Slashdot Mirror


User: feed_me_cereal

feed_me_cereal's activity in the archive.

Stories
0
Comments
456
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 456

  1. Re:CVS, huh? on Remote Root Exploit in CVS · · Score: 2, Insightful
    And how are they going to do that? Through a hole in something like CVS??? Couldn't be!

    no shit! Don't quote me out of context. I had some more following that. My original quote:

    That means the attacker would have either had to have nailed the server distributing the copies (and the people there would have had to have been dumb enough to go ahead with it)

    and also...

    Although the situation I described above is certainly possible, I would say the grandparents method is good security practice and probably a lot more than a mere "security blanket".

    So... I sincerly hope that the people distributing the release:
    1. practice better security than a mirror
    2. For christs sake, CHECK the release against a safe backup before releasing it!!! And they had better be backing up their code...


    and, of course,it's still possible that this could happen. Certainly. I never said it couldn't. That dosn't change the fact that checking multiple sites will probably take care of most of these CVS attacks, since it's a lot easier to hit one random mirror than the main fucking site.
  2. Re:CVS, huh? on Remote Root Exploit in CVS · · Score: 3, Insightful

    you sir, are an idiot.
    you sir, are an ass (albeit anonymous)

    what good does getting the md5s do? so you get your sources from 2 or 3 places

    It works when one of the CVS servers you're downloading from gets hacked. Of course it's possible for the distributing server to get hacked too, but I'd hope people are watching it a bit more keenly. If the developers don't have more than one copy of their own code with which to check before submitting their release to the mirrors, then they shouldn't be making OSS software.

    This is still much much much much better than doing nothing. You can never be 100% secure. Security is doing all the reasonable things you can to approach 100%.

    maybe the transfer from master to mirror mixed up a few bytes.

    Then the MD5 sum will be fucked up. What's your point?!

    maybe all your downloads from a mirror mixed up a few bytes

    In the exact same way ?! if the file is only a megabyte then the chances of this will be slimmer than 1 to 1 million squared! Either way the MD5 sum, since it's independant of the data, will be fucked up.

    either way, it doesn't matter how many sources you use to d/l source packages for 'safety'

    Maybe if you've never taken a statistics class.

    oss needs a better method of s/w distribution. sign packages and their md5 hashes with pgp would be a start.

    Um... there are OSS distribution rules? It's up to you to judge the competency of individual projects, as far as security goes.

    Oh, and why is this OSS's problem? Why isn't closed-source even MORE vulnerable to this phenomena? OSS developers aren't the only ones who use CVS internally.

  3. Re:CVS, huh? on Remote Root Exploit in CVS · · Score: 3, Insightful

    Unless you personally diff all the code that has changed since the last release, you don't know what's in there. Sure, you could check, and others can (and likely do), but you don't know until/unless they/you do.

    The grandparent said he checks at least 2 or 3 sources. This means all the sources would need to have the same hacked copy. That means the attacker would have either had to have nailed the server distributing the copies (and the people there would have had to have been dumb enough to go ahead with it) or by luck have comprimised all of these random servers.

    So enjoy your security blanket, but realize that is is only that.

    Although the situation I described above is certainly possible, I would say the grandparents method is good security practice and probably a lot more than a mere "security blanket". That is, if I'm correct in my reasoning. If not, I'd appreciate comments.

  4. well, I hope they weren't looking for more trolls on Slackware Forums Alive Again! · · Score: 4, Funny

    Announcing to slashdot readers that a forum that was shut-down by trolls is now back in operation is like telling the fry-guys and the hamburgler where the McDonald's truck routes run.

  5. mplayer is da shit! on Windows Media Player 9 · · Score: 5, Insightful

    Maybe because it's a nasty, semi-legal hack using MS/Apple binaries.

    You forgot to add "that works extremely well". I think it's better than WMP. It's much much much more stable (in my experience, can't speak for everyone) and supports about as many formats (more?).

    I will not install proprietary binaries on my computer.

    Then no soup for you!

    So I assume you're talking about the codecs, anyway. Well guess what, if you don't like the fact that mplayer uses binary non-opensource codecs, then write your own. mplayer itself is opensource and they don't need to re-write every fucking codec themselves. Why don't you volunteer your support?

    And if your'e not talking about the codecs, then check this (from the mplayer website): MPlayer is GPL now. In the past it contained non-GPL code from the OpenDivX project, which did not allow binary redistribution. This has been removed.

    Anyway, I hope you're not thinking that MS would release WMP opensource, cause... umm...

  6. Re:"or more often during heavy traffic" on Cryptome Log Subpoenaed · · Score: 2

    Is it be possible to just write a quick script to...

    provided what follows the dots isn't a complicated task involving intellegent decisions and is something you can do manually from a shell, then the answer should always be yes.

    Which means, if your job is to delete log files every few hours and some UNIX person walks along and notices you...

  7. Re:Why should this surprise anyone? on U.S. Pushing Conservative Science · · Score: 2

    I'm obsessed with NOT choosing a candidate based on skin color. I'm not trying to sound anything, I'm pointing out an indisputeable fact. If you READ my thread (or maybe you did read it and you're just a fucking retard), you'll notice I'm saying that a lack of proportional representation in the presidency means there's a problem. For the second time (again, read my posts or grow a brain) I'm not saying we need to remedy this (I'm NOT for affirmitive action, so don't call me a "racist progressive poser", I actually have a simmilar position to wha tyou're saying on that issue). I'm just saying theres a problem. And there is.

    I'm POINTING OUT (notice, pointing out, not asking for change, not anything other than pointing out) that all we get is white presidents in a country that is less than 80% (probably more, but I don't know the number) white, and there has NEVER been a non-white non-male president, and few that wern't WASP's, and that means that voters are racist. Refute that.

    I'm racist?

    Preferring a candidate based on skin color -- regardless of the fact that you think your choice of preferred skin color makes you sound cool and "progressive" -- is simply racist.

    and the exact OPPOSITE of what I've been saying!!!!!!!!! READ MY POST!!!!!! I'm saying this is bad... can you read? christ! There's a difference between saying "all presidents have been white and that constitutes a problem" (notice, what was just said is my position) and "all presidents have been white so we need to purposely elect a black president who we might not vote for otherwise" (notice, this is NOT what i've said at any point, and what you assume I'm saying because you can't read or something...)

    I hope I made it simple enough for you this time. I apologize for the redudancy but I figure you probably need it after missing my point in three posts.

  8. Re:There is something wrong here. on U.S. Pushing Conservative Science · · Score: 2

    This is exactly what I would advocate, but I think that many conservatives see the two options as mutually exclusive. I agree with you.

  9. Re:Why should this surprise anyone? on U.S. Pushing Conservative Science · · Score: 2

    SO what did clinton EXACTLY do for minorities?


    You must not have read my first post, and certainly not the links I included.

    just put a bunch of token blacks on the cabinet?

    Again, you must not have read my first post. My argument had nothing to do with token black/whatever people. It had to do with the fact that we don't see equal proportions of minorities in the presedency. This means that either minorities are not fit for such a position (which is bullshit), or there's something wrong with america. That was my argument, I didn't say one thing about how to solve it, and certainly not by putting token minorities in office. Read posts before you reply, and don't put words in my mouth.

  10. Re:Bush should duel with sadam at sundown. on U.S. Pushing Conservative Science · · Score: 2

    I'd prefer they suicide bomb eachother

  11. Re:Why should this surprise anyone? on U.S. Pushing Conservative Science · · Score: 2

    when did I imply any of what you said? First off, I never said all blacks, I mentioned the NAACP because it supports the idea that Clinton was for the rights of minorities, and how the hell did I imply that blacks not supporting the NAACP are unlce toms? Troll somewhere else.

  12. Re:There is something wrong here. on U.S. Pushing Conservative Science · · Score: 3, Interesting

    you forgot about some of the other things that keep being said on this thread:

    What's the best way to prevent pregnancy and sexually transmitted diseases? Condoms or Abstinence?

    I'm getting sick of this misrepresentation of the issue. No shit abstinence is better, but this is a choice that OTHER people are making, not the government. A real characterization of the issue before the government is this:

    Which would be a more effective method of preventing unwanted pregnancies and the spread of STD's: passing out condoms or advocating abstinence?

    This is a much more difficult question, and it is the one we actually face. Just because you say abstinence a better idea dosen't mean ANYONE is listening, and it could be possible that these people who are going to have sex whether you like it or not (which is most people I've knew in highschool and college) could benefit from condoms.

  13. Re:21st century on U.S. Pushing Conservative Science · · Score: 2

    Uhh, except maybe the book the Christian right follows does not endorse killing everyone who is not Christian? Big difference, pal.

    You're right, it says to always turn the other cheek and not to kill anyone. Guess who hasn't been following his bible? Of course, the Koran tells you that allah loves the pen of the scholar more than the blood of the martyr, but just as many terrorists ignore that.

  14. Re:I blaim Bush on U.S. Pushing Conservative Science · · Score: 2
    good post: no, but that's my opinion
    modded down unfairly: yes

    But stop whining. This happens to everyone. Slashdot dosn't lean that far left. Our common tie is usually free software, and not all of us can even agree with that. I've been modded down many times for left-leaning comments that were on-topic and not flamebait, but don't think it just happens to right-wingers, and don't be suprised when it happens to people with "You say 'start a war' like it's a bad thing" in their post, lest I quote Jimmy Carter:
    War may sometimes be a necessary evil. But no matter how necessary, it is always evil, never a good. We will not learn how to live together in peace by killing each other's children
  15. Re:Why should this surprise anyone? on U.S. Pushing Conservative Science · · Score: 2

    and what they stand for? um...

    sorry, but I won't catch bush's bones, I don't really care that some of his cronies are black women. I want minorities, women, etc.. making it to the PRESIDENCY. I don't buy the "look! these people aren't ALWAYS shafted" argument. If there wasn't a problem, we'd see them in equal proportions everywhere, including the presidency.

    Besides, to infer Clinton isn't on the side of minorities is ridiculous. He's been touted as our blackest president ever. Just take a look at what the NAACP thinks of him.

  16. Re:Why should we be surprised? on U.S. Pushing Conservative Science · · Score: 2

    The United States has never signed the Kyoto Treaty.

    You're right. Maybe they should.

    Even former Cliton administration officials agree that the treaty is flawed.

    Who gives a shit what he says? Not me, or most left-leaning people I know.

    With regards to North Korea, why doesn't somebody else deal with them?

    Yeah, like the pacifist country they're likely to aim their nukes at? The same one we nuked 60 years ago? In case you don't remember, we're supposed to protect our unarmed allies.

  17. Re:I blaim Gore on U.S. Pushing Conservative Science · · Score: 2

    Gore would continue the status-quo of pushover democrats who only do enough to get the left vote, but not enough to acually appease them. Hopefully he'll now be the last.

    Don't blame the greens for voting for the person they actually wanted to be president, blame Gore for playing the fence. Besides, if everyone who voted for Gore voted for Nader, we wouldn't be in this mess either :)

  18. Re:A: dead kids on New Jersey Enacts 'Smart Gun' Law · · Score: 2

    Actaully, I did look at the statistics before I posted. I had always heard this was true, but I took the time to verify it on the CDC page. Admittedly, on second try, I found that I made an error in my selection of accident category giving me the false result. I checked again and got a rate similar to what you have. Thanks for the correction, but save the self-rightous "advice". I check my facts, and being human, also make mistakes from time to time.

  19. A: dead kids on New Jersey Enacts 'Smart Gun' Law · · Score: 3, Insightful

    and the solution to THAT is responsible, diligent parenting

    You mean a solution, not the solution. It seems that this technology would also be a solution, and given the percentage of brain-dead parents there are out there who own guns in reach of children, I think this solution will be much easier to implement than a "no brain-dead parents" law, however you might word that. And given the importance of not having holes in the heads of kids, and the frequency in which these accidents occur (much more than any other gun-related death), I think this is a very prudent decision.

  20. Re:Progressives on Tim O'Reilly Says Piracy is Progressive Taxation · · Score: 2
    Of course Homosexuals are equals in the eyes of the law.

    They have the same right to marry a person of the opposite sex as the rest of us.
    They have the same right to express physical love to a member of the opposite sex as the rest of us.


    nope, you missed one very very important point. Heterosexuals are free to choose their prefered sexual partner. Homosexuals are not free to choose their prefered sexual partner. By definition, a homosexual prefers a sexual partner of the same sex, so by definition homosexuals are denied rights that heterosexuals have. You failed to look at the relative issue. A law against homosexual marrages is discriminatory against homosexuals. I can't believe I even have to make that argument...

    I've listened to rush, he commits errors like this all the time.

    The conservative philosophical sticking point is, these horrible gays *choose* to exhibit illegal, deviant behavior, and giving them the rights to do such behavior is tantamount to giving them rights above and beyond ordinary people

    Like those horrible blacks who *chose* to exhibit illegal, deviant behavoir on buses in the 60's? Yup, believe it or not, thats how conservatives used to view that. Time's are a'changin.

    I used to believe baseless arguments like this in... oh... 6th grade, when I still looked to other people for opinions. Luckily I've matured since then.

    No, giving them the right would be giving EVERYONE the right, we're not limiting rights to homosexuals only. We shouldn't be limiting rights to ANY group of people. If you make gay marrages legal, you won't have to show an "official gay person" licsense at the altar. If the laws were repealed, anyone would be allowed to perform this, as you say, "deviant" behavoir.

    Horrible, deviant? These are relavent terms, my friend. I think it's pretty horrible and deviant that people feel they can have control over other peoples love lives, or that they even care to invade the lives of people who have nothing to do with them. Why are they so threatened? Would it hurt to leave the issue alone? No, and that's why they call it "homophobia".

    So why is it deviant? Oh, let me guess... the bible said so, right? One thing that amazes me about bible thumping homophobes is that they haven't even read the bible. Or at least, they don't know how to organize their priorities. For every "homosexuality is a sin" reference there is in the bible, there's about 500 "don't be a hypocrite" (you know, the whole thing about the splinter in your brother's eye and the plank in yours?) or "love thy neighbor as thyself" references. You think jesus was just kidding about that stuff? No, he wants you to love sinners, and that includes homosexuals, and everyone else for that matter. There's also about a million references to having faith in crhist, so as long as we're writing the bible into law, should we make a law against being Jewish? Atheist? Let me remind you of something:

    Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof


    doh.

  21. you? on Tim O'Reilly Says Piracy is Progressive Taxation · · Score: 1

    Trolling is purposely trying to incite someone, and is typically done AC so as not to bear repercussions (cough, cough). I responded with more respect for the opposing position than the original poster asumed.

    These days progressives are absurd

    There's some objective thought for you. Questioning things involves asking questions, not just stating that something is "wrong".

    How did I not consider his argument? I broke it up and adressed nearly every sentence! What, are we so fucking PC that we're not allowed to disagree anymore? I have every right to propose a counter argument, and I don't have to congratulate anyone beforehand.

    Now I believe I'm done responding to AC flamebait for the day.

  22. note on Tim O'Reilly Says Piracy is Progressive Taxation · · Score: 2

    I'm sorry, I accidently inserted that last sentence before the italics... didn't mean to misquote you

  23. Re:its all about 'try before you buy' on Tim O'Reilly Says Piracy is Progressive Taxation · · Score: 5, Interesting

    same thing with games as well ... a nice box or animation on tv isnt enough to make me happy if the game is lame or behind by five years. especially in this world where nobody takes back returned games and many stores have kiosks for you to try games out on.

    I'm sorry, did they pass a law requiring vendors to allow customers to try products out, at their own expense, before they decide to purchase them? They can do whatever the hell they want, it dosen't give you the right to steal. Besides, you can rent most console games.

    Q: Why can't you return games?
    A: Piracy

    Now how do you suggest we solve this problem? Piracy? How about boycot, it's the only non-hypocritical and effective method, but since it requires sacrifice it's nearly garunteed that most people aren't going to go along with it...

    CD's are overpriced, but you probably don't appreciate the production costs that go into games. Many game companies don't make their money back. It dosen't take a lot of $ to make a music cd, unless the artists are already superstars and demand a high sum, but a team of programmers and graphic artists can be very expensive.

  24. Re:YHBT. HAND on Tim O'Reilly Says Piracy is Progressive Taxation · · Score: 2

    No shit this was a troll, but the fact is that there are enough people on this site that believe such tripe that a reply is warranted.

  25. Re:Gun control won't work on An Unbiased Analysis of Gun Crime vs. Gun Control? · · Score: 2