Slashdot Mirror


User: chill

chill's activity in the archive.

Stories
0
Comments
4,651
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 4,651

  1. Re:Ironically on LightEater Malware Attack Places Millions of Unpatched BIOSes At Risk · · Score: 1

    And here is a link to the BIOS simulators (in Flash) for just about every Lenovo BIOS.

    http://service.lenovo.partner-management.com/et.cfm?eid=1437

    Here you can see BIOS settings and get familiar with the layouts. Not sure how helpful it is for security, but it is very informative.

  2. Re: Is there any way to block the use of old ciphe on FREAK Attack Threatens SSL Clients · · Score: 1

    I was thinking server side, for the web server. But yes, you need to ensure every service you provide that uses TLS is properly configured.

    I'm not sure how much this would impact something like SMTP-S or IMAPS, since the connection duration on those types of service is so short.

    The big target is going to be web servers.

  3. Re:Is there any way to block the use of old cipher on FREAK Attack Threatens SSL Clients · · Score: 3, Informative

    Answering myself to preserve the thread.

    It looks like the export cipher suite must be enabled for this to work. So if you didn't turn off old, busted ciphers then you're potentially vulnerable.

    Meh. Set your approved cipher suite and be done with it.

  4. Re:Is there any way to block the use of old cipher on FREAK Attack Threatens SSL Clients · · Score: 3, Interesting

    Yes. http://www.openssl.org/docs/apps/ciphers.html

    The question is does OpenSSL accept the weak ciphers as a downgrade bug even when EXPLICITLY DISALLOWD.

    I haven't seen answered in any of the linked articles so am digging/testing.

    After the last couple of bugs my organization set the explicit cipher/algorithm/has acceptable list. The export ciphers were excluded on purpose from our list.

    SSL Labs https://www.ssllabs.com/ has a recommended list buried in their documentation somewhere.

  5. Re:Typical government official, breaking the law on Hillary Clinton Used Personal Email At State Dept., Possibly Breaking Rules · · Score: 1

    Nope. The devil is in the details as to the nature of the law being violated.

    The difference between a civil offense and a criminal offense are usually defined by the nature of the offense and the punishment assessed. Civil offenses involve violations of administrative matters.

    Read more: http://criminal-law.freeadvice...

  6. Re:Typical government official, breaking the law on Hillary Clinton Used Personal Email At State Dept., Possibly Breaking Rules · · Score: 1

    Palin violated Alaska State Law. Clinton violated Federal Law. Not directly comparable.

  7. Re:Sonic changes at boot-up on Ask Slashdot: How Does One Verify Hard Drive Firmware? · · Score: 1

    SSDs

  8. Re:The Keystone Pipeline already exists on Obama Vetoes Keystone XL Pipeline Bill · · Score: 4, Informative

    Almost.

    The Keystone-Cushing extension (Phase II), running away480-kilometre (300 mi) from Steele City to storage and distribution facilities (tank farm) at Cushing, Oklahoma, completed in February 2011.

    The Gulf Coast Extension (Phase III), running 784-kilometre (487 mi) from Cushing to refineries at Port Arthur, Texas was completed in January 2014, and a lateral pipeline to refineries at Houston, Texas and a terminal will be completed in mid-2015.

    It is only the Phase IV leg, running from between Hardisty, Alberta, and Steele City, Nebraska that wasn't approved. That part crosses the U.S.-Canadian border.

    Obama signed off on the rest (symbolically, I believe, as I don't think it required Federal approval), back in 2011.

  9. Re:Not too surprising on Attention, Rockstar Developers: Get a Talent Agent · · Score: 1

    It makes perfect sense once you realize "RPG" means "Rocket Propelled Grenades" and you're expected to demonstrate proficiency to (or on) the Tier 1 HR drone.

  10. Re: Network layer and education on Ask Slashdot: Parental Content Control For Free OSs? · · Score: 1, Informative

    No. It is usually referred to as "contributing to the delinquency of a minor" and criminal prosecution awaits for whomever supplied the alcohol.

  11. Re:T-1000 in button down shirt on The Robots That Will Put Coders Out of Work · · Score: 1

    You're confusing the T-1000 with ED-209.

  12. Online Manual on Also Hackable: Drive-Through Car Washes · · Score: 4, Informative

    A quick Google search for "laswerwash ip address" and the very first link is a PDF of the LaserWash Owner/Operator manual with LOTS of useful information.

    Things like default IP address, default port, default passwords, command sequences, etc.

  13. Of course... on How NSA Spies Stole the Keys To the Encryption Castle · · Score: 4, Interesting

    Why do you think all the recent cell phones that are rated for classified voice, such as the Sectera Edge and Project Fish Bowl all run VoIP for classified communications?

    Because they know better than to trust the commercial telephone networks and their voice "security".

  14. Re: They never hire for these jobs as far as I see on Government, Military and Private Sector Fighting Over Next-Gen Cyber-Warriors · · Score: 1

    No. InfoSec is exempt from that. Look for the phrase "direct hire authority".

    The problem is for every opening I've had posted there were 250+ applicants. We only interview the Top 10 and dang near every one of those has advanced degrees and decades of experience.

  15. Re:Pen name? on Wheel of Time TV Pilot Producers Sue Robert Jordan's Widow For Defamation · · Score: -1, Troll

    He's not dead, either. He just finally realized he had no fucking clue how to end the series and tell a coherent story and needed a way out.

    His wife hatched the whole "I have an incurable disease and am going to die soon" plot to boost book sales. She then got Sanderson to finish the series for a song and kept the rights.

    As best I can guess, she had her husband lobotomized -- seemingly sometime around book 5 -- and keeps him around as a pool boy.

  16. Trace the Transfers? on Bank Hackers Steal Millions Via Malware · · Score: 4, Interesting

    So shouldnt' they be able to trace the transfers to the destination accounts? And continue doing so until the money is withdrawn?

    Hell, even in places like Kazakhstan they don't have pallet loads of $100 bills waiting around for people to withdraw millions in cash. And you don't really walk into a bank ANYWHERE in the world and pull out millions in cash from a newly opened account without tons of ID, paperwork, being on cameras, access to large armored trucks, etc.

    I'm familiar with the concept of mules and blinds, but for a scheme so sophisticated it sounds suspicious to use low level mules to pull out millions in cash. Multiple points of failure/discovery.

    How the hell do they get the actual money OUT?

  17. Re:im sure the discussion was riveting. on Tech Industry In Search of Leadership At White House Cyber Summit · · Score: 1

    You forgot
    Ruth Bader Ginsburg: Is that the 1947 Rothschild? Be a nice boy and top me off here Tony.

  18. Re:Your rights don't include infecting my kid or m on Mississippi - the Nation's Leader In Vaccination Rates · · Score: 1

    And? Medical exemptions are not some sham to provide an "out" to the religious and personal exemption crowd. From the article:

    "For kindergartners that year, Mississippi approved just 17 medical exemptions, the Centers for Disease Control and Prevention said. Neighboring Arkansas, which had about 3,100 fewer kindergarten students than Mississippi that year, recorded 24 medical exemptions."

    This strikes me as honestly kids who might seriously have a condition that makes certain vaccinations dangerous. I mean 17 out of 45,000+ is a damn small number.

  19. Re:What are Autism rates in Mississippi on Mississippi - the Nation's Leader In Vaccination Rates · · Score: 1

    That's just among NJ politicians.

  20. Re: thank god for mississippi on Mississippi - the Nation's Leader In Vaccination Rates · · Score: 2

    Wrong section. Article VI says: ...but no religious Test shall ever be required as a Qualification to any Office or public Trust under the United States.

  21. Re:Article confuses "on Linux" with FOSS on The Current State of Linux Video Editing · · Score: 1

    LightWorks is, and they have a free (as in beer) version. Not FOSS, but a professional NLE tool on Linux.

  22. Yuggoth on Analysis Suggests Solar System Contains Massive Trans-Neptunian Objects · · Score: 0, Troll

    Beware! This heralds the return of the Great Old Ones! (Just in time for the U.S. 2016 election season it seems.)

    Keep an eye out for Mi-Go.

  23. Re:Real, real, real... on Silicon Valley Security Experts Give 'Blackhat' a Thumbs-Up; Do You? · · Score: 3, Insightful

    Actually, I know several that are gun nuts and are pretty damn accurate with firearms. Mostly when aiming at defenseless, motionless, bloodless targets, but still...

    Geeks and guns is a popular thing, at least in the U.S.

  24. Re: Fuck Me on SystemD Gains New Networking Features · · Score: 5, Funny

    Shell and userland? What do you think it is, Emacs?

  25. Godwin on SystemD Gains New Networking Features · · Score: -1, Troll

    End it now. Pottering == Hitler and Systemd == Nazi Party. Just move on to the next story already.