Slashdot Mirror


User: asdfghjklqwertyuiop

asdfghjklqwertyuiop's activity in the archive.

Stories
0
Comments
1,548
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,548

  1. Re:How long will IPv6 last? on Military Pressuring Vendors On IPv6 · · Score: 1

    Nobody wants to expose all their internal addresses. Period. Which part of that can you dumb fucks not understand? No organisation is going to want to implement that.

    Exposing your internal addresses should be irrelevant to security unless you're doing something else wrong. Those of us that understand that are OK with our internal addresses being exposed and want them to be. A lot of organizations already do implement that even with IPv4. Which part of that do you dumb fucks not understand?

  2. Re:The cost of CA-signing each key on Database of Private SSL Keys Published · · Score: 1

    That does nothing to solve the problem. Even if they somehow got a trusted CA to sign a separate routerlogin.net cert for every router they made an attacker could still use any one of them to spoof.

  3. Re:Not pro-corporate on Republicans Create Rider To Stop Net Neutrality · · Score: 1

    Lawns and streets and certain radio frequencies are not the private property of AT&T and Comcast (FTFY). You are quite naive if you think that they have to have access to this property. If people and local governments do not give them access to this property, they would not exist.

  4. Re:But but but on FBI Alleged To Have Backdoored OpenBSD's IPSEC Stack · · Score: 1

    I really don't care if anybody hacks it.

    Well other people do. I wouldn't mind fewer machines in botnets trying to send me spam or DDoS me off the net.

  5. Re:cPanel on Remote Exim Exploit In the Wild · · Score: 1

    Sounds like some pretty neat duct tape.

  6. Re:cPanel on Remote Exim Exploit In the Wild · · Score: 1

    Does any IDS or IPS actually do that?

  7. Re:cPanel on Remote Exim Exploit In the Wild · · Score: 1

    It might be covert if you support starttls. I agree, best to apply the patches...

  8. Re:cPanel on Remote Exim Exploit In the Wild · · Score: 1

    Except a brief run of ha-ha before the mail spools get moved off to their own partition which is mounted no-exec.

    Well I hope they aren't laughing too hard. They forgot /tmp, /var/tmp, /var/run/exim4, /var/log/exim4... and anywhere else the exim user can write to. And of course, none of that wouldn't actually prevent exploitation anyway since they are already able to execute arbitrary commands as root without creating any executable files with 'exim -C' as the exim user and ${run ...}.

  9. Re:There IS some idiocy in FOSS at times ... on Remote Exim Exploit In the Wild · · Score: 1

    Impossible to configure? No, not really, even in v3. It is actually pretty nice to use if you have a complicated configuration.

  10. Re:Was fixed in 4.70 according to Mailing List on Remote Exim Exploit In the Wild · · Score: 2

    It wasn't specifically reported as a security bug 2 years ago which is probably why the fix wasn't backported to debian. Someone probably went through the bug reports looking for a potential security bug that wasn't recognized as such and developed an exploit.

  11. Re:No no no... on Gentlemen Prefer Androids, Ladies iOS · · Score: 1

    Are there any android phones that are actually open besides the Nessus One/S?

  12. Re:Owner? on Explosive-Laden California Home To Be Destroyed · · Score: 1

    The tenant did the destruction

    The tenant is no longer there. Is the house still standing? Yes or no?

  13. Re:No no no... on Gentlemen Prefer Androids, Ladies iOS · · Score: 1

    Droid, autonomous device that empowers the user through its open architecture.

    Can you tell me when they're going to follow through and actually deliver this "empowers the user" and "open architecture" stuff people keep talking about? I have a droid 2. It came with some "CityID" nagware that asks me if I want to continue using the trial version every time I hang up a phone call. It also came with Quickoffice (some office suite, I guess) which a couple weeks ago sent me some notification saying the "professional version" or whatever was on sale that day. I'd like to get rid of all these worthless apps but the phone won't let me uninstall them - the option is greyed out. I'm not feeling very empowered.

  14. Re:Yes on Apple, Microsoft, Google Attacked For Evil Plugins · · Score: 1

    Re-read. I did not say that Mozilla shouldn't provide an automatic plugin installation method because it would be bypassed. I said it is impossible for Mozilla to _prevent_ automatic installation of plugins.

  15. Re:Yes on Apple, Microsoft, Google Attacked For Evil Plugins · · Score: 1

    Trojaning the passphrase would actually be criminal

    Oh I'm sure the sheysters in their legal department could come up with some weasel words to throw into the license blab to make it "consensual".

    plus it's unnecessary in almost all cases, so there's no point in them doing it.

    In the hypothetical situation the last poster came up with where some list of authorized plugins is singed or something...

  16. Re:Yes on Apple, Microsoft, Google Attacked For Evil Plugins · · Score: 1

    They cannot add to the list without using the public key to crack the private key,

    Or trojaning the program that prompts the user for the passphrase to intercept the passphrase or just install their malware at that time.

    Microsoft, Apple, or Google wouldn't want to have headlines about how they are erasing user passwords just to install obnoxious toolbars.

    I don't give them quite so much faith. You'd think they wouldn't want headlines about secretly installing obnoxious toolbars at all, yet here we are...

  17. Re:Yes on Apple, Microsoft, Google Attacked For Evil Plugins · · Score: 1

    Encrypted with a key stored where?

  18. Re:Yes on Apple, Microsoft, Google Attacked For Evil Plugins · · Score: 1

    Because they can't make it impossible. If they do that installers will simply start directly modifying whatever file contains that list of explicitly approved plugins to add theirs to it.

  19. Re:Good email systems blocks content on Facebook Messaging Blocks Links · · Score: 1

    Uh... no. You're wrong except for the part about unwanted messages not being delivered in the first place being better than just delievered to a special place. I've been doing that with plain old SMTP for years though.

  20. Re:Okay... on UK Games Retailers Threaten Boycott of Steam Games · · Score: 1

    they have said in the past if steam were ever to go offline permanently they'd patch all the games to remove the steamworks drm.

    Where? Someone says this in every single steam discussion on slashdot, but I have yet to see it ever substantiated. Why don't they just say that in the terms of service if it is indeed the case?

  21. Re:on the fence on T-Mobile G2 'Permaroot' Achieved · · Score: 1

    At least if my desktop PC becomes infested with malware I can go to best buy and have it removed and possibly get better at not acquiring it in the first place. With Android phones the drive-by browser exploit malware installs have been replaced by uninstallable carrier-installed malware. Instead of popups about fake virus software I get notifications asking me to upgrade QuickOffice for 50% off and a message from City ID, whatever the fuck that is, asking me if I want to continue my trial or have it ask me again later every time I end a phone call.

  22. Re:on the fence on T-Mobile G2 'Permaroot' Achieved · · Score: 1

    Run the app to root the phone. You can reek plenty of havoc.

    Like uninstalling this uninstallable piece of crapware on this verizon droid 2 which asks me if I want to buy or continue a trial after every single call when I hang up on?

  23. Re:on the fence on T-Mobile G2 'Permaroot' Achieved · · Score: 1

    Kind of like how end users having direct control over their PCs has resulting in nearly all PCs made over the past 35 or so years being bricked?

  24. Re:Don't put it on the Internet! on Evaluating Or Testing Utility SCADA Security? · · Score: 1

    That way, no file transfers can take place.

    That's not necessarily true. One could still do something like "type > file" or "copy con file" or whatever and have something on their client machine that automatically sends keystrokes to create the remote file (perhaps using alt-NNN as needed for special characters).

  25. Re:But you can still get it, right? on Google Bans Sale of Android Spying App · · Score: 1

    Lockdown is becoming increasingly common in the Android phone world. Soon you may not have much of a choice. Are there any completely open android phones sold today aside from the Nexus One?