Slashdot Mirror


User: Dwonis

Dwonis's activity in the archive.

Stories
0
Comments
2,728
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 2,728

  1. Re:A secure scheme for pad distribution on Meaningful MD5 Collisions · · Score: 1
    Think about it some more.

    That's not a one-time pad, even if there were only one copy of the DVD. The pad must be *random*. That is, it must be impossible (both practically and theoretically) to construct a test that would determine whether or not any given pad is valid. Individual DVD movies do not have this property. Even if the DVDs themselves *were* totally random, everyone has access to them, so assuming that there are 100 million different movies to choose from, your scheme has *at most* 27 bits of computiational security, and probably substantially less.

    Of course, if you know that your attacker isn't going to have access to all the DVD movies in the world, then your calculated risk is lowered (your security remains the same). However, the reason why people talk about the one-time pad in the first place is that it's immune to *any* attacker. Your scheme is interesting, but it's not comparable to a one-time pad.

    It's good to see you're thinking about it, though. If you keep at it, you'll improve.

  2. Re:These are important attacks.. on Meaningful MD5 Collisions · · Score: 1
    How exactly could they create junk documents that also match the expected filesize.

    Add in that restriction and md5 could become a difficult problem again :)

    Um... that's what they *did*:

    $ ls -l *.ps
    -rw-r----- 1 dwon dwon 2029 2005-06-10 21:36 letter_of_rec.ps
    -rw-r----- 1 dwon dwon 2029 2005-06-10 21:36 order.ps
    $ md5sum *.ps
    a25f7f0b29ee0b3968c860738533a4b9 letter_of_rec.ps
    a25f7f0b29ee0b3968c860738533a4b9 order.ps
  3. Batteries ;-) on Japan Displays Prototype Robot Suit · · Score: 1
    Due to the limitations in battery technology, if the unit is unplugged, it can only run 1 minute at full power, or 5 minutes otherwise.

    Apparently, they also can only be piloted by 14-year-olds. On top of that, these things have a mind of their own, so be careful!

  4. Re:This is what I get: on First Google Maps Hack Takedown · · Score: 1

    Companies often avoid having their programmers interact with the general public. It might be a good idea to avoid having their lawyers interact with the general public, for the same reasons.

  5. Re:more details... on Tokyo's Geek Ghetto · · Score: 1
    The blanket statement that Otaku are immature people is mighty strong, but I think I'm talking to those who know this already.

    Heh! You must be new here.

  6. copyright protection on DVD Decrypter Author Served With Take-Down Order · · Score: 1
    Sigh.

    "Copyright protection" is something that the *law* does. "Copy protection" (or perhaps more accurately, "copy prevention") is something that technology does.

    It does no good to use these terms interchangeably.

  7. Re:International laws? on Google Never Forgets · · Score: 1

    EntroPay offers a similar service.

  8. your sig (-1, Offtopic) on Researchers Control the Flip of Electron Spin · · Score: 1
    The GIMP has a very very good interface.

    Somebody needs to be taken out back and shot! ;-)

  9. Re:On-demand is the future, today. on Television Reloaded · · Score: 1
    No. I didn't say that. I never said anything about giving up freedoms.

    Don't be naive. You said:

    Unfortunately, this begs the ugly question of whether or not commercial skip should be allowed. Frankly, I think there's a compromise here. Get rid of commercial skip and add fast forward.

    The obvious way this would be done is by legislating/regulating feature out of existence, i.e. giving up freedom.

  10. Re:On-demand is the future, today. on Television Reloaded · · Score: 1
    Uhm...giving up what freedom? What he said was that they should not offer commercial skip; they should offer fast forward.

    The freedom to buy devices that do offer a commercial-skip feature. Or do you think manufacturers will all voluntarily leave out this feature forever without any influence from the regulatory bodies?

  11. couldn't resist... on Television Reloaded · · Score: 1

    Don't like what people say on Slashdot? Don't partake then.

  12. Re:Good on Trojan Built for Industrial Espionage · · Score: 1

    At least in Linux, if you're root, you can get *all* keystroke events, not just ones associated with a particular user's terminal or X session.

  13. Re:Good on Trojan Built for Industrial Espionage · · Score: 1
    OTOH, in a Linux or MacOSX environment, the worst that would happen is that the user's settings get lost or wiped.

    In theory. In practice, probably not.

  14. Re:Good on Trojan Built for Industrial Espionage · · Score: 4, Insightful
    Linux probably does not have "just about as many security flaws as Windows", because its design is simpler and there are fewer places for things to go wrong, among other reasons. You are obviously making statements that about things you know hardly anything about, so I put you in my foes list to remind me of that.

    However, you've touched on an important point about computer security: to an attacker, the number of security holes in a system is almost totally irrelevant. If I were an attacker, I'd be more concerned about the types of security holes in a system, than the absolute number of them. For example, if I run a malicious webserver, and my goal is to install a key-logging driver into the kernel of a Linux machine that accesses my webserver, I need two types of security flaws: one in the web browser that lets me execute arbitrary code, and one in the OS so I can get root privileges to install the driver.

    This where people get confused. Having 2 or 2000 local root holes doesn't help me if I can't execute arbitrary code on the computer, and having 2 or 2000 arbitrary code execution holes doesn't help me if I can't get root privileges. I need exactly one hole of each type for my attack to be successful. Beyond that, it makes little difference.

    So, if you create two categories, "secure" and "not secure", Linux and Windows fall into the same category: "not secure". Most systems fall into that category. If you're a decision-maker, and you're forced to use some of these systems, even though you know that they are all "not secure", which ones do you choose?

    You choose the ones that are going to minimize your risk. If that means choosing Linux, or some heterogeneous mix of systems, simply because that arrangement is less popular and therefore less likely to be exploited, then so be it. It's still a sound decision, given the circumstances.

    Regarding people demonizing Microsoft, don't you find it the least bit pathetic that a loosely-knit group of poorly-organized hobbyists working on their spare time can be even remotely competitive against the industry leader, a company that can spend billions of dollars per year on software development?

    What about all the people over the last decade who trusted Microsoft with their data, only to find out that (until recently) Microsoft didn't care about keeping it secure? Should they not be angry?

    What about Microsoft's idea of "ease of use": menus that are never in the same place, and word processors that mangle your data because "it looks like you're writing a letter"? Or how about the general Microsoft "we know better" attitude? Software that makes your computer not do what it's told (DRM)? Product keys? EULAs? Software patents? Mandatory file locks (sharing violation)? The Win32 API? Broken CSS support? Horrible context-switching performance? mikerowesoft.com? "Best Viewed with Internet Explorer"? The need to use defrag.exe? The DR-DOS error messages? Abandoning OS/2? "Abort/Retry/Ignore/Fail"? Direct3D? ActiveX? DLL Hell? "There are no significant bugs in our released software that any significant number of users want fixed"? The way the MSN website seemed to deliberately break itself when people used Opera to view it?

    Microsoft is a leader that's doing a crappy job, on top of its selfish motivations. People don't like that. You may not see Microsoft as being evil, but you shouldn't be surprised or disgusted that others do.

  15. Re:Good on Trojan Built for Industrial Espionage · · Score: 1
    If I found out my users were installing Free Porn programs on their work machines, I'd make sure they were fired on the spot.

    By the time you found out, it could easily be too late.

  16. Re:oh, and another thing before XP's ready on Windows Nearly Ready For Desktop Use · · Score: 1

    That joke will have to wait in line behind my Amiga... ;-)

  17. Re:Yard Sales.. on eBay sellers Told to Include GST · · Score: 1

    48.5%???

  18. Re:On-demand is the future, today. on Television Reloaded · · Score: 2, Insightful
    Get rid of commercial skip and add fast forward. I know this option won't go well with a lot of people. Sorry. But it's a sticky situation. If ads aren't being watched, the main source of revenue for these shows suddenly disappears.

    So, if I understand this correctly, you're saying that every time technology changes in a big way, the public should give up a little bit of freedom. What will be left in 100 years?

    I watch TV a lot, but I'd rather see TV die than take away people's freedom in order to save it. But that's probably a moot point, since in reality, TV won't die: there is money to be made selling television service to consumers.

  19. checks and balances on Exporting Knowledge Via Students · · Score: 1

    With any luck, this move will soon result in the outright dropping of crypto export restrictions. Hooray!

  20. Re:Corollary: on MS Invites Security Questions · · Score: 1
    It seems that permissions in the registry are given at the "folder" rather than at the key level.

    What are "folders" in the registry, exactly? My understanding is that the registry has keys, and every key can contain other keys, an unnamed value, and multiple named values. i.e. The things that look like folders in Regedit *are* they keys, aren't they?

  21. Re:Growl on OpenBSD 3.7 Released · · Score: 1
    It makes me crazy. I can't tell you how many times I've heard "da-nis" instead of D-N-S, or "fipt" instead of F-T-P.

    Yes, those are obviously "Dennis" and "Fingertip".

  22. Re:What if... on BPL: The Internet's Fool's Gold · · Score: 1

    3 phases + neutral? I doubt it. Maybe 3 phases + strength reinforcement? IIRC, you typically wire the neutral wire (and the safety ground) to a spike in the soil.

  23. Re:Laugh Test on BPL: The Internet's Fool's Gold · · Score: 1

    Wow, do you have any idea how much optical fibre you could run alongside the existing lines for the amount that it would cost to replace every single power line in North America? With shielded cable?

  24. Re:Laugh Test on BPL: The Internet's Fool's Gold · · Score: 1

    Not only that, but I'd guess that the grid is so noisy that you'd have to transmit at a fairly high power in order to get a discernable, high-data-rate signal through it.

  25. Re:Laugh Test on BPL: The Internet's Fool's Gold · · Score: 1
    This may be a dumb question, but would the fact that the AC delivered over power lines in the UK operates at a different frequency than it does in the US make a difference in the amount/kind/acceptability of the interference produced?

    Probably not. It isn't the 50-60 Hz frequency range that are the problem, it's the frequencies above that (which are used to carry data) that are the problem. The electrical grid is essentially a big, noisy, broadcast antenna. That's fine when you're only transmitting a narrow 50 or 60 Hz signal, but it's probably terrible for much else.