Slashdot Mirror


User: bloo9298

bloo9298's activity in the archive.

Stories
0
Comments
198
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 198

  1. Re:Windows exploitation? on Hacking: The Art of Exploitation · · Score: 1

    Shellcoder's Handbook?

  2. Re:That isn't sufficient. on Army to Require Trusted Platform Module in PCs · · Score: 1

    The access checks are made on other computers that communicate with the system that has a TPM.

  3. Re:Of course, again? on Should We Be Afraid of TPM Chips? · · Score: 1

    There's nothing to stop one from having an OS that allows you to add drivers. But whether anyone else chooses to trust attestations made by programs running on that OS is another matter entirely. I certainly wouldn't trust your OS with your drivers to obey a policy on data that I give to you, unless you can give me some proof that your OS and your drivers will not violate the policy that I ask you to enforce before handing you the data.

  4. Re:Of course!!!! on Should We Be Afraid of TPM Chips? · · Score: 1

    I don't think we have the same view here. Whether you run Linux, Windows, or OS XI doesn't make a difference. You will not be able to fake attestations (that other people believe) unless you can extract the private endorsement key.

    Bear in mind there are two things that you could dislike about TPM. The first is attestation which affects whether programs on other machines will trust you (based on the data in the attestation). The second is sealed storage, which could store data on your system that you can't recover if you run a program/OS that lets you create such ciphertext.

  5. Re:See for yourself on Should We Be Afraid of TPM Chips? · · Score: 1

    From that article:

    The TPM stores three important keys in non-volatile memory. The endorsement key is a 2,048-bit RSA public and private key pair, which is created randomly on the chip at manufacture time and cannot be changed. The private key never leaves the chip, while the public key is used for attestation and for encryption of sensitive data sent to the chip, as occurs during the TPM_TakeOwnership command.

    The endorsement key pair is the interesting one. No, you don't get the private component of the endorsement key pair, because that would make the attestation capability have no global meaning.

  6. Re:Mortgage your house... on What's the Best Way to Write a Business Plan? · · Score: 1

    Thanks!

  7. Re:Mortgage your house... on What's the Best Way to Write a Business Plan? · · Score: 1

    Do you have a link that says anything more about this?

  8. Re:Because it makes things work. on UNIX Security: Don't Believe the Truth? · · Score: 3, Informative

    Ask and ye shall receive: Keith Brown's Hall of Shame.

  9. Re:Lightning? Not The Result of Global Warming on Puzzling Electric Hurricanes · · Score: 5, Funny

    Aliens? That's silly. Don't worry, Pat Robertson will no doubt explain why the lightning occurred soon enough.

  10. Re:Secret Service? on Marriott Discloses Missing Data Files · · Score: 1

    Their mission includes:

    The Secret Service also investigates violations of laws relating to counterfeiting of obligations and securities of the United States; financial crimes that include, but are not limited to, access device fraud, financial institution fraud, identity theft, computer fraud; and computer-based attacks on our nation's financial, banking, and telecommunications infrastructure.
  11. Re:appliance on A Dedicated Firewall for a Small Town? · · Score: 1

    Cough, bounded memory.

    Just kidding. :-)

  12. Re:Such News!! on Hacker Team Releases First 360 ISO · · Score: 1

    Go ahead and try it. It will fail. When you accept that you misunderstand what's going on, read "CD Cracking Uncovered" or similar.

  13. Re:Web Based Scanning Won't Cut It on Symantec Hopes To Deliver Anti-Virus Online · · Score: 1

    Really? I have never been infected with a virus, and I don't bother with anti-virus software. Yes, I do use Windows, but I monitor the system myself and run code in sandboxes when I deem it necessary.

  14. Re:The Slowness Of Java on Quake2 Ported to Java, Play Via the Web · · Score: 1

    Um, no, he's talking about Windows. I fall on the side of Java over C/C++ for most purposes, but Azureus really does perform abominably on Windows.

  15. Re:if it ever gets working on A Skype Equivalent Without "Big Brother"? · · Score: 1

    Tsk. Useless use of "cat"!

  16. Re:The children will ask themselves on The Prodigy Puzzle · · Score: 1

    You're so smart? You figure the solution out!

  17. Re:Java failing? on PHP Succeeding Where Java Has Failed · · Score: 2, Insightful
    It's not quite clear from the article where Java is failing.

    On the contrary, the article makes it very clear: Java is failing to provide income for Marc Andreesen.

  18. Re:Which Platforms? on Common Malware Enumeration Initiative · · Score: 1

    Because no-one of any consequence runs Linux, MacOS, or a BSD? ;-)

  19. Re:It works both ways, but it's worse for MS on No Defense Against Windows Rootkits? · · Score: 1

    The parent poster should be modded up. They have pointed out that turning off loadable kernel module support gives a false sense of security. It is still possible for an attacker, running as root, to modify kernel memory using /dev/kmem. The underlying problem is that access control is too coarse on both UNIX and Windows. SELinux is much better in this respect, but one could still wish for more.

  20. Re:the defense of liberty on London Tube Dangerous for Technophiles? · · Score: 2, Funny

    Perhaps it would help to combat the obesity epidimic if nobody could hide their rolls of flab!

  21. Re:Target audience, Target audience on The UMD and PSP Getting Off The Ground · · Score: 1

    Take him outside to run around?

  22. Re:GIF? on Lockheed Chosen For Electronic Records Archives · · Score: 2, Interesting
    The corporate Disney that we know today should not diminish the work of one of the 20th century's greatest imaginative minds.

    I agree, Walt was much more evil than corporate Disney. Credit where it's due.

  23. Re:Missing Poll Option: vegetarian on New Mad Cow Test on the Horizon? · · Score: 1

    Perhaps, but cutting it a bit fine.

  24. Re:I think you mean... on Spyware Maker Indicted on Hacking Charges · · Score: 1

    Stop appealing to the least common denominator.

  25. Re:knowledge is power on New Round of P2P Lawsuits from Hollywood · · Score: 2, Funny

    Oh, they're already working on the "Open Sauce" porn series. Eric Raymond is up first, with some transexuals and hermaphrodites. The title is the "The Bazaar and the Bizarre".