyware doesn't need root privileges to spy on you.

    But it sure helps. For instance, a regular user has no way to run a process without it appearing in the process list. A regular user can't load kernel modules. On the other hand, root can do both those things.

    Spyware installed as root can become invisible, by taking advantage of root's powers. It makes the problem that much harder to detect and diagnose. If you run as root all the time, there's just no way to know if you've been owned. On the other hand, running under a regular user account, you can be a lot more confident that there isn't an invisible process/module watching you.

    Not to mention that a lot of viruses like to guarantee their execution by piggybacking into system files. Remember when instead of worms, we had viruses that would infect .exe files? If all of your apps are root:root r-xr-xr-x and you aren't running as root, then it's a lot harder for a virus to add itself to a system binary.
  10. Re:Correct (I hope) script on Star Wars: Revelations Available Online · · Score: 1
    I love golf! 18 characters.
    _____1234567890123456789
    perl -pe'y/ //dif$.!=1'
  11. Re:Won't someone PLEASE think of the children? on Anti-DMCA Petition in Canadian Parliament · · Score: 1

    We should really be milking the "think of the children" viewpoint more. The pro-children viewpoint has to be the lenient-IP viewpoint.

    It's not what the WIPO people want us to think, but it's the true. The more restrictive our IP laws become, the more we neuter our children. IP laws are like pollution - harmful to the children.

    The more we strangle the public domain, the less that they have to build on in the future. The more restrictions we place on what they can do, the less job oppourtunities they'll be able to create.

    It drives me nuts that people can be pro-draconian-IP and still tell us to "think of the children."

    Kudos to your daughter. She still working on things? I can't recall any recent emails to the DCC list, though I'm about a week behind.

  12. Re:NDP took opposite stand during election on Anti-DMCA Petition in Canadian Parliament · · Score: 1

    This last election was tough for me. I considered IP to be one of my deal-maker issues, and only the Conservatives had a sane policy stance on it. The Liberals were pro-WIPO, the Greens were just confused, the NDP was super pro-WIPO, but the Conservatives were... conservative on the issue.

    Unfortunately, the rabid CCRAP members ruled out the Conservatives as a sane vote, leaving me to pick and choose from parties with poor IP platforms.

  13. Re:9/11?! on Best Buy Has Man Arrested for Using $2 Bills · · Score: 1

    Not act like cowboys? The city's big stadium is the SADDLEDOME

  14. Re:This is exactly why... on VLC & European Patents · · Score: 1

    I use VLC exlusively on my Windows computer (a 233) because WMP just can't do it. I can't explain it, but where WMP shows a blank screen and plays choppy audio, VLC plays back choppy video and perfect audio. ffmpeg must be tuned more than the windows codecs or something.

  15. Re:unverifiable on The End of Mathematical Proofs by Humans? · · Score: 0, Troll

    Good idea. You write us a verifying program that can tell us if any given program will halt, and then we'll use it to test our theorem generator.

  16. Re:Sad on Black Holes 'Do Not Exist,' Contends Physicist · · Score: 1

    Interesting link, thanks.

  17. Re:Stupid security model on U.S. Blogger Breaches Canadian Publication Ban · · Score: 1

    This is Canada. When I went to vote, they said "are you on our lists?" I said "no." They said, "oh. are you a citizen?" I said "yes, here's my passport." They said, "ok, sign this list here, here's a ballot."

    Pre-blog days, this system makes perfect sense. The government remains transparent, it's just there's a delay until everyone hears about it in order to guarantee a fair trial.

  18. Re:poor baby on U.S. Blogger Breaches Canadian Publication Ban · · Score: 1

    I like the sound of the navy's system. It seems to me that it'd be way easier to hit an icbm on the way up than on the way down.

  19. Re:Did anybody say crackpottery? on Black Holes 'Do Not Exist,' Contends Physicist · · Score: 1

    experiment can only disprove, and never prove, our hypotheses

    People love to point this out. I think it's worth mentioning that most (all?) actual scientists are aware of the fact that you can't prove something, you can only confirm it.

    That said, when they do use the word prove, scientists mean it in a different way than mathematicians. For instance, "we've flown the plane between here and there 100 times, and it's been proven flight-worthy" vs. "a => b. a. therefore b".

    Or: "I've promoted Bob because he's proven himself to be competent" vs. "The proof of Fermat's Last Theorem is the length of a book".

  20. Re:Sad on Black Holes 'Do Not Exist,' Contends Physicist · · Score: 1

    What model gives CTCs? I've done some basic GR, but we didn't cover anything crazy like that. That sounds really neat.

  21. Re:Grow up. on e-Scrabble gets Cease and Desist Order from Hasbro · · Score: 1

    I'll very much grant you that the trademark case here seems open-and-shut from a layman's viewpoint.

    But a patent on Scrabble? I can't even begin to make sense of that. What did they patent? The tile? A bag full of tiles? A board with tile shaped divits? Actually - the board, I could see. It strikes me as unlikely that an online Scrabble clone involves a physical board though.

  22. Re:Have we forgotten our Eldred v. Ashcroft alread on e-Scrabble gets Cease and Desist Order from Hasbro · · Score: 1

    I still don't understand that retroactive extension. Did Congress not even discuss it? Lessig makes a pretty good argument against it in Free Culture.

    Actually.. I wonder.. Does the US Congress keep transcripts dating back to then? More usefully to me, does it keep them online? It might be an interesting read on a rainy weekend.

  23. Re:Uhhh on e-Scrabble gets Cease and Desist Order from Hasbro · · Score: 3, Interesting

    I saw Scrabble for sale at a games store not too long ago. Those bastards.

    Really, I agree that I don't find anything particularly suprising or outrageous about this. But you are totally allowed to just copy other people's things and sell 'em. Witness the history of the modern desktop computer. In fact, the so-called American way is pretty much based on that fact. Otherwise every new product would be a monopoly and the system would break down pretty fast.

  24. the public library on Sources of Intelligent Audio for Commute? · · Score: 1

    Every public library I've been to has had a huge book on tape section. They'll have nerdy books, and they'll have non-nerdy books. I might suggest using the time to branch out and listen to non-nerdy books. Variety being the spice of life, and all that.

  25. Re:Car computer? on Via Now Shipping Dual-Processor Mini-ITX Board · · Score: 1

    It's usable on this 233 ;)