Slashdot Mirror


User: I+Have+a+Hard

I+Have+a+Hard's activity in the archive.

Stories
0
Comments
50
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 50

  1. cool! on Junkyard Wars Tour · · Score: -1

    Remeber back in the 80s when that Tiffany chick did a mall tour too? That was totally awesome!

  2. FYI on Eyes on Karamba · · Score: -1, Troll

    Close your web browser, shut down your fucking linux "b0xen" and go outside for once in your life.

    I think the fact that a site like slashdot, which caters to you fucking nerds out there, can't even survive without having to charge you for reading it, says alot about how much you fucks are worth to the rest of the world: ZERO.

    This should serve as a wakeup call to all you nerds out there who think that working on your b0xen in your one bedroom apartment, posting useless shit to a useless web site like slashdot and reading about the newest version of OpenBSD that can run on your fucking Dreamcast console is a good way to go through life.

    So wake the fuck up and DO something productive, something that makes money. Stop wasting your time talking about open source fucking garbage that will never amount to anything useful.

  3. May Day on The Costs of Patching · · Score: -1

    Is a celebration for the worker!

  4. Re:ILL on Ten Years of Web Browsing · · Score: -1

    are you the reason bill self left?

  5. cool, but . . . on Networked Refrigerated Microwave · · Score: -1

    I would miss yelling "Bitch, shup up and make me a samich!" too much.

  6. ummmm on Plasmon Exhibits Working Blue Laser DVD Drive · · Score: -1

    blue

  7. in case of /.ing on Security Expert Paul Kocher Answers, In Detail · · Score: -1

    1) Serious Threats?
    by Prizm

    While studying cryptanalysis, I've been learning about a number of interesting attacks such as timing attacks and differential power attacks (your specialty, if I recall). While these attacks certainly seem to help cryptanalysis of various ciphers, how practical are they in terms of real security? That is to say, what are the chances that these methods are actively being used by attackers?

    Paul:

    It depends on the target. If the system you are trying to protect isn't worth an attacker's effort, or if there are easier ways to break in, the chances are small. On the other hand, if you are protecting extremely desirable data (money, data that will affect stock prices, Star Trek episodes, government secrets, etc.) you have to assume that smart people are going to attack your security. We spend a lot of time helping credit card companies and other smart card users build testing programs -- their products need to operate in high-risk environments where DPA, timing analysis, and other sophisticated attacks are a real problem.

    2) Worst implementation?
    by burgburgburg

    In your consulting capacity (and without naming names), have you ever run across a companies security implementation that was so bad, so insecure, so open to exploitation that you felt an overwhelming compulsion to shut down the servers, lock the doors and call in a security SWAT team? That you actually felt like going out and shorting the companies stock? That you had to hold back from whomping someone upside the head? That you inquired about having the head of security investigated to make sure he wasn't a black hat hacker/competitor's security spy/foreign agent? How bad was the worst implementation you've ever seen?

    Paul:

    To save typing, can I make a list of the systems that don't make me uncomfortable?

    A smart, creative, experienced, determined attacker can find flaws in just about any standard commercial product. Our security evaluations find catastrophic problems more than half the time, even though evaluation projects generally have very limited budgets.

    The most common situation is where the systems' security objectives could theoretically be met if the designers, implementers, and testers never made any errors. For example, in a quest for slightly better performance, operating systems put lots of complexity into the kernel and give device drivers free reign over the system. This approach would be great if engineers were infallible, but it's a recipe for trouble if all you have are human beings.

    What I find most frustrating isn't bad software -- it's situations where we tell a company about a serious problem, but they decide to ignore it because we're under an NDA and therefore the problem won't hurt sales. If your company is knowingly advertising an insecure or untrustworthy product as secure, try to do something about it. Intentionally misleading customers is illegal, immoral, and a gigantic liability risk. (Keywords: Enron, asbestos, cigarettes.)

    It's also frustrating that users keep buying products from companies that make misleading or unsupported claims about their security. If users won't pay extra for security, companies are going to keep selling insecure products (and our market will remain relatively small :-).

    As for the worst security, I nominate the following password checking code:

    gets(userEntry);
    if (memcmp(userEntry, correctPassword,
    strlen(userEntry)) != 0)
    return (BAD_PASSWORD);

    ROT13 SPOILER: Na rzcgl cnffjbeq jvyy cnff guvf purpx orpnhfr gur pbqr hfrf gur yratgu bs gur hfre ragel, abg gur yratgu bs gur pbeerpg cnffjbeq. Bgure cbgragvny ceboyrzf (ohssre biresybjf, rgp.) ner yrsg nf na rkrepvfr sbe gur ernqre. [Funzryrff cyht: Vs lbh rawbl ceboyrzf yvxr guvf, unir fgebat frphevgl rkcrevrapr, pbzzhavpngr jryy, naq jnag n wbo ng n sha (naq cebsvgnoyr) pbzcnal, ivfvg uggc://jjj.pelcgbtencul.pbz/pbzcnal/pnerref.ugzy.]

    3) Int

  8. typo on Automatic Wireless Network Organisation · · Score: -1

    You misspelled organization. Please fix, thanks.

  9. burn baby burn on ELC Releases Embedded Linux Standard v1.0 · · Score: -1

    Props to GREAT WHITE and their fans!

  10. Re:interesting on Acacia Climbing the Food Chain · · Score: -1
    that was the lamest IN SOVIET RUSSIA jokes I've ever heard. I mean, it's like you aren't even trying.

  11. huh? on Acacia Climbing the Food Chain · · Score: -1

    huh?

  12. Re:Top 5 reasons to avoid Slackware on Rise of the 'Consumer' Linux Distribution · · Score: -1

    best post of the day!

  13. Re:Why do we always come back to this on Rise of the 'Consumer' Linux Distribution · · Score: -1

    You can always plug in any USB mouse.

  14. 20 seconds on Intel's Itanium 2: Succeed or Fail? · · Score: -1

    huh?

  15. /. subscription base on AOL Not Alone In Subscriber Decline · · Score: -1

    getting smaller too?

  16. german on Corporate KDE · · Score: -1

    no one who speaks german could be evil.

  17. question on Athlon 64 Pushed Back to September · · Score: -1

    does it run linux?

  18. stop it on Miyazaki Region 1 DVDs at Last? · · Score: -1

    see, it's shit videos like this that turn Pete Townshend to kiddie porn. stop it

  19. Re:First post? on Top 10 Vulnerabilities in Web Applications · · Score: -1

    You mean like this:

    hey, everybody! I'm a stupid moron with an ugly face and big butt and my butt smells and I like to kiss my own butt.

  20. Re:I love you guys on DIY Ethernet Audio Receiver · · Score: -1

    best.post.evar!

  21. wow on SGI Demos 64-Proc Linux Box · · Score: -1

    i'm imagining a beowulf cluster.

  22. cool on Zaurus Sync Software (Finally) Available for Linux · · Score: -1

    I just downloaded that song the other day.

  23. thank gawd on Libranet 2.7 Released · · Score: -1

    just what we need, yet more linux!

  24. had to be said . . . . on FSF Award for the Advancement of Free Software · · Score: 0, Flamebait

    Close your web browser, shut down your fucking linux "b0xen" and go outside for once in your life.

    I think the fact that a site like slashdot, which caters to you fucking nerds out there, can't even survive without having to charge you for reading it, says alot about how much you fucks are worth to the rest of the world: ZERO.

    This should serve as a wakeup call to all you nerds out there who think that working on your b0xen in your one bedroom apartment, posting useless shit to a useless web site like slashdot and reading about the newest version of OpenBSD that can run on your fucking Dreamcast console is a good way to go through life.

    So wake the fuck up and DO something productive, something that makes money. Stop wasting your time talking about open source fucking garbage that will never amount to anything useful.

  25. Genome sux on Genome · · Score: -1, Offtopic

    Go KDE!