Slashdot Mirror


User: Greger47

Greger47's activity in the archive.

Stories
0
Comments
183
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 183

  1. Sigh. on Firefox 1.0.3 and Mozilla Suite 1.7 Released · · Score: 4, Informative
    I'm sure they got a million submissions about this. Why do they insist on picking the worst one?

    It's Mozilla 1.7.7, there's nothing new we didn't already knew about. The update has the same security fixes (scroll down) as the new Firefox release, that's all...

    /greger

  2. Re:April Fools Idea on DNS Cache Poisoning Spreads Malware · · Score: 3, Funny
    On Slashdot it's redundant. We already subconciously add

    3. Profit!
    In Soviet Russia ... you!
    Imagine a Beowulf cluster...

    to all posts.

    /greger

  3. Re:Crimnal Case??? on First Swede Prosecuted For File Sharing · · Score: 1
    Won't putting these people in jail prevent the copyright holders of collecting damages? (Isn't that the point: that they are supposed to be reimbursed for lost money?)

    When you're in prison you don't need your house nor your car...

    /greger

  4. Re:Good reasons for chosing GPL over BSD on Tracking GPL Violators · · Score: 1

    Yea, but it's kinda hard to sell it when you already gave it away for free.

  5. Meta Slashdot on Regulators Lose Piracy Battle · · Score: 5, Interesting
    How about this?

    Lets create "Meta Slashdot", a site where we solicit news items. We'll have some real editors that actually weed out the dupes and check the facts. Then we submit the news to Slashdot where Cowboy Neal can rubberstamp it.

    With some luck we can even bribe Slashdot's ISP to reroute their mail to us, to make sure all submissions are properly vetted. :)

    So, what do you say folks? Instead of this endles bitching about how the Slashdot editors suck, let's get together and do something about it!

    /greger

  6. Re:WOW Dijjer Blows the doors off bitTorrent on Beware The Rotundus Rover · · Score: 1
    Dijjer requires a known "root" node for the p2p network to which clients initially connect. The current client connects by default to a root node run by the makers of Dijjer.

    Bittorrent requires someone to run a tracker, Dijjer requires someone to run a root node. I don't see any big breakthroughs here. Dijjer might have a slightly more userfriendly way for the publisher to seed his file but thats about it.

    /greger

  7. Well duh! on Hondas in Space · · Score: 1
    And the obvious statement of the year award goes to:

    A Ferrari is a very expensive car. It is not reliable. But I would bet you 1,000-to-1 that if you bought a Honda Civic that that sucker will not break down in the first year of operation.

    Ofcourse! A Ferrari is built to squeeze every last bit of performance out of the machinery, sacrificing silly stuff like economy, comfort and reliabiliy.

    A Honda Civic is built to be as cheap as possible, but without sacrificing reliability. If repairs ended up costing as much as the car it would be a tough sell. :)

    /greger

  8. Re:You can't do that. on TCPA Support in Linux · · Score: 1
    Well, as far as I can tell the specification does not mandate that the security chip verifies the BIOS before the CPU boots.

    The PC specific part of the spec does a cop-out and makes it the motherboard manufacturers problem to somehow keep the BIOS and security chip safe from tampering. But ofcourse, the data bus between the BIOS, CPU and security chip must be protected as well, or it's all a moot point. :)

    /greger

  9. Re:Here comes the flood?? on TCPA Support in Linux · · Score: 1
    Well, the GRUB thing was just an example. Since the chain starts at the BIOS, so will I.

    My hacked BIOS keeps a copy of the hash of the trusted version and sends that to the TPM (or a copy of the entire BIOS in case the TPM wants to do its own hashing).

    I don't even have to do all that work in the BIOS, the only thing I need to do is to remove the part that activates the security chip. When my OS is up and running I can run my own utility that starts the chip and feeds it a "fake" boot process with hashes of a trusted BIOS, bootloader and OS.

    The point is, as long as TCPA isn't part of the CPU itself, it's hosed. It's not even enough to put the BIOS in an embedded tamperproof ROM on the CPU (a la microcontrollers), as long as the security chip is external I can interfere with the communications and feed it fake data.

    /greger

  10. Re:Here comes the flood?? on TCPA Support in Linux · · Score: 5, Interesting
    This is the thing that I don't get. The supposedly secure boot process seems to be broken from start to finish.
    The "trusted" boot functions provide the ability to store in Platform Configuration Registers (PCR), hashes of configuration information throughout the boot sequence. Once booted, data (such as symmetric keys for encrypted files) can be "sealed" under a PCR. The sealed data can only be unsealed if the PCR has the same value as at the time of sealing. Thus, if an attempt is made to boot an alternative system, or a virus has backdoored the operating system, the PCR value will not match, and the unseal will fail, thus protecting the data.
    The whitepaper also mentions that in IBMs implementation the chip is connected to the SMbus.

    This means that the entire security of the boot process hangs on whatever data the CPU feels like sending to the chip for hashing. I could as well make a patch for GRUB that sends the "secure" version of GRUB down the SMbus and actually executes whatever nastiness I have in store.

    In the case of DRM this lets me run whatever OS I want. The only thing I have to do is to feed a copy of whatever OS Hollywood trusts to the chip and voila the chip will say I'm legit and Hollywood will give me access to their movies for me to pirate at my leisure. :)

    As I see it, the only way to get this to work for real is if Intel steps up and builds TCPA support into the CPU itself such that the PCR register is continuously updated as each instruction is executed. And all existing external chips have to be blacklisted, ofcourse.

    Or does the TCPA system have some other trick up their sleeve that makes this work even though it's implemented externally to the CPU?

    /greger

  11. Coincidence? on Mac mini to PC Hack · · Score: 4, Interesting
    The Mac mini box is 16.5 cm along the edges. Compare that to the mini-ITX PC boards that are 17x17 cm.

    I guess Apple decided to give all those nerds that insist on "upgrading" their Macs with a PC mobo a challenge. :) /greger

  12. Re:It's always a mixed bag. on PHP Vulnerabilities Announced · · Score: 2, Informative
    Err?

    Like 90% or so of the modules included with the basic PHP distribution are just wrappers around standard libraries, no code is duplicated nor functionality reinvented. The wrapper is there to make the libraries easy to use.

    The 2 libraries you mention happen to be bundled with the distribution for convenience, but you are free to use external versions supplied by your OS installation or perhaps yourself.

    /greger

  13. Re:READ THE DAMN ARTICLE on Samsung to use Sub-Pixel VGA Screens · · Score: 2, Informative
    Err, why? It's the same thing as ClearType, they just rotated the display 90 degrees and are doing subpixles vertically instead of horizontally.

    My guess is that someone read that MS patent really carefully and concluded that it only covers horizontal subpixels. :)

    The novelty would be that it's implemented in the display driver chip thus I guess it can move any pixel around, not only when rendering fonts.

    /greger

  14. Re:What are the odds? on EFF Goes To Court To Fight The Broadcast Flag · · Score: 2, Insightful
    What are the odds that Congress will happily enact the necessary law to mandate the broadcast flag if it turns out that the FCC ain't allowed to put it in its regulations?

    /greger

  15. Sigh :~ on Sun Files For Patent on Software Licensing Method · · Score: 4, Insightful
    I dont know what saddens me most, that they have the balls to submit an application for something so old and obvious like per employee pricing, or the fact that it actually has a pretty good chanse of beeing granted...

    /greger

  16. Re:Calendar Server on Red Hat Acquires Netscape Server Products · · Score: 1

    So whatever happened to Netscape's calendar server?

    If I'm not entierly misinformed, it ended up with a company named Steltor who developed it further under the name CorporateTime. A year or two ago they in turn got bought by Oracle and it's now called Oracle Calendar. It's still actively developed.

    /greger

  17. /. effect on Microsoft Releases FlexWiki as Open Source · · Score: 4, Funny
    Well, regarding which one is best, I think FlexWiki wins the /. effect test, showing a 503 Service not available. Compared to Kwiki that doesn't respond at all... :)

    /greger

  18. Re:Shift? on Windows Laptops Ship With Linux Media Player · · Score: 3, Interesting
    Well. I don't think most application vendors are interested in becoming OS vendors as well.

    Besides, don't we reboot Windows enough as it is today?

    /greger

  19. Re:Funny... on Lucas to Make Sequels to Star Wars After All? · · Score: 5, Funny
    Riminds me of the classic

    Bart: How could you Krusty, I'd never lend my name to an inferior product.

    Krusty: Oh! They drove a dumptruck full of money up to my house. I'm not made of stone!

    /greger

  20. Pfft... on Composite Of Earth At Night · · Score: -1, Troll
    That image is soooo 1990ies. News for dementia anyone?

    /greger

  21. Re:WAP 1 vs. 2 on WAP is Dead, Long Live WAP · · Score: 5, Funny
    No, WAP isn't an acronym. It's and onamatopoetic word derived from the sound your phone makes when you throw it at the wall out of frustration...

    /greger

  22. Re:Too complex, too brittle, too expensive.Advanta on Attention Bonds Gain Momentum · · Score: 1
    The problem is that with the new entities, things can go wrong. They can simply be down (keeping me from sending or receiving e-mail!). Or their security can be compromised. The bottomline is: this is too complicated.

    Or the escrow can become the new VeriSign, charging a truckload of money for a service that costs nothing to provide.

    /greger

  23. Everyting is trademarked. on Rendezvous Renamed to OpenTalk · · Score: 1
    So who has the trademark on OpenTalk? Can the next person in line to sue us please step up to the counter!

    /greger

  24. Re:Hrm? on SpaceShipOne to Try for Space on Monday · · Score: 1
    No, it's enough to fly with one person + ballast instead of the remaining two. The craft must still be large enough to seat three people ofcourse.

    /greger

  25. Re:What are legitimate uses on DirecTV Extortion Program stopped by EFF · · Score: 1
    It might not be morally right for other reasons, but listening in to mobile phones is not theft.

    /greger