Slashdot Mirror


User: jd3nn1s

jd3nn1s's activity in the archive.

Stories
0
Comments
40
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 40

  1. Re:Pedestrian problems? on Roundabout Revolution Sweeping US · · Score: 1

    Yes! I HATE the fact they have replaced the really effective Shinfield Rd mini-roundabout with that set of lights. I tend to only drive in Reading for a week, once a year, but know it quite well because I used to live there. Also I question myself every time I have to navigate Winnersh Triangle roundabout and have ended up in Lower Earley more than once instead of Wokingham Rd.

  2. Re:5.1, 7.1, 9.1...Who needs it?? on Why Has Blu-ray Failed To Catch Hold? · · Score: 1

    It doesn't have to be gratuitous, and I like a good score arranged multi-channel - it feels more immersive. A good 5.1 system combined with a good centre speaker will allow the dialog to be more intelligible.

  3. Re:Less lines than SD in PAL on Goodbye, HD Component Video · · Score: 1

    Haha absolutely (and that is just from someone who tries to edit HD 1080i). From the viewer's perspective though I think most TVs today don't flicker at 50 or 60Hz

  4. Less lines than SD in PAL on Goodbye, HD Component Video · · Score: 1

    540p would be less lines than SD in PAL regions where SD is 576i. Actually 576i is called out as SD at the beginning of TFA. Would progressive scan really make up for this?

  5. Re:In Soviet Russia... on Russia Moves To Universal ID Card · · Score: 1

    OK gotcha - I failed to adjust my context correctly when reading your comment.

    I believe that most of the hassle of identity theft is cleaning up your credit report after the fact and letting the creditors know they've been duped.

    I do know that in the UK you can get credit without ID, and you can apply online but they mail a credit agreement for signing which you send back before you get a card.

    In the US I wonder how much of the talk of identity theft is the credit agencies selling credit report monitoring services. :)

  6. Re:In Soviet Russia... on Russia Moves To Universal ID Card · · Score: 1

    Actually I was thinking more about doing something like applying for a credit card where I don't think its necessary to supply any ID (not covered by the PATRIOT act). A few years back it was possible (don't know if it is still possible) to apply for a credit card online with not much more than your address and social security number. You could get instant approval and they'd supply the credit card number on the approval screen so you could start spending online immediately! I suspect that if someone applies for credit in your name with your social security number online this would be classed as 'identity theft'. Also if identity theft is generally only large scale operations why is talk of it so prevalent? While not a supporter of national ID cards I definitely see the benefit of a crypto card with a private key stored on it where authentication can be done via RSA or some other asymetrical algorithm. Using insecure methods to 'authenticate' (SSN, name etc) people is absolutely an issue of identity and identification! :)

  7. Re:In Soviet Russia... on Russia Moves To Universal ID Card · · Score: 1

    Does that mean that if a criminal has both those numbers he can sign up online for a credit card in your name? I think that is where a lot of identity theft issues come from: being identified by a number with no form of authentication. I've never experienced identity theft myself but I know from moving house that online credit applications never seem to complain when I give an address that isn't already on my credit file. Anyone have any statistics or info on the most common forms of identity theft are in the US?

  8. Re:New Rule: Detachment on Spoofed White House Card Dupes Many Gov't Employees, Steals Data · · Score: 1

    Both of these suggestions are cool. You could also use AppLocker on Windows to do application whitelisting.

  9. Re:New Rule: Detachment on Spoofed White House Card Dupes Many Gov't Employees, Steals Data · · Score: 1

    But you've ignored my main point which is that no alternative OS protects from this scenario (without using some unmanageable SELinux configuration that you will switch off): User gets program as attachment, authorises the running of said program and program accesses everything user normally accesses. Therefore no privilege escalation. It is not 'more secure' in this scenario.

  10. Re:New Rule: Detachment on Spoofed White House Card Dupes Many Gov't Employees, Steals Data · · Score: 1

    What privileged operation is required to access resources that are readily available to the user context? None that I can think of. You can read files and connect to the network without root/administrator. This can only be solved with a combination of policy and user education. AV and attachment filtering would be a start. As this was a targeted attack I don't think that security by obscurity would necessarily work (i.e. running a different OS)

  11. Re:AT&T deposit on AT&T Slaps Family With a $19,370 Cell Phone Bill · · Score: 1

    You guessed it: no interest.

  12. Re:Read Contracts & Limits aren't carriers wan on AT&T Slaps Family With a $19,370 Cell Phone Bill · · Score: 1

    There was when I did, as a new US arrival I had to put down an $800 deposit because I had no credit. Got it back a year later. This was AT&T

  13. Re:Problem exists between keyboard and chair. on Windows Vista SP1 Meeting Sour Reception In Places · · Score: 1

    Vista discs with SP1 included are available for download on MSDN.

  14. Re:Since when? on Cell Hits 45nm, PS3 Price Drop Likely to Follow · · Score: 2, Informative

    I believe it's because the chip is smaller therefore more fit on the same size wafer.

  15. Re:February is kind of a long time, isn't it? on Steve Jobs Announces iPhone SDK · · Score: 3, Informative

    Interesting, however typically there is no necessity for an application to be compiled from source for it to be signed. People could just sign a binary.

  16. Re:I'd much rather it... on What's Really Broken with Windows Update - Trust · · Score: 1

    The issue for me is that Windows will reboot even if you have unsaved documents open (e.g. notepad). Also if you leave a manually installed update for long enough without rebooting the popup window informing you that you need to reboot becomes a countdown to an automatic reboot, again with the potential loss of any unsaved documents. I don't think Windows Update is a bad thing, but this behaviour I find kind of annoying.

  17. Re:Putting a band-aid on a sucking chest wound on Credit-Card Data Breaches Drive Security Solutions · · Score: 1

    How do you make the payment information worthless to someone wishing to carry out fraudulent purchases without new hardware systems?

  18. Re:encrypt transmission across public networks .. on Credit-Card Data Breaches Drive Security Solutions · · Score: 1

    OK so this solution requires additional hardware to allow your computer to interface with the chip on the card.

  19. El Reg at the weekend? on Research Reveals Mislaid Microprocessor Megahertz · · Score: 4, Funny

    To me the giveaway was El Reg posting new articles at the weekend :)

  20. Re:encrypt transmission across public networks .. on Credit-Card Data Breaches Drive Security Solutions · · Score: 1

    So how does the server learn the credit card number etc necessary to perform the transaction?

  21. Re:Bullshit on Credit-Card Data Breaches Drive Security Solutions · · Score: 1

    The most recent version of PCI DSS states that any direct external availability of DBMS is an instant failure, and this is tested by the ASVs (or at least it should be). Any buffer overflows in remote available services should also be detected by the required quarterly vulnerability scans.

  22. Re:Putting a band-aid on a sucking chest wound on Credit-Card Data Breaches Drive Security Solutions · · Score: 2, Insightful

    The PCI DSS has nothing to do with stopping fraudulent credit applications. It's about making sure that payment information you have given to a merchant is protected from security breaches. The merchant is rightly responsible for this.

  23. Re:If only on Secure Programming Exams Launched · · Score: 1

    Agreed, prepared statements are definitely the best protection against SQL injections. I don't see why this point starts with a "but" though. If that is what is "recommended" then those doing the recommending need more education.

    Some blame lies with the way certain web-app languages have been put together; e.g. default output to the browser not being escaped. Further abstraction by newer languages, or in-house built layers can solve these problems though, if the programming team understands the risks.

  24. Re:If only on Secure Programming Exams Launched · · Score: 2, Informative

    I think this misses the point. Common vulnerability types could be avoided with a little education on how they actually work. By understanding how vulnerabilities come about would allow programmers to avoid creating instances of them in the first place.

    If you monitor the bugtraq list you can see that the vast majority of reported vulnerabilities are XSS and SQL injections in web apps. Most of these can be easily avoided if you know how they occur.

    This would mean less time needed for reviews as the code would be more secure in the first place.

  25. Re:High-speed on US Lags World In Broadband Access · · Score: 1

    I don't know anyone who has just a 1mbps connection any more. I have an NTL (NTHell) 10mbps cable internet service and I truly do get over a megabyte a second download if I use a FireFox download accelerator like DownThemAll.