Slashdot Mirror


User: Minupla

Minupla's activity in the archive.

Stories
0
Comments
687
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 687

  1. Re:Universe Quantitized at Low Enough Level on No, We Probably Don't Live in a Computer Simulation, Says Physicist (gizmodo.com) · · Score: 1

    Agreed - and Quantum effects are discrete if someone is looking at them, which sounds a lot like a computing optimization... "Hey, I can save a lot of cycles if I just flip a coin if someone happens to look at an electron that closely and return a random spin for that electron rather then keeping track of a whole universe worth of electrons. Cool!"

    Min

  2. Enterprise solution on Ask Slashdot: How Would You Implement Site-Wide File Encryption? · · Score: 1

    I see a number of good ideas already for home-brew solutions so here's one for an enterprise out of the box solution. (usual crypto caveats apply, if you don't build it yourself, how do you know there's no backdoors... otoh, if you do build it yourself, assuming your not Bruce Schneier, how do you know you got it right? Take as directed, evaluate your risks before using)

    I've had good success with Gemalto's protectfile product in this space. The NAE device handles the master key storage, temporal keys are stored in the device driver, encrypted by the master key. Accesses can be controlled by user through any of the usual authentication mechanisms, including saying "This is my backups user, it can read only encrypted data" which is a nice feature I don't see often enough on enterprise level encryption. Saves me from having to trust the sketchy encryption on the backup solution which is almost always backed by the "trust us" guarantee.

    Min

  3. Re:So I'm going to be the grouchy old man here... on Canadian Millennials Struggle As College Degrees Don't Guarantee Jobs (www.cbc.ca) · · Score: 1

    That's a sociopolitical issue to be resolved not by minimum wage hikes or make-work programs, but by legislating shorter standard work weeks and nationalizing health benefits. Make it affordable for employers to hire more people to do the work, make it less life-affecting for people to work less.

    We can start by rolling back OT exemption rules. "Hey, you know what would be cool? If employers couldn't work you 100 hrs/wk without repercussions?"

    That's simply fixing the free market. If your business model is so broken that you're not investing in proper automation and instead are working your IT staff 60hr/wk to compensate, congratulations, we just fixed your decision making process. Go invest in some IT automation instead, (or pay the OT to your IT staff, but I'll bet you the automation is cheaper, and will create jobs in the company that produces that automation software).

    We've created a false supply, and are shocked that our job numbers aren't rising at the rate we'd like.

    OT exemption is just a corporate handout paid on the backs of the people doing the work, and I'm speaking as a manager. Fix it.

    Min

  4. Duress pin on Ask Slashdot: Would You Use A Cellphone With A Kill Code? · · Score: 1

    I'd like a duress pin instead. It lets the phone function totally as normal, except it fires an email with my location, and an email that I'm being forced to unlock my phone to my lawyer or (for my work phone) my corporate legal dept. If I'm being forced to unlock my phone, I want to make it tough to disappear me, no matter what the circumstances are.

    If you want, have it fire a user-defined script too, that way if you want to fry your crypto memory, have at it, or wipe your lastpass storage, or whatever.

    Min

  5. Re:So what? on RSA Conference Attendees Get Hacked (esecurityplanet.com) · · Score: 1

    If you're interested, most people would agree that when you connect to a defcon wifi network you should probably be... cautious. Let's face it, Defcon is to RSA from an info-risk pov as walking in downtown NY at 1am is to walking around the North/South Korean DMZ at 1am. Both are hazardous, but one of them is just plain insane.

    Now watch this: https://www.youtube.com/watch?...

    That's the 'so what'.

    And keep in mind that most ppl are still using the same passwords on multiple sites.

    Oops.

    Min

  6. Re:This won't be popular... on Should International Travelers Leave Their Phones At Home? (freecodecamp.com) · · Score: 2

    The issue is, that's not my call. I'm a professional, I travel to the US on business. In doing so, I bring data that is not mine with me. Corporate emails, credentials that could cause a CNN moment if mishandled, etc.

    Those data are stored under cryptographic control, using two factor authentication. It is not mine to decide if it's acceptable to hand it over to anyone.

    So now I need to take further steps to ensure I have access to the data required when I travel internationally to my corporate HQ, which increases the cost of doing business.

    My company will never move their HQ out of the US, but others may decide at some point that it'll cost them less in the long run.

    Min

  7. Re: Question about Canada and "media tax" on Canada Remains a 'Safe Haven' For Online Piracy, Rightsholders Claim (torrentfreak.com) · · Score: 3, Informative

    Also the caps on penalties are more reasonable here, making the "Pay us 5000, or we'll sue you for 1,000,000" threat ineffective. The max for non-commercial infringement up here is 5k. Since that's the max, in most circumstances, the judge would prove a much lower cost, say 100-200$.

    Quoting directly: "(b) in a sum of not less than $100 and not more than $5,000 that the court considers just, with respect to all infringements involved in the proceedings for all works or other subject-matter, if the infringements are for non-commercial purposes."

    The copyright trolls haven't been too interested since then.

    background if you're interested:

    http://www.michaelgeist.ca/201...

  8. Re:If the *.AA think it's bad on Canada Remains a 'Safe Haven' For Online Piracy, Rightsholders Claim (torrentfreak.com) · · Score: 1

    Honest question - how does he (and you I suppose by extension) feel about Libraries. They effectively cause the same issue for authors at a smaller scale (although maybe larger in aggregate, (not having firm numbers on ebook piracy rates vs traditional library use), especially since some libraries (my local included) offer ebook borrowing services.

  9. Time to rename Facebook on Facebook To Autoplay Videos With Sound On By Default (androidandme.com) · · Score: 2

    Time to rename Facebook RickRollBook!

  10. dubug commands on Ask Slashdot: What Are Some Things That Every Hacker Once Knew? (ibiblio.org) · · Score: 1

    debug G=C800:5 to low level format a harddrive!

  11. I avoid them for safety reasons on How UPS Trucks Saved Millions of Dollars By Eliminating Left Turns (ndtv.com) · · Score: 1

    After I got nailed making a left shortly after getting my license, I started thinking about left-turns and how much more dangerous they are then right turns. There's so many more things to account for, and more chances for other people to make errors that force me to take hazardous countermeasures. A NYC study showed they are 3 times more dangerous then right hand turns. So now unless doing the right would take me way out of my way, I do that instead.

    Remember, two wrongs don't make a right, but three rights make a left :)

    Min

  12. Re:Good. Sex and Computers dont mix on RSA: Ban On Booth Babes Has Been No Big Deal (networkworld.com) · · Score: 1

    The one that always got me was the RSA booth at Blackhat - I mean, Blackhat is in VEGAS. If you want that sort of thing, you can get it with fewer lines any number of places. But one year they had people lining up to pose with women dressed in biker costumes at the RSA booth.

    Seemed a little bit like bringing icecubes to Alaska.

    Min

  13. Re:Expand the H-1B beyond the Tech Industry . . . on Microsoft's H-1B Workers Cited In Motion That Successfully Blocked Trump's Travel Ban (geekwire.com) · · Score: 1

    Yes, let's get rid of the AMA - after all who doesn't want goat testicles? :)

    https://en.wikipedia.org/wiki/...

  14. Re:Great alternative to minefields on China Is Splashing $168 Million To Make It Rain (fortune.com) · · Score: 1

    "Make Mud - Not War" - It's been done: https://en.wikipedia.org/wiki/...

      Min

  15. Re:wipe your ass sir? on Amazon, Apple To End Audiobook Exclusivity: EU (marketwatch.com) · · Score: 1

    I'd read a book, but people get SO upset when they see me with a paperback in my hand going down the freeway... Turns out they're OK with me listening to an audiobook instead.

    Min

  16. Re:Well, as an electrician ... on Europe Calls For Mandatory 'Kill Switches' On Robots (cnn.com) · · Score: 1

    I don't know. There's precedent.

    In every subway station in my town there's a big red button that kills all power to the rails. Hitting that button would be a major PITA for everyone, but yet, it sits there, red and inviting, and somehow humans manage NOT to press the red button, years of D&D evidence to the country notwithstanding.

    Humans can be trusted with (limited) power.

    I vote we don't terminate all of them. We should keep at least 7 as historical landmarks.

    ai@google.com

  17. Re:mouse orientation on Windows 10 Will Soon Lock Your PC When You Step Away From It (theverge.com) · · Score: 1

    My replacement is changing the screen rotation. As much fun, and more visual. Also it has a handy hotkey. Ctl-Alt-Left arrow. Quick and easy to do on a walk-by.

    Min

  18. Re:Should already be habit on Windows 10 Will Soon Lock Your PC When You Step Away From It (theverge.com) · · Score: 1

    I have seen the chief of security frig around with unsecured workstations.

    Hey - I resemble that remark, although my current goto is ctl-alt-left arrow. I assume no responsibility for neck injuries resulting from use of the aforementioned keyboard combo. :)

    Min

  19. Re:My phone on Ask Slashdot: What's The Most Useful 'Nerd Watch' Today? · · Score: 1

    I wear an android watch so that I have a "Hey, look at your phone" or "Hey, get to your next meeting" reminder that's not disruptive. The fact that my time is on my wrist is a nice side effect, but mostly it avoids me having to take my phone out of my pocket in social and business situations where it would be disruptive or frowned upon.

    Looking at your watch is a LOT more socially acceptable in certain circumstances then pulling your phone out.

  20. Re:Security. on Ask Slashdot: What's The Best Job For This Recent CS Grad? · · Score: 2

    I'll second this. Weaknesses I've observed in the current crop of SEs currently in the market place are:

    1) Lack of security understanding and related defensive programming skills - If I have to tell you I found a XSS vulnerability in your code, you should be embarrassed, because you should have caught it way before I found it in QA.

    2) A lack of understanding of the world outside your box. I don't expect that you'll be able to configure a cisco router, but I DO expect you to be able to tell me what ports you're using, and details on your communication protocols (are you encrypting, if so what protocol?

    3) A lack of understanding of BASIC security principles, e.g. Authentication, Authorization, Auditing, & Availability. You should be able to rattle off what your code is doing with respect to those core needs.

    Min

  21. Re:Easy Solution - Hold Manufacturers Responsible on US Government Offers $25,000 Prize For Inventing A Way To Secure IoT Devices (ftc.gov) · · Score: 1

    Easier solution: Unplug them, remove any batteries. Security. When do I get my cheque?

  22. One would presume the same way the US can gain jobs that had yet to be lost?

  23. I know talking to myself is a bad habit, but I'll also point out that arguably the largest nation state attack on record - the RSA SecurID breach was caused by someone in HR opened an email that said 2011 recruitment plan and clicked on the attachment. Some lateral movement later, and they made it into RSA's holiest of holys. LOTS of orgs are hard and crunchy on the outside and chewy on the inside. Once you get a toehold into the network it's often a matter of time before you can move to what you're looking for.

    Min

  24. Re:Bigoted much? on FBI and Homeland Security Detail Russian Hacking Campaign In New Report (theguardian.com) · · Score: 4, Informative

    At the end of the day, you don't get style points in the spy game. If script kiddie level efforts give you the results you want and you don't really care about not being caught, script kiddie level stuff it is.

    Governments have engaged in similar script kiddie level attacks in the past, both before and after the digitial age ("You've won a contest, come collect your prize here!", criminal shows up to collect prize, gets a pair of handcuffs)

    This stuff is low-risk, high reward. Attackers only need to get lucky once, defense has to be good every time.

    Min

  25. Re:This is interesting but.. on The Farmer Who Built Her Own Broadband (bbc.com) · · Score: 1

    This is true so long as the big telcos care.

    Had this experience about a month ago:

    Big Telecom (Rogers) comes to the door

    "Hi! I'd like to lower your internet bill. If I can't give you better service for less, I won't waste any more of your time. Are you using Bell?"

    "No, Teksavvy"

    "OK, I won't waste any more of your time then. Have a nice evening" :)

    Min