Slashdot Mirror


User: Monkier

Monkier's activity in the archive.

Stories
0
Comments
110
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 110

  1. if you have control of the domain you can get a domain validated certificate. EFF's Let's Encrypt certificates use the ACME protocol to verify you have control of a domain: https://letsencrypt.org/docs/c...

  2. What about developers who mix tabs and spaces? on Developers Who Use Spaces Make More Money Than Those Who Use Tabs (stackoverflow.blog) · · Score: 1

    Their salary should be zero.

  3. email addresses and plain-text passwords, separated by a colon

    Always have a colon in your passwords!

  4. Interview with a career burglar on Phony Laser Security System Proves Perception Is Reality · · Score: 1

    I remember seeing some documentary interview with a career break & enter guy. He said he learned pretty quick to rob rich neighbourhoods; they had much better stuff to steal. The interviewer asked if he was worried about house alarms, and he said that the vast majority of houses he robbed had alarms not switched on or otherwise inoperable. He'd just try break in, if he didn't hear a siren he'd be in and out in a few minutes.

  5. Re:"..know who was using an IP address..." ? on German Court: ISPs Must Hand Over File Sharer Info · · Score: 1

    ..and this appeared in an Australian newspaper just yesterday "'Right to silence' law changed" http://www.smh.com.au/nsw/right-to-silence-law-changed-20120814-2462p.html

  6. Re:If you don't have javascript, you're a bot? on Company Claims 80% of Facebook Ad Clicks Are From Bots · · Score: 1

    or to extort facebook? "pay for our botnet protection, as we wouldn't want to see your advertisers getting poor value for money".

  7. Re:Interesting. on Author Kills DarkComet Spyware After Syria Uses It · · Score: 2
  8. Someone steals my identity on Cell Carriers Responded Last Year To 1.3M Law Enforcement Data Requests · · Score: 2, Interesting

    Someone steals my identity (from cards in a wallet robbed from my house) - signs up a bunch of cell phones in my name, then steps out on the bill. The police get me to fill out a form, and I spend hours dealing with 3 different cell companies, and debt collection agency.

    Do you think the police checked any cell tower data to find the perpetrator?

  9. Mock-up on Full-Body Airport Scanners Downsizing For Doctors/Dentists · · Score: 4, Funny

    Here's a quick mock-up of how it will look: http://i.imgur.com/2aA3Z.jpg

  10. Re:didnt even have devkit the first 9 months on On the iPhone and Apple's Meteoric Rise To the Top · · Score: 1

    Anyone remember this? http://www.engadget.com/2007/06/11/apple-announces-third-party-software-details-for-iphone/

    Apple announce "You won't be able to write native apps, just do everything in a browser!". They must've known they were buidling at app store at that time!

  11. Re:is YAHOO working on a smartphone?? on Is Facebook Working On a Smartphone? · · Score: 1

    The onion has covered this :) Fast foward to 2:21, the mockup phone always makes me laugh http://i.imgur.com/KO0Xg.jpg

  12. Re:Why the hell would twitter even KNOW my passwor on 55,000 Twitter Accounts Hacked, Passwords Leaked · · Score: 1

    I wish i had some mod points for you

  13. Re:on a totally unrelated unbiased note on Cash For Tweets and Facebook Posts? Aussie Startup Pays You to Astroturf · · Score: 0
  14. Re:A failure of conventional hack-ism ? on Google Ups Bug Bounty To $20,000 · · Score: 2

    Which is a much better position than "Let's pretend there's no bugs, and hush up anyone who says there is". Nice one, Google...

  15. Re:EC2? on Suggestions For Music Hosting? · · Score: 1

    S3 is just storage. Someone still needs to pay the bandwidth on the server that streams that content. Cloudfront can do streaming from your S3 store.

  16. "gaps in the security of digital certificates" on New Malware Signed With Stolen Government Certificate · · Score: 2

    So the gap is "the secret key must be kept secret"? I don't see that as a digital certificate failing. It's also the reason we have revocation lists.

  17. Why not send a hash of the email addresses on Carbonite Privacy Breach Leads To Spam · · Score: 1

    The 3rd party would only ever get the intersection of "do not mail" and their own marketing list. And emails wouldn't be sitting around in clear text in a database / filesystem..

  18. What are Supercookies - in 20seconds on Microsoft Drops Use of 'Supercookies' On MSN · · Score: 1

    Here's what 'supercookies' actually are (from the horse's mouth: http://cyberlaw.stanford.edu/node/6715)
    * you hit a page which includes a wlHelper.js script
    * wlHelper.js is served with header that tell your browser - cache this forever
    * wlHelper.js contains code something like this:
          var unique_id = 'RANDOM_LOOKING_STRING_JUST_FOR_YOU'
          if MUID cookie doesn't already exist
                set MUID cookie to unique_id

    You delete your MUID cookie - but next time you hit a page that contains wlHelper.js the cached version is pulled form your browser. unique_id is there in the cached code, so the cookie gets set again.

  19. Re:How does centralized login solve keylogging? on NYT Password Security Discussion Overlooks Universal Logins · · Score: 1

    Combine centralized and "multi-factor"? Build more PCs with smart card readers?

    I'd like to see google offer some form of multifactor on their openid provider. A keyring token generator, or maybe a smartphone app?

  20. Pay Amazon Turk to "crowdsource" it on Open Source Transcription Software? · · Score: 1

    Here's someone who has already done it..
    http://waxy.org/2008/09/audio_transcription_with_mechanical_turk/

    Split up the audio into 5 min pieces.
    Set up a template on Amazon Turk for'workers' to grab the 5 min mp3 files, and pay them $2 for each file translated.

    More info in the comments. http://www.audiobookcutter.com/ is capable of chopping up the file at the silences for you.

  21. Re:Working as a dialler coder... on When Telemarketers Harass Telecoms Companies · · Score: 1

    Could be "call back" spam, i.e. I look at my phone and see "missed call from 555-1234". I swear I didn't hear that ring, but I call the number back anyways - and I get a recorded message selling some crap. So I generally google / don't call numbers I don't recognise now. If someone has something important to tell me they'll leave a message.

  22. worm potential on Anyone Can Play Big Brother With BitTorrent · · Score: 1

    I'm surprised a nasty worm hasn't propagated via torrent client exploits. Get a list of IPs from a tracker AND the client/version they are using. Not only that: all the users would've opened the port on their router..

  23. Re:Anthropology on Professor Says UFO Studies Should Be Taught At Universities · · Score: 1

    X-files has gone off TV?

  24. Re:The new way to shut ppl down who you don't like on Questionable "Best Effort" Copyright Enforcement · · Score: 5, Interesting
    Can you easily implicate people by registering their IP address with a tracker? From the article:

    ...requests to BitTorrent trackers can also use CoralCDN, as these are simply HTTP GETs with a client's relevant information encoded in the tracker URL's query string, e.g., http://denis.stalker.h3q.com.6969.nyud.net/announce?info_hash=(hash)&peer_id=(name)&port=52864&uploaded=231374848&downloaded=2227372596&left=0&corrupt=0&key=E0591124&numwant=200&compact=1&no_peer_id=1. Notice that the HTTP request includes a peer's unique name (a long random string) and a port number, but notably does not include an IP address for that client. It's an optional parameter in the specification that many BitTorrent clients don't include. (In fact, even if the request includes this IP parameter, some trackers ignore it.) Instead, the tracker records the network-level IP address from where the HTTP request originated (the other end of the TCP connection), together with the supplied port, as the peer's network address.

    In this case CoralCDN was effectively acting as a proxy - the IP address wasn't being falsified. Although these guys did appear to have some luck with falsified IP addresses: Why My Printer Received a DMCA Takedown Notice.

  25. Re:Strike 2 on Italian Prosecutors Seek Prison Sentences For Google Execs · · Score: 1

    Two more strikes and Google gets their internet connection cut? Oh, no!