Slashdot Mirror


User: Zaiff+Urgulbunger

Zaiff+Urgulbunger's activity in the archive.

Stories
0
Comments
1,422
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,422

  1. Re:ITS ED209!!! on New Bipedal Robot Demoed by Google X Company (i-programmer.info) · · Score: 1

    Also a little like the robots from Silent Running; not so much in how they mechanically work, but more so in the visual appearance of a bipedal robot that's relatively wide compared with it's hight.

    Do you think... nah... they wouldn't.... okay, do you think Google/Alphabet use midgets too?

  2. Re:ITS ED209!!! on New Bipedal Robot Demoed by Google X Company (i-programmer.info) · · Score: 1

    What about the very last seconds (at about 2mins 22secs) of the video? What are those things burning in the background? Quite clearly, the aftermath of a battle. Probably human remains being burnt!!

  3. Re:I thought most intelligent people did that on The FBI Director Puts Tape Over His Webcam (npr.org) · · Score: 1

    Also, what if you buy a device with a faulty switch? I think it needs another light to indicate the switch is off.

  4. theage.com.au is... on Leaked Emails Reveal Widespread Corruption in Global Oil Industry (theage.com.au) · · Score: 1

    ...robbing my computer of CPU cycles!

  5. Re:Insider Previews on Microsoft Working on Tool to Port Chrome Extensions to Edge · · Score: 1

    Do you know if MS have any extension developer docs publicly available? I'd like to see how similar it is to Chrome extension development.

  6. Re:new recommendations for drive health also out. on Study Finds That Humidity Has More Effect On Drive Failures Than Temperature (rackcdn.com) · · Score: 1

    Based on the recent finding, the IEEE has issued new guideline

    FFS - my company has just spent the last year designing and rolling out Drive Marination Process (TM), and now you're saying that's out of date?!!!

  7. Street Hawk on Autonomous Cars? How About Autonomous Bikes? · · Score: 1

    I was thinking "Street Hawk"... but then I saw the pictures.

    So... not Street Hawk then?!

  8. Re:Well????!!!111 on Linux Kernel 4.5 Officially Released · · Score: 2

    Yeah, but does it run Linux?

    As of last week, "Does it run MS SQL Server?" is the new "does it run linux".

  9. Re: There's a long history of on UK Gov't Launches Anti-Adblocking Initiative, Compares It To Piracy (thestack.com) · · Score: 1

    And why do these politicians think I should be forced to download ads to my computer? I can/will control my browser however I damn well please, thank you very much. Website owners are free to invent an algorithm that checks if my browser is downloading ads or not, and block the real content on their end. Not my fault that their server sends data when my browser requests it. Reply to This

    ^ this. Only a few days ago I had to unblock the Telegraph website because it showed an unmovable* banner otherwise. I don't much like it, but any website is free to handle this how it chooses.

    I couldn't be arsed to faff about with the browser dev-tools to get rid of it!

  10. Anyone else think it was a bit ominous it leaving the building at the end?

    Still wish they programmed it to say "YOU HAVE TWENTY SECONDS TO COMPLY". I would've!

  11. Re:Really? on New Metallic Glass Creates Potential For Smart Windows · · Score: 1

    Yep. They've invented "Glass Doors". They're like windows, but they open AND close. And you can look through them too. It's the future!!

  12. Re:Kittens & Selfies on Panasonic To Commercialize Facebook's Blu-Ray Cold Storage Systems (cio.com) · · Score: 1

    So Face book has bluerays that are full of kittens and selfies does anyone care if they store them for more than a month I mean really!

    I'm just imagining archaeologists of the future (you know, after "The Event") discovering landfill full of these disks and thinking... "but why?!!"

  13. Re:RF? on Obama Orders Feds To Study Smart Gun Technology (cnet.com) · · Score: 1

    Give me the frequencies. I'll have jammers made in China within a month.

    I suspect this is *part* of layered approach to preventing the vast number of unnecessary deaths that occur in the US every year. So this bit *might* be useful in preventing children using improperly secured weapons and inadvertently killing themselves/friends/family.

    Whether it's practical or not, I suppose is what the study will establish.

    But it's like adding safety features to anything - it likely increases the cost a bit and may result in more product failures... but on the other hand, everyone *may* be safer as a result, and less innocent people die.

  14. Re:Anyone who uses mongodb.... on Over 650 TB of Data Up For Grabs From Publicly Exposed MongoDB Database (csoonline.com) · · Score: 1

    Shard gets corrupted? Oh bad luck, thats some of your data gone - unless you've used also replication in which case you'll have spent 2 months trying to set it all up.

    To be fair, I think all exposed MongoDBs mentioned in TFA are being replicated right now, so they've inadvertently got that side of things covered! :D

  15. Re:Relative performance also interesting on HHVM Beats Stable Version of PHP 7.0 In Recent Benchmark (kinsta.com) · · Score: 1

    ..also, forgot to mention, WordPress 4.4 is noticeably worse than WordPress 3.4.1 which is unfortunate. Maybe the router handling the REST API stuff has more work to do now?

  16. Relative performance also interesting on HHVM Beats Stable Version of PHP 7.0 In Recent Benchmark (kinsta.com) · · Score: 2
    Ignoring HHVM and just focusing on PHP 7 vs. CMS and Frameworks, the results were:
    1. Laravel 5.1.11 / PHP 7: 1363.24 trans/sec
    2. Drupal 8.0.1 / PHP 7: 917.10 trans/sec
    3. October CMS / PHP 7: 407.89 trans/sec
    4. WordPress 3.4.1 / PHP 7: 306.24 trans/sec
    5. WordPress 4.4 / PHP 7: 287.92 trans/sec
    6. Magneto 2.0 CE / PHP 7: 183.87 trans/sec
    7. PyroCMS v3 b2 / PHP 7: 145.95 trans/sec

    I assume Laravel is using static content here hence it's performance, but I'm intrigued at Drupal's performance compared with October and WordPress. Is this because Drupal's sample site is simpler and had less to do, or because Drupal is better optimised/cached?

  17. Use Google Chrome-like extension interface? on Microsoft (Briefly) Reveals New Extensions For Edge, Including Reddit and Pinterest (thestack.com) · · Score: 1

    I seem to recall reading that Edge (like Firefox) will be using the same extension interface as Google Chrome. Obviously, that would make porting existing extensions to Edge rather easy.

    Does anyone know if this is still actually the case, or have they, you know, "changed a few things"?

  18. Re:Next up: on ISIS's Hunt For a Bogus Superweapon · · Score: 1

    We tell them Andromeda Strain was a documentary.

    Well, even if it isn't a documentary, I'm still drinking to stay safe!

  19. Re:Sure glad I don't have any of those! on Ad Networks Using Inaudible Sound To Link Phones, Tablets and Other Devices (arstechnica.com) · · Score: 1

    I submit to slashdot via their PostalPost(TM) feature. That's why my posts are always at least a day late! :D

  20. Re:Valid images can contain scripts on Ask Slashdot: Automated Verification For Uploaded Files? · · Score: 2
    ^ this is really really important!

    But it could be even worse depending on your server configuration. I believe (but I haven't tested) that some Apache configurations can result in unknown file extensions being ignored. So if someone uploads a file named say "myhack.php.foobar" and it is placed in a publicly accessible directory, Apache will ignore the "foobar" extension because it doesn't recognise it, and then decide it's a PHP file, and execute it.

    Also check out Apache content negotiation (and mod_mime while you're at it) and here the you see that index.html.en and index.en.html could all evaluate as index.html and you can see a similar way file naming could potentially be abused.

    The parent post describes how PHP (or any script for that matter) _could_ be injected, but doesn't completely show how it could be executed. The above gives some ideas how that might work.

    You _could_ just test that the file name ends with (.png) and Apache _should_ serve it as "image/png". But that's not secure enough for my liking, so my recommendations are:
    • 1. Don't allow users to define their own file names, or if you do, massively restrict the format to alphanumerics and a single dot png|jpg|gif extension.
    • 2. Set the directory where uploaded files are stored to NOT execute any scripts, so even if everything else fails and some how a script gets in there, it still can't be executed
    • 3. Consider not keeping uploaded files in publicly accessible directories. Instead, use a script as a proxy to read those files and serve them with a specific mime type. Thus Apache won't try to execute them and you can be certain what mime-types are being served
    • 4. Be super careful when the file is uploaded that you don't move it into a public directory BEFORE you validate it otherwise there might be a brief window to try to execute it.

    And lastly, don't leave anything to chance. This is a really risky area that a lot of people screw up! Never be complacent. Always revisit it. Don't rely on server configuration to be correct because it's too easy to set things up, then move/rebuild a server, and then find you're vulnerable. You need multiple layers of defence.

    I have a question to any who anyone who knows - why doesn't Apache demand that PHP scripts have their execute bit set? Because it seems to me that would help quite a bit.

  21. Re:Automated Air Gap on Ask Slashdot: Automated Verification For Uploaded Files? · · Score: 1

    You need to print it out, have the paper drop into a fax machine, fax to email, and then use that. It's the ONLY way to be sure you've stripped the meta-data!!!! For serious!!!

  22. Re:Maybe botnet members should be held responsible on Webmail Services Struggling Against DDoS Attacks (fastmail.com) · · Score: 1

    But the user is responsible for it. Like a car owner is responsible for their car. Users don't *have* to understand either of those things to own and use one, but they're still responsible.

  23. There are some that posit that Faraday is a thinly disguised front for Apple....

    Plus, Apple's new HQ is in the shape of... A WHEEL!

  24. Re:When I see "could" in a headline ... on British Spaceplane Skylon Could Revolutionize Space Travel (ieee.org) · · Score: 1

    When I see "could" in a headline, I add "but it probably won't/doesn't" to the end.

    Doubly so when it also has "British" in the there! (and I'm a Brit so I'm allow to be disparaging!)

  25. Re:This would have never happened. on Badly-Coded Ransomware Locks User Files and Throws Away Encryption Key (softpedia.com) · · Score: 1

    If the author decided on an open source project, the community could have found and developed a fix during beta testing.

    To be fair, the author probably coded it, posted it somewhere, tried it out and then... "oh shit!"
    So they likely half-tested it, and it did half work.