Slashdot Mirror


User: Jon+Stone

Jon+Stone's activity in the archive.

Stories
0
Comments
60
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 60

  1. Re:Privatization FTL on Hackers Penetrate Nasdaq Computer Networks · · Score: 3, Insightful

    it should damn well be under Military-grade security and government control.

    Is this the "military-grade security and government control" that prevents classified material being leaked to Wikileaks so effectively?

  2. Re:Slightly unrelated on Comcast Activates IPv6 Trial Users · · Score: 1

    You have 18 quintillion addresses to hide in. How much uncertainty do you need?

  3. Re:People stopped using Telnet? on Hackers Bringing Telnet Back · · Score: 1

    Simple 3-way handshake and boom, datastream.

    Then you're not using the telnet protocol. Telnet does a certain amount of negotiation at connection to pass through environment variables and the like to the server. Most clients automatically skip this if the server port is not 23.

  4. Re:https doesn't necessarily solve this on How Facebook Responded To Tunisian Hacks · · Score: 1

    https/ssh/etc require that you have a trustworthy translation from name to ipaddress. A corrupt ISP defeats it.

    Not true. The reverse proxy would need a private key certified by a trusted CA in the name of the server. If we assume (big assumption...) that the root CAs trusted by the browser never make a mistake, then there isn't any practical way for the proxy to impersonate the server and get away with it. X509 protects you from corrupt ISPs meddling with DNS, as long as the trusted third parties (the CAs) are truly trustworthy.

  5. Re:I have an Android phone .... on The 10 Best Android Hacks · · Score: 1

    My apologies, I just couldn't resist.

  6. Re:I have an Android phone .... on The 10 Best Android Hacks · · Score: 3, Funny

    ... but it could be nice to have anything usefull among those hacks, don't you think ?

    Like a spell checker?

  7. Re:Where are the torrents? on Beware of Using Google Or OpenDNS For iTunes · · Score: 1

    Akamai charge for their distribution servers around the Net. If they were to use torrents, those distribution servers would become the seeds and Akamai would still be able to charge a small fortune for them.

  8. Re:Multiple DNS feature? on Beware of Using Google Or OpenDNS For iTunes · · Score: 2
    That's sounds very much like the default behaviour of ISC's bind, up until version 9.6 https://www.isc.org/software/bind/new-features/9.6

    Randomize server selection on queries As a security improvement to make forgery a little more difficult, BIND 9.6 now attempts to make the order of the server selection for queries less predictable. Previously, BIND would prefer to query the server with the lowest round trip time (RTT). Now servers that haven't been tried yet have their RTT set to a random value between 0 ms and 7 ms. And the RTT values of servers which have been tried are now randomly changed up to 128 ms.

    This algorithm also applies to DNS servers specified with the "forwarders" clause. A local bind installation with the ISP's and Google's DNS servers configured as forwarders would do what you want. The OS and applications would then be configured to use the local DNS server.

  9. Re:Large-scale NAT in Qatar on After IPv4, How Will the Internet Function? · · Score: 1

    Is there a future in preventing abuse by blocking IP addresses? In IPv6, each end user might have control over 2^64 IP addresses. Blocking individual addresses won't scale, and blocking entire /64s will risk the same affect of blocking innocent bystanders. I can't see how sites like Wikipedia and the RBLs will be able to scale their blacklists to these numbers of addresses cost effectively.

  10. Re:Large-scale NAT in Qatar on After IPv4, How Will the Internet Function? · · Score: 1

    Qtel force all web traffic through a proxy server in order to block access to certain sites. All Qtel web traffic is seen to come from the IP address of the proxy server. This is completely different to NAT. http://www.state.gov/g/drl/rls/hrrpt/2007/100604.htm