Slashdot Mirror


User: mortonda

mortonda's activity in the archive.

Stories
0
Comments
903
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 903

  1. It's the music. on Fans Come Together To Complete Star Wars Uncut · · Score: 4, Insightful

    This is just proof that you can put any sort of crap to great music such as John Williams and make it look interesting. How many movies has he saved, anyway?

  2. Re:Does she feel any different? on Artificial Heart Recipient Has No Pulse · · Score: 1

    Says one who has never had a life ending event.... ;)

  3. Re:From the last Slashdot article and FYI: on Revisiting DIY HERF Guns · · Score: 2, Informative

    but sometimes a person will pull into the left lane and either maintain the same speed as the right lane (two-lane scenario, for simplification), or so minimally faster that it will take several miles before they pass the car on their right.

    Just so you know, this is illegal in Kansas, as of July 1st. They will be issuing warnings for a year, and then start ticketing.

  4. Re:Cleartext Passwords? Really? on ISP Emails Customer Database To Thousands · · Score: 1

    No you don't have to send it back, but a MITM attack could still sniff passwords. PAP can store passwords salted, yes. The problem I ran into was that the people running the modems said, CHAP, nothing else. That requires plaintext at the radius server.

  5. Re:Do Naps Count? on Alzheimer's Disease Possibly Linked To Sleep Deprivation · · Score: 1

    I'm suspecting sleep apnea for myself. Sleepiness, brain fog, slow thinking, lack of willpower, even mild depression... all can be caused by it. I'm seeing a doctor about it next week. I wonder if it ties into Alzheimer's now. My grandfather had both.

  6. Re:Goverment on Canadian ISPs Fight Back, Again · · Score: 1

    That's almost exactly my experience with Bell here in Kansas. :(

  7. Re:Passwords are needed - CHAP on ISP Emails Customer Database To Thousands · · Score: 1

    The only reason for CHAP to exist is so that you can avoid sending the password in plaintext over an unencrypted channel. Proper encryption fixes that problem without introducing the greater problem of requiring plaintext password storage.

    True, the better solution would be to use PAP over a VPN or SSL tunnel, but have fun convincing the large telcos or modem concentrators to do that. We were given no other option than CHAP.

    I think that was about the time I began to lose interest in sysadmin and network admin stuff.

  8. Re:To err is human... on ISP Emails Customer Database To Thousands · · Score: 1

    Most isp's have just one password for the account.

  9. Re:Passwords are needed - CHAP on ISP Emails Customer Database To Thousands · · Score: 1

    That would require a user to know two passwords, which is 2 more than they are capable or remembering.

  10. Re:Cleartext Passwords? Really? on ISP Emails Customer Database To Thousands · · Score: 1

    With CHAP or PAP?

  11. Re:To err is human... on ISP Emails Customer Database To Thousands · · Score: 4, Informative

    Unfortunately, that's not the case. CHAP authentication requires cleartext passwords to be stored. See my other post

  12. Re:Cleartext Passwords? Really? on ISP Emails Customer Database To Thousands · · Score: 1

    Yes, really. It's called CHAP authentication, and it requires plain text passwords. see my other post

  13. Passwords are needed - CHAP on ISP Emails Customer Database To Thousands · · Score: 4, Informative

    I can't believe this still happens. They shouldn't even be storing the passwords anywhere, even in their primary database, much less an Excel spreadsheet. Use a one was hash with salt, folks!

    While having it in an excel document is unexusable, there is a real reason why password are stored as plain text, and I hated it as a sysadmin. Look up CHAP vs PAP authentication... Basically, PAP sends the password in plain text across the wire from the modem server to the radius server, which can then look up the salt, hash it, and then verify the password.

    However, since this means sending passwords in the clear, most modem concentrators (most ISP's resell for a handful of large telcos that operate the modems nowdays) prefer to use CHAP, which hashes the password with something at the terminal server and sends both to the radius server. In order for the radius server to authenticate the session, it must have access to the original plain text to hash with the provided salt. Thus, the ISP must store all passwords in plaintext somewhere.

    That said, it should be stored in a hardened and dedicated server that only handles the storage (sql or ldap) and the radius server. Any billing interaction should only be to update the password, never to read. And it should never be put into a excel or word doc!

  14. Re:Advertising "it's got Linux" is as stupid as... on Net Radio Exec Says "Don't Mention Linux" · · Score: 1

    ...new website was using Java on the backend or something. .... Does your product work reliably?

    See.... the answer to that *was* in the ad. :P

    Yes I jest. Maybe...

  15. Re:We Know Best on Snow Leopard Snubs Document Creator Codes · · Score: 1

    My problem is that I cannot seem to set defaults for files without an extension. Some perl scripts for example that look like commands, leave off the .pl extension. My mac wants to execute them instead of opening them in a text editor.

  16. Re:Local? on Windows 7 Reintroduces Remote BSoD · · Score: 1

    Agreed -- it IS rather bad, but generally speaking you're not expecting attacks from inside your LAN. As Windows vulnerabilities go, this isn't horrible in a practical sense.

    If you think that, please don't go into the security industry. The greatest threat to a corporate network is from you local network and "trusted" users. This bug just makes it easier.

  17. Re:Fix SMB first on A Different Perspective On Snow Leopard's Exchange Support · · Score: 4, Interesting

    What SMB problems? My MBP connects just fine to all te shared drives around, and when I connect to a new network, it shows all the available shares very quickly.

    Compare that to a XP install that repeatedly tells me that "I don't have the necessary permissions" to view the public, no password share.

  18. Re:Glad to see the "coalar" tag on Mixing Coal and Solar To Produce Cheaper Energy · · Score: 1

    Turn off the lights in the hold as you transport, and the shipping is free!

  19. Re:Good luck in university on Schooling, Homeschooling, and Now, "Unschooling" · · Score: 1

    All of a sudden, they'll be expected to shut up, sit still, and listen for hours to a boring instructor with his whiteboard and PowerPoint slides.

    erm, if I homeschooled my kids, that would not be much of a change.... *sigh*

  20. Re:How to do rock band without "Rock Band" on The Design Failures That Led To Rock Band · · Score: 1

    Best troll I've seen in a long time... ;)

  21. Re:Blaming the Govt. Strawman on Slow Oracle Merger Leads To Outflow of Sun Projects, Coders · · Score: 1

    Oracle could have reassured them at any time, if they knew, and cared, which isn't a very realistic expectation for a small team in a big merger.

    But anyone in that position knows that those assurances aren't worth the air breathed to utter them.

    And the lack of those assurances at any value says even more. No wonder they jumped.

  22. Re:No thanks. on India's First Stealth Fighter To Fly In 4 Months · · Score: 2, Funny

    If you're really going to be that pedantic, Goose is a fictional character and is not alive, and therefore can never die.

    Are we done yet? ;)

  23. Re:Non problem with modern Doppler weather radar on Wind Farms Can Interfere With Doppler Radar · · Score: 1

    Thank you for that, and I would also like to ask, where is a picture of the supposed false alarm? Wouldn't the article be more informative if they had included that? I'm curious to know how it could even look the same.

  24. Re:He doesn't even look black on Microsoft Poland Photoshops Black Guy To White One · · Score: 1

    Well, if he wasn't the original, then they remembered to shop the hand in the first but not the second... talk about mixed race.... lol

  25. Re:Actually having read the patent on US Court Tells Microsoft To Stop Selling Word · · Score: 1

    If MS is doing this, it isn't part of standard XML, AFAIK.

    Let me say it again: This patent isn't about XML, SGML, CSS, etc. It's pretty specific,

    It's an index. maybe a precompiled parse tree. Hardly innovative.