Slashdot Mirror


User: cortana

cortana's activity in the archive.

Stories
0
Comments
2,628
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 2,628

  1. Re:Openoffice on Windows OSS Only For Administrators? · · Score: 1

    Ah, I'm glad someone else on this forum knows this. It's worth noting that this irritating limitation is gone in OpenOffice.org 2.0--there is no longer a need to maintain a machine-wide "network" install, and separate user installs for each user.

  2. Re:Support Steam on Top 20 Gaming Lows of 2004 · · Score: 1

    Not only are Valve very publicly against this practice, but it is also no good if the seller didn't take the trouble to create a separate Steam account for each game he wanted to sell.

  3. Re:Debian Unstable on Debian 3.0r4 Released · · Score: 2, Insightful

    It doesn't mean unstable as in crashing; it means unstable as in volitile, changing. Every night you can apt-get upgrade to a new host of potential problems. Stable is called such because the only changes that are ever made are backports of security fixes. Thus, stable is suitable for servers or large workstation deployments, etc, while testing/unstable are ok to use for random hacking on a desktop machine at home.

  4. Re:Well.. on Inside the Shadow Internet · · Score: 1

    Hey, hey, don't blame the (most excellent) FTP protocol just because your client couldn't resume transfers!

  5. Re:That's really sad, still on Internet Use Cuts Socializing Time · · Score: 1

    To your first paragraph: I posit that such people do exist, and may indeed read Slashdot. Just consider that you would never know about it, because the instant they mention that they don't have a TV, they are relegated to the "pompous windbag" category, and if they don't then they are assumed to _have_ a TV because it's the default...

  6. Re:Green with envy on FBI Investigating Laser Beams Pointed at Aircraft · · Score: 1

    Oh come on, this is the same kind of argument that Reagan's yes men made for the existance of (among other things) a Soviet missile defence system. The CIA repeatedly said that there was no evidence that the USSR had anywhere near the technology or resources to pull off such a thing, and that furthermore their economy was collapsing--Team B retorted that this was an elaborate ruse by the Soviets, and if the CIA couldn't see evidence of such a system then the Soviet system was obviously SO ADVANCED that it was undetetectable!

    I think it's a far more likely explanation that a copilot, cabin crewmember or passenger was messing around with a laser pointer. :)

  7. Re:Two things: on What's Wrong with Unix? · · Score: 2, Interesting

    There's actually a patch floating around that allows you to do exactly that with /proc/net/$proto/ports/$port or some such. Can't remember the name unfortunatly.

  8. Re:Fix it from the bottom up on What's Wrong with Unix? · · Score: 1

    > Decide whether we like curses or termcap, and get rid of the other one

    Hmm. Curses is a library that allows you to say stuff like "print text in bold" or "draw a box here".

    Termcap is an (obsolete) system that allows you to map operations such as "print text in bold" to the specific escape codes to do so on a particular terminal.

    Termcap is used _by_ ncurses. One cannot replace the other. Besides, termcap is obsolete, everyone (including ncurses) actually uses terminfo these days. I think...

  9. Re:Program Installation Locations on What's Wrong with Unix? · · Score: 1

    > What's the difference between the kind of installer you despise and an
    > installation script ebuild on Gentoo or a Debian installation script packaged
    > into a .deb file?

    It's all about where you get your packages from. Speaking for Debian, no package that did such things would be allowed into the archive. However, since there is no similar repository of vetted software for Windows, everyone gets software from the vendors' individual sites.

  10. Re:Program Installation Locations on What's Wrong with Unix? · · Score: 1

    $ which cp /bin/cp

    I think the poster meant that the stuff in /sbin is generally used for administration, rather than being commands that a user would often use.

    Nothing stops a user from running stuff in /sbin; ifconfig is useful, but most of the programs in there (ldconfig, fsck, mkfs and so on) won't do much without access to the system that usualy only root has.

  11. Re:BooHoo on Following up on Torrent Shutdowns · · Score: 1

    Erm, the little matter of distributing copyrighted material without the permission of the copyright holder.

  12. Re:Security? on How Can I Trust Firefox? · · Score: 1

    I am merely trying to counter the bad advice you are handing out: namely, that verifying the MD5 sums can be used as anything other than a check for file corruption. If you're not doing some kind of cryptographic check, then you can not be sure that the file is safe.

    If, in fact, this was not your position then I apologise--the ratio of signal to noise is hitting an all time low in the comments on this story.

  13. Re:BooHoo on Following up on Torrent Shutdowns · · Score: 1

    I specifically said, "the people providing the content" in order to avoid an agrument about whether hosting torrent files is legal (which from my layman's understanding of the law, it is).

  14. Re:Veri$ign on How Can I Trust Firefox? · · Score: 1

    Publik? argh! :)

    Well, the fact that the checksums are signed allows me to check that the certificate mozilla.org (hypothetically) provides is legit. Of course, most people aren't in the web of trust, the self-signed cert thing was only a suggestion as an alternative to getting a cert for TLS from Verisign, or another trusted CA.

  15. Re:BooHoo on Following up on Torrent Shutdowns · · Score: 1

    The people providing the content are not permitted to by the copyright holder.

  16. Re:Irony? on Following up on Torrent Shutdowns · · Score: 1

    Yes, it's forgery, and a damn sight more serious. What's your point?

  17. Re:Verisign Code Signing Certificate on How Can I Trust Firefox? · · Score: 1

    > The MD5 sums are posted on ftp servers all over the world, and only take a few
    > seconds to get.

    What part of this don't you understand? This is not secure at all! Again, the attacker could be sitting at your ISP, ensuring that no matter what site you visit, you recieve his poisined data.

    > Didn't say to do that - said to get the MD5 hash from a second site. quicker,
    > and easy to check - heck, you can just paste the two into an editor and eyeball
    > them if you don't trust your computer to do the job.

    The two approaches have exactly the same merit, security wise. That is, none at all. If you're not verifying that you can trust the checksums cryptographically, then you have no security at all.

  18. Re:Security? on How Can I Trust Firefox? · · Score: 1

    > You are giving people the wrong idea! There is no such thing as absolute
    > security, only levels of security.

    Of course there is no such thing as absolute security.

    However, checking the MD5 sums against the downloaded file does not help you. You must verify that the MD5 sums you have are in fact the "correct" values.

    > How do you know someone didn't tamper with the repository of certificates or
    > keys?

    If someone is messing around with stuff on my own computer, I'm fucked anyway. As for the rest of the chain, start reading here: http://www.google.com/search?q=chain%20of%20trust

    > At least by comparing the computed MD5sum from a copy of Firefox with the MD5sum
    > on the mozilla.org website, you would make it much harder for an employee at the
    > mirror site to alter Firefox without your knowledge.

    Harder, but still not good enough. What if both sites are compromised by the same cracker? What if the cracker is sitting in your ISP's server room, poisining all traffic going to your machine?

  19. Re:Verisign Code Signing Certificate on How Can I Trust Firefox? · · Score: 1

    Please actually read what I wrote, before you crack off your next wiseass reply.

    If *both* sites have been compromised by the same person, the MD5 sums will match.

    Neither site has to have actually been broken into for this to occur--a third party between you and the two sites could be altering packets as they get sent to your machine.

    If the attacker was your upstream ISP, then they would be able to poisin the traffic from any site you cared to visit.

    Presumably you trust your ISP, otherwise you wouldn't be on the Net. But do can you trust them to not have been broken into by another, malicious, party?

    For the final time, I will state that MD5 sums are (the clue is in the name) a *checksum*. Unless you get the checksums from a trusted source (eg, verify them against a Moz developer's PGP key) then you are not in a position to make the call on whether the file you downloaded has been altered.

    Downloading the same file off two sites and seeing that the two copies match does not count as verification!

  20. Re:it's lame that... on Building Applications with the Linux Standard Base · · Score: 1

    Well, the global version number _is_ the API version. The developers are making the assumption that the APIs break every new release of the software. This is a conservative decision, one that errs on the side of caution. After all, even though the API and ABI match exactly, if the behaviour of one of the functions changes, the API _is_ broken.

    But, if you want to override the extension manager, you can re-enable your disabled extensions. Google for more info.

  21. Re:Random servers on How Can I Trust Firefox? · · Score: 1

    Indeed, the dialog box should have Cancel selected as the default option. However, it is worth noting that the dialog will only ever be *displayed* if the XPI file came from a site in the user's extension installation whitelist, which by default only contains update.mozilla.org.

  22. Re:Random servers on How Can I Trust Firefox? · · Score: 1

    Please go away and read about how PGP works before cracking off a smart alec reply. You can start here.

  23. Re:Veri$ign on How Can I Trust Firefox? · · Score: 1

    Oh, or mozilla.org could use a self signed certificate, and post the sha1sum and md5sum of the publik key on their web site, along with a PGP signature.

  24. Re:Veri$ign on How Can I Trust Firefox? · · Score: 1

    You can get a certificate from another CA. Verisign is not the only other choice.

    You can view the list of trusted root CAs that IE uses (I dunno how off the top of my head). Any one of them will do.

  25. Re:I agree ... on How Can I Trust Firefox? · · Score: 1

    The MD5SUMS file can be signed, this allows you to make sure that it is trusted.

    Without using cryptography (either PGP, which mozilla.org provides in spite of what the author of the original article claims; or certificates), the MD5SUMS file is indeed just a checksum.