Slashdot Mirror


User: philip.paradis

philip.paradis's activity in the archive.

Stories
0
Comments
1,023
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,023

  1. Re:Somebody please explain... on In Letter To 20 Automakers, Senator Demands Answers On Cybersecurity · · Score: 1

    Maybe it's an erroneous interpretation of the acronym TPMS, which is supposed to mean tire-pressure monitoring system. Alternately, it might be some new term meant to introduce tire pressure as a third metric for standard monitoring, in addition to oil and brake fluid pressure levels.

  2. Re:I hope on In Letter To 20 Automakers, Senator Demands Answers On Cybersecurity · · Score: 1

    Sure you could. Heck, an astronaut has even proven the technology works great for long road trips.

  3. Re:Are they really being hosed? on Spotify's Own Math Suggests Musicians Are Still Getting Hosed · · Score: 0

    Yes, over the scale of human history, three hundred years would indeed qualify as "recent." Reference Paleolithic flutes dating back 40,000 years. What was your point again?

  4. Re:Never underestimate the bandwidth on How the LHC Is Reviving Magnetic Tape · · Score: 1

    Phoenix offers advantages beyond temperature, which isn't nearly the problem you think it is for the multiple major datacenters operating in the area. As an example, see the low risk location page for PhoenixNAP. This really doesn't have anything to do with golf.

  5. Re:What RMS has in mind ? on RMS Calls For "Truly Anonymous" Payment Alternative To Bitcoin · · Score: 4, Funny

    Besides, who will accept so much cash if he's not allowed to put it on a bank account afterwards?

    I'll gladly accept it.

  6. Re:Tried to Sign Up, Already Frustrated on Officials Say HealthCare.gov Site Now Performing Well · · Score: 1

    A consultant, eh? I've run a consulting firm of my own. I'm not talking about my company in particular, either. Instead, I'm referring to the great many places I've seen both good and bad password management practices being employed. The difference between us in reference to the latter case is the fact that I've helped people find simple tools that would solve simple problems like these, thus preventing further issues down the road.

    It's disturbing that you would attempt to use your work history as a consultant to reinforce (yet again) acceptance of bad information security practices. Perhaps your clients needed someone a bit more informed to help those in the trenches, and it makes me wonder what other bad practices you've spread around over the years.

  7. Re:Tried to Sign Up, Already Frustrated on Officials Say HealthCare.gov Site Now Performing Well · · Score: 1

    Oh, the real world? Would that be the real world where multiple floors worth of offices at a company have employees using sound password management practices, frequently utilizing tools just like the ones I and others have pointed out?

    Listen to yourself. You're trying to cover up for your own inability to take simple information security measures with baseless appeals to your imaginary view of what the world is like. You are dispensing security advice by attempting to continue to push that view, essentially making the case that it's perfectly normal and reasonable to continue doing stupid things because, hey, you do those stupid things.

    Maybe the people around you share your attitude, but I assure you it isn't universal. So now you have a choice: either continue being ignorant and lazy, or do something useful with yourself and help those around you as well.

  8. Re:Tried to Sign Up, Already Frustrated on Officials Say HealthCare.gov Site Now Performing Well · · Score: 1

    Based on comments like yours, you're not not a normal human being. You are a lazy human being. Normal people might ask "gee, how might I solve this problem?" Instead, you're adopting the "oh no, it's too hard" attitude.

    I've been working with normal people who manage to memorize multiple passwords for fifteen years. They aren't programmers, either, although some people are naturally better at this than others. For those who have a lot of passwords to manage, there are a wealth of options available, including things like KeepPass, Password Safe, and many others. There are "local only" options, online options, portable options, etc.

    Again, your fundamental problem is that you're lazy, and you're encouraging others to be lazy and adopt terrible security practices. Stop dispensing security advice, and stop attempting to speak for what others can or can't handle.

  9. Re:Tried to Sign Up, Already Frustrated on Officials Say HealthCare.gov Site Now Performing Well · · Score: 1

    It just so happens that I use one of those characters in my standard secure password.

    Why are you using the same password (or even very similar passwords) on multiple sites, especially for sites that involve sensitive personal healthcare and financial data? Are you aware that this very practice is the source of greatly increased rates of personal information compromise and identity theft, as compromising one set of credentials makes it much easier to access other systems? Further, are you aware that you're rolling the dice every time you create an account anywhere when it comes to whether the password you supply will even be properly hashed? Have you managed to entirely miss the nastier cases involving large organizations storing passwords in plaintext, or using deeply flawed hashing measures (outdated/weak algorithms, failing to use salt, etc) that fall to analysis within seconds?

    With practices like yours, why are you dispensing security advice?

  10. Re:Alternatives to Flash? on New Windows XP Zero-Day Under Attack · · Score: 1

    The GP asked about vector animation, not embedded video. These are different things; you can make videos of vector animations, but you can also have vector animations presented and controlled as fully accessible trees of objects in the DOM. Why are you talking about videos?

    It's worth noting the GP's response to your post is quite accurate, however.

  11. Re:Alternatives to Flash? on New Windows XP Zero-Day Under Attack · · Score: 1

    Flash is on its last legs. You need to start moving to HTML5 based solutions. A Google query for "HTML5 animation editor" will yield a wealth of options.

  12. Re:To hire specific people on Ask Slashdot: Why Are Tech Job Requirements So Specific? · · Score: 1
  13. Re:Ghost transactions on 195K Bitcoin Transaction · · Score: 1

    Quoting the original text:

    Was this transaction really intended to be secret? "Leaking" the identity seems like a positive PR move for the exchange

    I don't think the poster was intending to imply that BTC transactions are anonymous. In reply to his/her post, reiterating the oft-missed point that the protocol has no design attributes intended to enforce anonymity isn't splitting hairs; it's more a conversational response referencing the GP above that post. Also, an entity doesn't have to directly link itself to BTC transactions to be revealed as a participant, given sufficient analysis of all transactions. 1-1 transactions don't do much to frustrate traffic analysis, either. These are points that other posters have made, and you have missed.

  14. Re:Ghost transactions on 195K Bitcoin Transaction · · Score: 1

    Please read what I said again, and then read the rest of the thread beneath that comment.

  15. Re:Quiz? on Indonesian Politicians Plan To Quiz Snowden Following Visit By Russians · · Score: 3, Interesting

    and in fact he didn't since he wasn't planning on his destination being Russia

    Prove it. It's likely he had a number of eventual destinations in mind, unless he's a complete idiot, which he doesn't appear to be.

    why hold on to something that gives the USA reason to assassinate you and Russia reason to torture it out of you

    This demonstrates extremely thin understanding of the conditions under which it would be useful to torture someone, and of the actual information that could be gained as a result.

    as well as a matter of ensuring that info would be able to get out

    There are many ways of ensuring information gets out in the event of your demise. Reference "dead man's switch." Cheers.

  16. Re:another day on Route-Injection Attacks Detouring Internet Traffic · · Score: 1

    Roger that (pun intended, if my guess is correct). Thanks for the backup; it's a bit unsettling how many people are taken seriously on topics like these when they don't actually know what they're talking about. Oh well, I suppose we get what we get.

  17. Re:Quiz? on Indonesian Politicians Plan To Quiz Snowden Following Visit By Russians · · Score: 4, Interesting

    Snowden no longer can be given credit for anything; He released everything he stole months ago.

    A finite, but as of now undetermined, amount of data was conveyed to journalists. I am keenly interested in seeing objective proof that the sum of those disclosures is equal to the sum of all information in his possession. If you're planning on using Snowden's public statements in support of your view that everything he has is already in someone else's hands, I suggest you consult the dictionary for the definition of "naive."

    I served in the United States Navy as a submariner, and I've been rather intimately involved with communications networks since around the age of eleven. You might be surprised to learn that I applaud Snowden's revelations regarding pervasive NSA surveillance of American citizens at home, abroad, and in interaction with allied nations. I doubt you have the depth of experience or context to fully appreciate why I applaud it, though, given your choice of the word "stole" to describe the materials in question. I prefer the term "returned," or perhaps "disclosed," as in "disclosed to the American people what their government had been doing in violation of their own Constitution," a document I swore an oath to uphold and defend against all enemies, foreign and domestic. Again, I doubt you truly understand what that means.

  18. Re:Quiz? on Indonesian Politicians Plan To Quiz Snowden Following Visit By Russians · · Score: 5, Insightful

    Given Snowden's background, it doesn't seem he has issues with divulging information. As part of fleeing to Russia, I'm certain he understood that he would have many conversations with many interesting people. I hardly think any sort of "working over" will be necessary in this case.

  19. Re:Ghost transactions on 195K Bitcoin Transaction · · Score: 4, Insightful

    Indeed on all points, and I'm still trying to figure out why people keep making the assumption that identity protection or obfuscation measures of any sort are part of the protocol. Maybe it's the "crypto" part of "cryptocurrency" that causes some kind of automatic correlation, although if that were the case one would think that the widespread use of cryptographic mechanisms for identity verification might encourage the opposite assumption.

  20. Re:Ghost transactions on 195K Bitcoin Transaction · · Score: 4, Insightful

    I don't understand why people keep assuming Bitcoin is designed to be anonymous. It isn't.

  21. Re:another day on Route-Injection Attacks Detouring Internet Traffic · · Score: 0

    I'll expand upon my last comment a bit: if I had a dollar for every time I've heard the expression "I'm an expert at [insert thing here]" from someone who has the benefits of age and allegedly tons of experience with [insert thing here], and I subsequently have to fix whatever busted server/network/software config was put in place by the "expert," I'd be a wealthy man. Instead, at 32 I've learned that assumptions about competence should never be made based on things like UIDs. You can hope someone who has been in a field for a while knows what he's doing, but you cannot assume it, as you'll simply see that assumption proven wrong too many times and with too many nasty consequences.

  22. Re:another day on Route-Injection Attacks Detouring Internet Traffic · · Score: 1

    Your assumption would be incorrect. Someone existing for a set period of time on this planet is not a reliable indicator of knowledge. That's one of the hardest things I've had to learn in fifteen years of systems work.

  23. Re:another day on Route-Injection Attacks Detouring Internet Traffic · · Score: 1

    You've demonstrated you have no idea how these attacks work, why they're important, or even how BGP itself works.

  24. Re:Fixed-point arithmetic on Ask Slashdot: How Reproducible Is Arithmetic In the Cloud? · · Score: 2

    No worries at all; the intent of my post was to encourage the GP to consult documentation specific to the implied case that the Mathematica developers hadn't considered the problem. I believe your submission was a good one, as it isn't always a guarantee that developers will have considered the implications of floating point calculations in any given codebase. Getting people to think about things is never a bad thing.

  25. Re:WTF? on Ask Slashdot: How Reproducible Is Arithmetic In the Cloud? · · Score: 1

    "Fix the compiler" presumably meaning "change the compiler not to support non-SSE x86 processors" or, at least, "change the compiler not to *default* to supporting non-SSE processors".

    I think this really is the best option, all things considered.