Slashdot Mirror


User: Zeinfeld

Zeinfeld's activity in the archive.

Stories
0
Comments
3,931
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 3,931

  1. Only it will automatically update itself unless you stop it.

  2. Can anyone help fix my end-to-end encryption? on Google Proposes Changes To Chromium Browser That Will Break Content-Blocking Extensions, Including Various Ad Blockers · · Score: 1

    This is irritating as it upsets my plans for end-to-end Web encryption. By which I mean encryption of the data on the server so that the server has no access to it. The only things that are on the server are encrypted data blobs and a pile of random numbers.

    By end-to-end Web I mean that you will be able to set up comment forums like slashdot, read email in a Web browser and everything else you are accustomed to doing on the Web but without any of the plaintext content being accessible to the server.

    The technical basis for this scheme was worked out in the 1990s and then patented by a completely unrelated company which merely sat on the patent till it expired last year. It uses meta-cryptography which is a property of the Diffie Hellman schemes that if you add two private keys, the corresponding public key is the product of the public keys, etc. Matt Blaze, Torben Pedersen and others worked out how to apply these effects to achieve an effect they considered interesting but insufficient. My contribution is merely to show that the simple scheme is more than enough to do interesting things.

    So now I need to work out how to hook into the browser. One possibility is to present the decryption module as a new compression scheme. It looks like a compression scheme in other respects. It just requires the host to have access to a private key capable of completing the decryption.

    Any help would be appreciated: hallam@gmail.com

    The project site is mathmesh.com but that is of the previous approach which has been superseded in the reference code but not yet documented.

    [Oh and yes, I do know what I am doing sort of, I have probably considered the corner case you have just thought up. This has been in discussion for many years with serious protocol design people.]

  3. Re:doh! on FBI Finds 14,900 More Documents From Hillary Clinton's Email Server (go.com) · · Score: 2, Informative

    Obama didn't release his birth certificate for one very good reason, he is very clever and Trump is very stupid.

    The fact is that the Republicans will always invent some crazy idiotic 'scandal' that they obsess about and endlessly throw up smoke. The birther conspiracy was mind numbingly ridiculous. It would require someone to go back in time to plant the birth notice in the papers. Or for some group of conspirators to go to an enormous amount of trouble in order to make a particular black kid president.

    So rather than release the birth certificate and let the Republicans invent a new scandal, Obama held onto it and let them obsess about a scandal nobody else thought made the slightest sense, knowing that he could knock their house of cards down any time he chose. Which of course he did a week before the Bin Laden raid which was guaranteed to end the story.

    George W. Bush opened torture chambers across the world and collected photographs for a sick sexual thrill. Yet nobody ever talks about that. None of the people complaining about Hilary ever complained about GWB refusing to comply with Congressional investigation or the deletion of 5 million emails.

    So here is what is going to happen. Trump is going to go down to the biggest defeat since Carter and he is going to drag the rest of his party down with him. And afterwards there is going to be a new civil rights act that prohibits Republican voter suppression tactics and the gerrymandering that give them a 5% advantage in elections. And by the time it is all done the Republican party will have two choices, either boot the racist conspiracy theorists and Trumpists out or face two decades in the wilderness.

  4. Re:Wny did they need the certificates? on Google Threatens Action Against Symantec After Botched Investigation (itworld.com) · · Score: 1

    Issuing for .test and .local are strictly prohibited by the CABForum EV requirements. They will soon be outlawed for DV under the basic requirements.

    What seems to have happened is that instead of issuing all test certs for test.verisign.com as the procedure manual required, they had to modify the procedure when Symantec took over and they no longer had verisign.com.

    So instead of doing what they should have done and using test.symantec.com or a test domain bought for the purpose, they typed the first name that entered their head.

  5. Actually it doesn't. DANE certificates are not self-signed for a start, they are signed by the DNSSEC key for the zone.

    The problem with DANE is that you swap the choice of multiple CAs for a monopoly run by ICANN, a shadowy corporation that charges a quarter million bucks for a TLD because that is what the market will bear. What do you think the price of DANE certification will rise to if it takes off?

    ICANN is the Internet version of the NFL only with greater opportunities for peculation and enrichment.

  6. Re:Wny did they need the certificates? on Google Threatens Action Against Symantec After Botched Investigation (itworld.com) · · Score: 1

    Damn right they should. The CPS has a long section on the use of test hardware.

    The problem is that all the original team that built VeriSign have been gone for years. A lot of us left before the sale of the PKI business to Symantec. The PKI/DNS merger was not a happy or successful partnership. The original point of the merger was to deploy DNSSEC. that effort was then sabotaged by folk in IETF and ICANN which has delayed the project by at least 10 and possibly 20 years. ATLAS was originally designed to support DNSSEC.

    Unfortunately, in PKI terms what VeriSign was to IBM, Symantec is to Lenovo.

    They apparently remember the ceremonies we designed but not the purpose. So they are going through the motions but not the substance.

    One of the main criticisms I have heard is that we built the system too well. From 1995 up to 2010 it worked almost without any issues. So people decided that they didn't need things like proper revocation infrastructure. The only recent issue the 1995 design could not have coped with was DigiNotar which was a complete CA breach.

    There are some developments on the horizon in the PKI world that will help add controls to mitigate some of the issues arising since. But those depend on cryptographic techniques that won't be practical for mass adoption till we get our next generation ECC crypto fully specified.

  7. Re:What is a pre-certificate? on Google Threatens Action Against Symantec After Botched Investigation (itworld.com) · · Score: 3, Informative

    A pre-certificate is created for use in the Certificate Transparency system. Introducing pre-certificates allows the CT log proof to be included in the certificate presented to an SSL/TLS server.

    The CT system generates a proof that a pre-certificate has been enrolled in it. The proof is then added to the pre-certificate as an extension and the whole thing signed with the production key to make the actual certificate.

    If the CT system logged the actual certificate, the proof of enrollment would only be available after the certificate had been created.

  8. Re: Not quite true on UK Hotel Adds Hefty Charge For Bad Reviews Online · · Score: 1

    Whether the term is enforceable or not is debatable and almost certain to be rendered moot. Unlike US Republicans, UK Conservatives do actually believe in the rule of law and honest business practices (sort of). There isn't any party who believes that screwing the consumer is a constitutional right. There will be a bill passed.

    A rather more direct question is whether the hotelier was entitled to collect the charge under the credit card agreement. And that is unambiguous, he isn't. A credit card merchant cannot use a charge card to recover a disputed charge. It does not matter what the purported contract term was or if it is enforceable. The credit card agreements are designed to prevent cardholders from dishonest merchants. So the consumer will get their refund and the hotelier will find themselves facing a 30 quid chargeback fee.

    The only option for the hotelier to recover would be to take the matter to court. The most he could win is the hundred pounds, if he lost he would likely be out the legal costs which could be a couple of thousand. Small claims courts don't usually award costs but they might well do so in this case. Judges tend to detest bullies.

  9. Re: Ask the credit card for a refund on UK Hotel Adds Hefty Charge For Bad Reviews Online · · Score: 1

    Its more than that, without regulation you end up with a lemon-law market.

    Lots of times the difference between an honest product and a dishonest one only becomes apparent years later. If the product is safety equipment you only find out if the hard hat works when someone drops the brick on your head.

    The libertarian theory that self interest will drive people to make honest products has turned out to be utterly false. In fact it turns out to be quite difficult for a company that intends to do the right thing to do so. I once had to get a guy fired after I found he had goosed his response rates for customer support calls by deliberately setting the phone tree up as a maze.

    People do all sorts of idiotic short sighted stuff. This hotelier for example got his pants in a twist over a bad review and now he has probably sunk his business completely.

    Rational choice is not an empirical fact of human behavior. It is a modelling assumption that tends to give good results in certain cases. But it does not hold for corporations because the interests of the corporation are not identical to those of the employees. All those banks who go belly up because the traders get big rewards for raking in profits and face no consequences for a loss. I don't gamble with my own money but if you want to give me $100,000 to gamble with I am happy to take it to Vegas, find a roulette wheel and let you take 100% of any losses and 90% of any gains.

  10. Re:Build refineries in ND on Obama Delays Decision On Keystone Pipeline Yet Again · · Score: 1

    There is plenty of capacity in St Louis and room to build more.

    The cost of the pipeline is much more than the cost of a refinery. The 'surplus capacity' claim is total nonsense. The tar sludge isn't anything like the crude that the existing refineries process. There would have to be major upgrades in any case. And building a two thousand mile pipeline costs a heck of a lot more than any refinery would.

  11. Re:after november... on Obama Delays Decision On Keystone Pipeline Yet Again · · Score: 1

    The decision was made years ago: No pipeline.

    Not announcing the decision stops the Koch bros and the Keystone corp from starting their appeal. Its like an administrative filibuster.

    There is already a pipeline that runs to St Louis, the only reason to build the second pipeline is to sell the sludge to China. Having that option available will allow the price to be jacked up when the sludge is sold to the US market as it will fetch the international price which is a lot higher than the refiners currently pay in St Louis.

    There is absolutely no reason for the US to OK a pipeline that will increase the cost of supply to the US market. The only reason the GOP backs the pipeline is that the Koch bros stand to make $100 billion from the increase in the value of their shale tar sands.

    It is a purely tactical decision because nobody outside the GOP wants the pipeline built. Everyone who wants the pipeline will vote GOP in November whatever the decision. Obama could make a short term political gain by announcing that there will be no pipeline but that would allow the appeals to start. Better for the country to wait until there have been some GOP deaths on the SCOTUS.

  12. Re:Control vs. Prosperity on A Strategy For Attaining Cuban Internet Connectivity · · Score: 2

    What I find problematic with that mode of argument is that it tends to turn McCarthyite very quickly. Castro attempted to cut a deal with the US before going to the Soviets, he is rather less committed to communism than either his supporters or his opponents believe. He also gave the CIA the location of Che Guavera when he decided he was a liability. So there has been a basis for cooperation for a long time.

    The list of crimes committed by US Presidents panicking about communism is very long. Snuffing out a democracy in Iran to replace it with a bloodthirsty dictator, supporting the Khumer Rouge after Vietnam ejected them, installing Pinochet, a mass murderer in Chile. George W Bush just managed to cause the deaths of a half million Iraqis and wonders why he isn't being praised for his efforts.

    The problem isn't capitalism of communism, the problem is authoritarianism and elites who believe that brute force is the solution to every problem. Castro is a thug and a murderer but its the US who set up a torture chamber in Cuba.

    Since the US government has been spending a large amount of money to get the Internet into Cuba, giving them a pipe and letting them rip with it seems like the best way forward. They will try to control it but everyone knows that Cuba is going to liberalize in the near future.

    The logical way forward would be for the US to lift the blockade and let the commerce flood in. The communist system would collapse pretty quickly when there was money to be made. But the problem is that there is a faction that is less interested in bringing democracy to cuba as returning their assets that were nationalized. Since they stole the assets under the corrupt Batista regime, there aren't going to be many interested in that happening.

  13. Re:Tor on Utopia, Silk Road's Latest Replacement, Only Lasted Nine Days · · Score: 1

    The Dutch government is very clear about not being a haven for drug dealers shipping to other countries. Unlike the US police, they don't spend time going after domestic pushers or users. But anyone who is shipping through the Netherlands to another country is in for serious grief.

    >Hmm... perhaps their mistake was even dumber than simply believing tor is magic.

    Magical thinking is very common in security. Lots of people think BitCoin is anonymous despite the fact the transaction log is public.

    Call Tor services 'hidden' and some people think that means the NSA and GCHQ can't find them. Call them the 'dark Web' and they think its protected by Professor Dumbledore himself.

  14. Re:The Surprised Dutch Prosecutor on Utopia, Silk Road's Latest Replacement, Only Lasted Nine Days · · Score: 1

    No, Tor is not compromised. Tor isn't really designed to protect the privacy of Web Sites. Tor is designed to protect the privacy of Web Site users.

    If you have a server that is visible to any client on the Tor network then either the server IP itself must be visible to an exit node put up by Law Enforcement or an intermediary node that is directly conspiring with the server has to be visible to law enforcement.

    That is just a basic limitation of onion routing. A client can hide because it gets to choose the entry node. A server can't hide because anyone can set up an exit node.

    This illustrates one of the big problems with computer security, people want to believe that security claims are true so they tend to be very gullible. They often rely on claims being made about a product by people talking about it on Web sites rather than the people who built it. And note I said 'rely'. Taking note of someone saying 'steer clear, this is why' on a Web site is very different to following the advice of people playing the pied piper.

    There are lots of people who are convinced that Bitcoin is anonymous. This despite the fact that every transaction is public and every wallet tracks every one of them. The BitCoin people don't like hearing that their scheme might not be the future of currency or that it really isn't very different from e-Gold or GoldAge or Liberty Reserve which the FBI had no trouble rolling up. Take a look at the comments on my Bitcoin podcast, not a single substantive comment from a BitCoin supporter. Just a regurgitation of the ideology as fact:

    http://www.youtube.com/watch?v...

    I think this is coming close to the endgame for BitCoin. The FBI might be nervous about the influence that the Winkelvoss twins and other rich supporters of BitCoin might be able to buy (but Senators probably don't take bribes/campaign contributions in Bitcoin). So the logical tactic to make them radioactive would be to arrest them too.

    Funny how an ideology that holds the government is an oppressive freedom destroying force can be self-fulfilling. But Bitcoin can't possibly survive when LE believes that the vast majority of Bitcoin transactions involve drugs or kiddie porn or gambling. And I see no evidence to the contrary.

  15. Re:Windows keys? on Stop Trying To 'Innovate' Keyboards, You're Just Making Them Worse · · Score: 2

    Symbolics machines had the key well before Microsoft even talked about ripping off DOS

    The serviceable 16 bit CP/M clone was the Holy Grail for every geek in his garage who saw the potential of the 8086. What the geek didn't have was a full suite of programming languages ready to port and the resources to build on the launch of the new IBM micro,

    Except Gary Kildal who famously refused to sign the IBM NDA on the advice of his wife going surfing instead. Microsoft then bought MSDOS 1.0 from one of said garage geeks. But all they needed it for was to be undetected long enough to be able to sell MSBasic while they worked on a clone.

    The Windows key was appearing on DEC keyboards before it was a Windows thing. And that is from Symbolics as many of the DEC engineers were Symbolics graduates. And when DEC crashed, Microsoft bought up most of the talent. Given the state of Apple at the time, it was pretty much the only option if you hated UNIX.

    I am surprised that nobody has brought up a pathetic piece of bought-by-lobbyists research 'the fable of the keys' written by a couple of K-street hacks for an organization calling itself 'the independent institute'. This tried to claim that path dependence and network effects don't exist. Microsoft funded the 'study' while they were fending off the anti-trust suit.

    One of the examples that the authors tried to expose as 'myth' is that Dvorak was more efficient. And they do actually have some evidence to suggest that the studies on efficiency are unreliable. But that does not prove their case. All it actually shows is that the Navy realized that there was no point in performing further tests because they were not going to switch from Qwerty regardless of what the result was. A 10% improvement in typist productivity was not worth the cost of retraining. Many typists would refuse to be retrained. Nobody would want to learn a keyboard that was only used in the Navy under a program that might be cancelled at any moment.

    The same goes for their effort to 'prove' that VHS was better than Betamax. Like the idiots trying to disprove evolution, they don't make their case and all they do is to show that things are a little more complex than the naive version of the theory they are attacking suggests. The point of VHS and Betamax is that what made a VCR better than a competitor was not picture quality, it was how many movies you could buy and watch on it.

  16. Re:Fuck religion. on US Justice Blocks Implementation of ACA Contraceptive Mandate · · Score: 1

    The "separation of church state" works both ways.

    You don't like religions dictating how your government is run? The price to be paid for this is not having your government dictating how religions operate.

    LK

    Since the Catholic church under Benedict threatened to excommunicate Kerry for supporting abortion, they are clearly not holding up their end of any bargain.

    It is completely consistent to insist that no law be made based on or requiring religious observances and that what religion is permitted be regulated by the state. The price religion has always paid to be allowed to operate is to obey the laws of the land and support the government order.

  17. Re:hypocrites on US Justice Blocks Implementation of ACA Contraceptive Mandate · · Score: 1

    Religious organizations invented many ways of parting gullible rubes from their cash.

    It wasn't until the mid 1800s that medics came close to saving more patients than they killed. And that was because of the introduction of science and the scientific method.

  18. Re:Fuck religion. on US Justice Blocks Implementation of ACA Contraceptive Mandate · · Score: 1

    Semantics is a Greek word. It means 'meaning'.

    So if you are fine with just debating meaning...

  19. Re:Fuck religion. on US Justice Blocks Implementation of ACA Contraceptive Mandate · · Score: 1

    The catholic church wants to be able to deny coverage to their "secular" employees on the religious grounds.

    Wrong - specific coverages are denied, and for obvious reasons. Employers can pick and choose what they will and will not provide to their employees, as is their right. Nobody as a "right" to free contraception.

    Employers are required to provide coverage under the ACA. It is a requirement not an option so they don't get to choose what they provide, end of story. In the future they will be required to provide coverage for abortions. Tough noogies.

    Religion is a control freak thing and becoming a priest is a great way to get your rocks off telling other people what to do based on some tendentious reading of the history of a guy who never existed.

    The catholic church can not dictate how an employee can spend their pay check and they shouldn't be able to dictate what health care options the employee uses.

    No one is stopping those employees from purchasing their own health insurance, or from refusing to join in their employer's insurance plan. No one is stopping those employees from buying their own damned pills or rubbers - considering that both are cheap enough, I fail to see what you're so agitated about.

    Nobody requires the Catholic church to run a business taking public money to provide social services. I would prefer that they stopped and the services were provided by secular organizations. Getting the church out of adoption policy was a good thing. I look forward to their other social programs shutting down. There is no shortage of secular organizations doing the same work without tying the effort to a religious recruitment drive.

  20. Re:Fuck religion. on US Justice Blocks Implementation of ACA Contraceptive Mandate · · Score: 2

    I think pretty much every employer would prefer not to be involved in health care. It is a stupid system. But the reason that it was necessary is that insurance does not work when the insurer knows the individual risks. The individual insurance market began to collapse in the 1980s.

    The only way to save the insurance model is with a mutual mandate, insurers have to be mandated to cover everyone who applies, including those with pre-existing conditions and individuals have to be mandated to buy insurance. Which is what the ACA does for the individual market.

    Employer based coverage worked because the pools were big enough to spread the risk. But they only worked for employers with a large enough number of employees. Which was a huge drag on the economy. People could only work for a high risk startup if it was adequately funded enough to provide full benefits or if the employees had insurance through their spouses.

    The only way to get the ACA passed though was if people who already had insurance were assured that they wouldn't lose it. Many people have subsidized insurance built into their employment package and would lose substantially if that happened. Which is why the ACA has big tax penalties for employers who drop coverage and requires the coverage to meet certain minimum standards.

    The idea that employers have a right to impose their religious beliefs on their employees should make anyone who actually believes in freedom of religion puke. But the republican party has a feudal view of society in which employees are mere serfs to their employers. I think it will hurt them in 2014 and 2016 though because women really don't wan't little Ricky Santorum getting his rocks off by controlling their access to fertility control.

  21. Re:Fuck religion. on US Justice Blocks Implementation of ACA Contraceptive Mandate · · Score: 1

    Since the Democrats held the House, Senate and White House when the ACA passed, gerrymandering was not an issue. The filibuster was an issue because the Republicans were corruptly preventing Al Franken taking his seat.

    The Republicans are the party complaining about the ACA and they only hold the house and that only due to gerrymandering. So they don't have the ability to change the law because they don't have a democratic mandate despite holding one house of Congress.

    The filibuster is gone now so it won't be an issue in future. While the rules have not been changed for legislation or SCOTUS appointments, there is no doubt that they will be if either party ever gets control of the house, senate and WH. Since the democrats are close to being the only party that can win the WH under the current electoral college arrangement, that means any change would come from the Democrats. But the forcing function here was the Republican's threat of the nuclear option under Bush. Once the threat was made, the end of the filibuster was inevitable.

  22. Re:Fuck religion. on US Justice Blocks Implementation of ACA Contraceptive Mandate · · Score: 1

    Nobody is saying that the Republican's didn't have the right to obstruct

    What they don't have the right to do is to obstruct the bill and every attempt to make technical amendments and then complain that there wasn't time to debate it properly or protest about problems the Democrats have tried to fix.

    The US has universal healthcare no, so seven million people will get healthcare. Boo-fucking-hoo republicans. Your mental masturbation sessions will not be quite so sweet today when you can no longer enjoy the fact that millions of poor people will die early because your party denied them care.

    Having derided the ACA as 'Obamacare' you have now ensured that one of the main pillars of the US welfare state will be named after a Black man who was elected President. A permanent reminder that the Southern Strategy of pandering to racism and bigotry failed.

    There is only one way to avoid that outcome being permanent and that is to allow Hilary to replace Obamacare with the much simpler public option that would also be cheaper.

  23. Re: Fuck religion. on US Justice Blocks Implementation of ACA Contraceptive Mandate · · Score: 1

    Yeah, it stopped that civil rights bill, can't have black men voting, next thing you know it a black man will be President.

    Republicans don't believe in democracy, they try to 'win' elections by stopping black people voting to this day. And they arrange to have the broken voting machines in Democratic precincts.

    Congress had more than enough time to debate the ACA. The Republicans were never interested in discussing the implementation and they still aren't interested.

    In this particular case there should be no religious exception whatsoever. There should be a super tax on the Catholic church and the money go to pay for free abortions.

  24. Re:Unequal treatment on Ulbricht Admits Seized Bitcoins Are His and Wants Them Back · · Score: 1

    You clearly don't understand the US civil forfeiture laws then. Yes they can and yes they do.

    There are certainly corrupt uses of the civil forfeiture laws but this is not one of them. The coins were seized from a rig operating a market for illegal drugs.

    There are cases where the cops have performed seizures on no evidence at all and no indictment.

  25. Re:Seize on Ulbricht Admits Seized Bitcoins Are His and Wants Them Back · · Score: 2

    I suspect the bitcoins in question were 'live' on the servers during the raid.

    Running a marketplace means that the servers have to be able to move money about. So the servers have to have access to keys for spending to perform some operations. So the keys have to be accessible to the machine just like pretty much every web server with SSL has a private key that is effectively unencrypted. Sure it might be encrypted under a password but the password is no the same machine.

    If he has $30m on the live systems I suspect he had even more stashed away offline. Begging for his money back is probably more of a ploy to try to throw the investigators off the chase for the rest of his cash.

    The problem he is gonna have is that he is facing a 20-40 year jail term without parole. So the chance that he will be able to actually cash out his wallets before the bitcoin bubble bursts is essentially zero.

    The fed have been shutting these schemes down continuously. Bitcoin is merely the latest incarnation of the old 'gold backed currency' that has been running for 15 years. The feds let them run for three years on average before they shut them down.

    And before folk explain why bitcoin is different, all the previous schemes claimed to be different as well. And they all claimed to be beyond the reach of the law.