Slashdot Mirror


User: Kevinv

Kevinv's activity in the archive.

Stories
0
Comments
240
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 240

  1. Re:Why no 17" w/o SuperDrive? on New iMacs (and iPods) · · Score: 1

    money probable. apple most likely gets a better profit margin on the higher-end device, AND they probably get a larger discount buying just these devices in larger quantities.

    The biggest downside to a 3rd party DVD burner is it doesn't work with iDVD. Which pisses me off, I can understand the royalty issue but I'd pay $100 for an iDVD that worked with 3rd party DVD's.

  2. Re:Another one-question test... on Slashback: Bouncing, Taxing, Releasing · · Score: 1

    Notification of a rejected virus/worm/trojan e-mail should go to the To:, not the From:. From: addresses are totally wrong on virus e-mails these days and the bounce is of no use -- and the sender STILL won't know it went to the wrong person because the From was forged for someone else.

    And by a strict reading of that RFC, shouldn't I be sending bounces to all those e-mail messages I discard because their SpamAssassin score is > 10?

  3. Re:Social-engineering != Virus on Is Linux as Secure as We'd Like to Think? · · Score: 1

    I've seen many apps for Windows that assumed they had full write privs to c:\, c:\windows, c:\windows\system32, and not just at install time. Don't ask me why a programmer decides this app HAS to put it's temporary files in c:\ instead of %TEMP%, but it certainly seems more common on Windows than linux.

    And why would a server application need root access? The only reason on Linux is to bind to a network socket in the reserved range, most apps I use that need to do this drop root privs as soon as this is done (and I believe the security enhancements available from several sources do away with even this much.)

    Microsoft's apps are less secure because Microsoft thinks it needs to do more for the user in stupid ways -- send me an .exe, why i'll just launch that sucker for you without even asking (or asking for every little thing so you get used to hitting Yes). I know of no Linux mail reader that automatically executes scripts or binaries that are sent to you, or even has the capability of doing this. All require saving the attachment manually, chmod'ing to give execute privs, then running it. Pretty long time to consider the folly of your actions.

    Of course Microsoft's solution to this was a security patch that simply blocked all access to most executable content! Now you don't even have the option of saving to file first, you can't get to it at all. Again Microsoft assumes they are smarter than you.

  4. Re:Are OSS fixes really faster? on Is Linux as Secure as We'd Like to Think? · · Score: 1

    windows update sucks. you have to run it multiple times to make sure you got all the patches, you have multiple reboots, and many patches require being installed by themselves before any other patches.

    The 2 distributions I've run, Debian and Gentoo, have none of these problems. Unless the kernel is updated neither requires a reboot. All installs take place in one session, all patches are installed in the correct order.

    Both update systems are also very easy to script from the command line, Windows Update requires Internet Explorer and everything to be done by hand.

  5. Re:Exim for me on Postfix: A Secure and Easy-to-Use MTA · · Score: 2, Interesting

    Yeah me too. I messed with Postfix on Debian for awhile. I got it to work but I wasn't real comfortable that I understood what I had done.

    Switching to Exim was great, I thought the config file much better. When I rebuilt my server to Gentoo a couple of weekends ago, I moved to Exim 4.1 and thought the config even better.

  6. Re:Replacing SENDMAIL does not eliminate problem. on Postfix: A Secure and Easy-to-Use MTA · · Score: 2, Interesting

    Most of the installs I've done for postfix and exim (I prefer exim) replace sendmail completely and setup a link from /usr/sbin/sendmail (or whereever) to the replacement. Both postfix and exim will accept the same commandline parameters as sendmail (although they ignore some of them) so this won't break any locally installed software that expects sendmail to be available.

  7. Re:Postfix and SMTP-AUTH on Postfix: A Secure and Easy-to-Use MTA · · Score: 1

    Switch to Exim. I use SMPT-AUTH (CRAM-5) with it. It was a breeze to setup. I just added:

    begin authenticators
    cram:
    driver = cram_md5
    public_name = CRAM-MD5
    server_secret = ${lookup{$1}lsearch{/etc/exim/allowed_auth}{$value }fail}
    server_set_id = $1

    to the end of the config file. I keep the passwords in the /etc/exim/allowed_auth file (make sure it is readable by the mail uesr ONLY, not world or group readable. Not writable by anyone.

    In the relaying section you need to have:

    accept authenticated = *

    which means you can relay from any IP in the world if you authenticate first. You can restrict that down to particular subnets if needed.

  8. Re:Down in three seconds flat on A TCP/IP Stack and Web Server In BASIC · · Score: 4, Funny

    How could you tell if it were slashdotted? 20 seconds per page is already a slashdotted server....

  9. To quote Zahpod Beeblebrox... on A TCP/IP Stack and Web Server In BASIC · · Score: 5, Funny

    ten out of ten for style, but minus several million for good thinking.

    I actually have some Apple //e's lying around. Maybe I'll dig up an ethernet card and see if i can get this to work.

  10. Re:UMR - don't go there on Missouri Wins American Solar Challenge · · Score: 1

    heh, i've been out of school for 12 years, don't make anywhere near 6 figures and dress to be comfortable. i don't change who i am to get chicks.

  11. Re:UMR - don't go there on Missouri Wins American Solar Challenge · · Score: 1

    eh, more like 4 to 1. Still not good odds, but when does a geek ever have good odds?

    not much else to do is certainly true.

  12. Re:As a former UMR student, I can say.... on Missouri Wins American Solar Challenge · · Score: 4, Funny

    See what you can accomplish when there are no women clouding your thoughts? 8-)

    Another UMR grad ('91)

  13. Re:G4 Cube on Third Party Selling Upgraded G4 Cubes · · Score: 3, Insightful

    they are nice, and apple really led charge on the small system form factor.

    downside to the cube is, personally, i don't like the connectors on the bottom, well there should be at least a usb and firewire on the front. a hub would help, but that expands the footprint.

    and repair absolutely sucks. i had to replace an ethernet card in a friends cube and it was a huge process -- you have to completely dismount the motherboard to replace it, no easy task in itself.

    wouldn't have been such a hassle if someone had a usb-ethernet driver for OS X.

    other than that they are sweet machines. i'd love to have even an old one as a wireless MP3 server and to leave permantly connected to my firewire video converter to do imports with.

  14. And just how did they accomplish this... on How to get 1.5 TeraFlops from Linux · · Score: 4, Funny

    without SCO's help?

  15. Re:First a radio series on Slashback: Hawash, Monomania, Rocketships · · Score: 2, Informative

    thank you. i didn't think that was going to get corrected. and it was actually 2 radio series before the books.

    http://www.bbc.co.uk/cult/hitchhikers/metaguide/

    And Don't Panic was written by kick ass comic book author Neil Gaiman.

  16. Re:I haven't figured out how to do this in Quicken on MoneyDance 2003 Reviewed · · Score: 1

    moneydance doesn't do this yet, but I think it's on the todo list to add the ability to manually match a manually entered transaction to a downloaded transaction.

  17. Re:Why would I need this? on MoneyDance 2003 Reviewed · · Score: 1

    Not unusual to have more than one bank account, or credit cards, or loans from different banks. At least in the US. Moneydance gives you a way of looking at your finances as a whole.

    I've got online banking with autopay too, works great. But it doesn't tell me what's going on with my mortgage (except when I make payments) because that's at a different bank. My car loan is with yet another financial institution. My 2 credit cards, 1 with my online bank, 1 with someone else....

    And Moneydance goes back as far as you want. Get audited 3 years down the line? your financials are right there.

    And they are stored on your computer (encrypted if you wish) so you don't have to worry so much about the bank getting broken into, or going out of business.

  18. Re:what ? on Linus on DRM · · Score: 3, Interesting

    if you put the private key in the kernel itself it then becomes part of the source code and must be relvealed via the GPL license (if you distribute the kernel at least)

    External keys are fine.

  19. Best...Comic...Ever.... on Return Of Bloom County. Sorta · · Score: 2, Insightful

    I didn't think MyComics was worth signing up for until this became available. Bloom County rocks! And $10 a year is the right price.

  20. WebDAV? on FTP: Better Than HTTP, Or Obsolete? · · Score: 2, Insightful

    How about implementing a webdav solution? You can get away from clear-text passwords, users can mount them like a drive on Mac, Windows and Linux (via DAVfs, http://freshmeat.net/projects/davfs/?topic_id=143% 2C90 )

    Still have some of the unreliablity of HTTP transfers and slowness. But works a lot better through firewalls (and more securely since connection tracking works better with WebDAV).

    I've found Passive Mode FTP to also be more unstable than standard ftp transfers.

  21. Re:any know the tech of how the BBC did this? on TiVo switches off UK sales · · Score: 1

    tivo can record shows it "thinks" you'll like, if you have space and if it does not conflict with a show you've said you do want.

    You can turn off this feature.

    Any UK tivo that either had the feature turned off, or had another show recording at the time this comedy came on did NOT get this show. But the BBC did pay to have all "available" units record the show, that comes pretty close to spam IMO.

    Under the normal sorting of the recorded list these shows are at the very bottom of the listing and have a different icon than shows you've requested. I sort my list alphabetically so the "you might like" shows are mixed in with the other shows, but they still have a different icon.

    This recording of "shows you might like" is the source of the "My Tivo thinks I'm gay" and "my tivo thinks i'm a fascist" stories. The algorithym used to decide what should be recorded for you may look at past recordings and decide you like gay themed shows (or cowboy themed shows or science fiction or so on). You can tweak the choices by rating shows with the thumbs up or thumbs down buttons.

  22. Re:What happens on TiVo switches off UK sales · · Score: 2, Informative

    you get a choice. but i've found i pretty much only watch shows already recorded on the tivo (for the commerical skipping) and just let it record what ever it wants from the cable box.

    now if i could just get the cat to stop chewing on the IR blaster that controls my cable box.

    now with the direct tv satellite version of Tivo you can record one show and watch another, or record 2 shows (this is because it records the already compressed version of the show from satellite so it doesn't waste processor power on the encoding, saving plenty of processor for dual recording)

  23. Re:What investigative powers/authority do they hav on Is the BSA "Grace Period" a Scam? · · Score: 1

    the BSA isn't stupid. Neither is Microsoft, Adobe, AutoDesk, etc.... A bunch of those companies founded the BSA as a non-profit organization to enforce their copyrights. Basically it gives them a scapegoat "it wasn't us that raped you it was the BSA." But it's a load of crap -- the BSA acts on very few of the letters that go out (probably less than 1%) but when they do act they have all their legal ducks in a row and do so with the Authorization of their members.

    Licenses & the law allow the company to appoint a legal representative for them -- that's the BSA. They are authorized to act for their member companies. That's why they can fle copyright infringment suits, that's why they can get the gov't to impound the computers (to prevent destruction of evidence via format or bulk erasers)

  24. Re:How it works on Is the BSA "Grace Period" a Scam? · · Score: 1

    because you don't posses software you license it. this can actually be a benefit to most companies as accountants tend to track receipts much more closely than computer people track cd's/serial numbers. But small companies can get screwed, especially if they let employees buy software as they need it.

  25. Re:How it works on Is the BSA "Grace Period" a Scam? · · Score: 2, Interesting

    forgot to mention. when bsa busts somebody they like to make the point as much as possible to make sure everyone knows they mean business so you'll see press releases like this:

    http://www.bsa.org/usa/press/newsreleases//2003- 01 -26.1439.phtml?type=policy