Slashdot Mirror


User: Thanster

Thanster's activity in the archive.

Stories
0
Comments
19
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 19

  1. Re:Complexity arising from simplicity on Making Facebook Self Healing · · Score: 1

    Here's a real one that defeated a modern multi-path network not so long ago, constructed with WAN paths over some antiquated link encryptors. it seems that there was an undocumented (at least to the end user) "drop all keys" bit sequence. Now being a link encryptor this was parsed for within the flowing data stream, now one day an unassuming jpeg file attached to an email just by absolute chance (the bit sequence didn't have a lot of entropy to it) contained this bit-sequence, - instant denial of service attack as each link dropped, network re-converged and the still extant tcp connection between mail servers resent the offending packet until the site in question had completely isolated itself from the network. (that was a real doozer to figure out what had happened!)

  2. "As it turns out......." on Court Reinstates $675k File Sharing Verdict · · Score: 1

    This Dilbert came to mind...... http://dilbert.com/fast/2011-09-16/

  3. Re:SKY TV set top box on Anyone Besides Zune Owners With New Year's Crashes? · · Score: 4, Interesting

    Replying to myself, as I forgot my login details briefly. Sky tv set top box crashed precisely at midnight (was sadly watching the newyears TV stuff. Had to switch over to the old fashioned arial to watch the london fireworks. Did this happen to anyone else (thinking unlikely to find many people willing to admit watching the newyear on tv!) (personal excuse is having a young child!)

  4. Its probably the different pots of money question. on Antique Voyager Technology · · Score: 2, Insightful

    In (my experience of) public finances, an expenditure to re implement a protocol would be a capital expense, bring on "careful" scrutiny of the whole programme, and risk all these scientists jobs etc. (with no guarantee of getting the cash) and given that the question being answered is more than an entire career in the making (wall clock wise)......... A maintaince bill for existing equipment gets paid (almost) no questions asked.......

  5. Re:The ever heard of cost vs benefit? on AACS Revision Cracked A Week Before Release · · Score: 3, Insightful

    Slight adjustment to your formula: ProfitA = $MEDIA_INCOME - DRM R&D - DRM content - lawsuits - alienated customers - recalls (i.e. rootkit) - piracy loss ProfitB = $MEDIA_INCOME - piracy loss Kinda makes it clearer :-)

  6. Re:Dispatch the Tie Fighters on What to Do When Your Security is Breached · · Score: 1

    So, is that the Empires finest or those deadly Bangkok Chickboys? *confused*

  7. Re:CableCARD is all that matters on MythTV Vs. TiVo, Round 2 · · Score: 1

    I've got a DVB-C card working with myth-tv it does the trick for _unencrypted_ content very nicely (on uk cable networks that appears to be BBC1 BBC2 ITV and C4 (but not 5) there is is a seedy underground of "softcam" support for decrypting the other stuff.... but I havent looked at that. (mythTV wont let the project go anywhere near that stuff)

  8. Re:A step in the right direction, I think. on Open Source Federal Income Tax Software · · Score: 1

    How about a freedom of information request to release the details/specification of the API?

  9. Re:She did great! on Forbes Now Thinks Carly Saved HP · · Score: 1

    Can I ask what it is you are doing that needs 15-25 racks of servers at a time??

  10. Re:Better Universities? on Why Startups Condense in America · · Score: 1

    No No No, Left is Right and Right is Wrong!

  11. Re:Justifiable Reasoning on Policy Wonk Castigates Net Neutrality · · Score: 1

    Well, here in the uk we have a website called: http://www.theyworkforyou.com/ which allows you to track everything your member of parliment says, havent been subscribed for long, but I have to say it is a nice change from the mass media rhetoric.

  12. Re:Offtopic? on Cisco IT Manager Targeting 70% Linux · · Score: 2, Informative

    you can use samba 3 to join an active directory in full native mode (no schema extensions, no mixed mode) we have completed this on Solaris and Linux.

  13. Re:MS only use one "salt" for their hashed passwor on MS Employee Calls for No More Passwords · · Score: 1

    Incase anyone read my previous comment you may wish to look at this: /etc/shadow file for 3 user accounts fred,jane,john all having password abc123 set. fred:$1$IWCWzozx$MdJcLJ.RTg5tZXJlLHiH71:12827:0:99 999:7::: jane:$1$P0EOTtBA$1LP2mfJw9IxX6OKlIuJ12/:12827:0:99 999:7::: john:$1$7CAXAlzP$n.BEUaIRqAMbUhU6ShSqN/:12827:0:99 999:7::: A dump of a similar set of 3 users from a windows XP box: (used utility pwdump2.exe) fred:1006:78bccaee08c90e29aad3b435b51404ee:f9e37e8 3b83c47a93c2f09f66408631b::: jane:1007:78bccaee08c90e29aad3b435b51404ee:f9e37e8 3b83c47a93c2f09f66408631b::: john:1008:78bccaee08c90e29aad3b435b51404ee:f9e37e8 3b83c47a93c2f09f66408631b::: note all 3 store 2 hashed passwords (the first being the weak LM variety) and MS only uses one hash.

  14. MS only use one "salt" for their hashed passwords! on MS Employee Calls for No More Passwords · · Score: 1

    Microsoft password hash tables are WEAK why?? 2 reasons, firstly, they use one salt only for all password hashing i.e. password FRED123 will hash to AAAFda3 EVERY time, where as with Linux there are (Dependent on algorithm used) there are 4096 different hashes that could result, now your precomputed table has to be 4096 times the size. Secondly the microsoft hash table stores 2 versions of your password. 1 the normally hashed relativly safe version and 2 a truncated to 8 characters in 2 4 character block _UPPER_ _CASED_ LM hash for "backward compatability". This second hash is not only easy to precompute, (reduced character set 4 character passwords, single salt) it gives a great stepping stone to the main password!

  15. Re:Persuit of DRM policy on Cory Doctorow on Digital Rights Management · · Score: 1

    "if you build deliberately crippled tooks" I will charge you with halfling cruelty!

  16. Re:Sun will Shine at the Big Blue on SCO Says No Way To a GPL Solaris, Moves Trial Back · · Score: 1

    Hmm well how HIGH end do you want Linux to be? 256 and even 512 way penguin boxes are coming out of SGI. http://www.sgi.com/newsroom/press_releases/2004/ju ne/altix.html http://www.sgi.com/newsroom/press_releases/2004/ma rch/large_scale.html

  17. Current firmware on Netgear site "fixes" this one on Netgear's Amusing "fix" for WG602v1 Backdoor · · Score: 1

    Just checked my router:
    1.715 fixes the superman (what is it now??)
    1.714 appears to have changed super >superman (I can confirm the superman account worked :(
    1.5?? had the "super" account vulnerability. again I did confirm that this firmware had this backdoor.

    Netgear have now removed the 1.714/1.5?? firmwares from the site.

    I only hope that they have actually fixed this!!

  18. confirmation, I (was) affected by this on NetGear Also Has Remote Access Wide Open · · Score: 2, Insightful

    My home network has a wireless point that is provided by this very router, I checked, and the backdoor worked. :( The updated firmware available on netgears site fixed this :) I used to really like netgear stuff, now less so! Thanks for bringing this to my attention slashdot!

  19. Alternative (cheap) dust remover on An Affordable Air Purifier For Dusty Computer Labs? · · Score: 1

    One of the sites at my company swears by using tac mats at the entrance of their computer rooms, keeps dust way down, (a tac mat is a floor mat with layers of slightly sticky plastic that can be peeled off when the stickyness is gone.