Slashdot Mirror


User: spacerog

spacerog's activity in the archive.

Stories
0
Comments
37
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 37

  1. Re:Random? on 178 Arrested In US/EU Credit Card Cloning Ops · · Score: 2, Interesting

    "This short paper will examine several discovered statistical irregularities
    in functions used within the SecurID algorithm: the time
    computation and final conversion routines. Where and how these irregularities
    can be mitigated by usage and policy are explored."

    http://www.linuxsecurity.com/resource_files/cryptography/initial_securid_analysis.pdf

    My point is just because it is encased in plastic does not mean that the number can not be determined.

    - SR

  2. Re:Two hours? on Self-Destructing USB Stick · · Score: 4, Insightful

    "At a contest held in London, Victorinox was offering a £100,000 cash prize ($149,000) to a team of professional hackers if they could break into the USB drive within two hours. They failed."

    Umm, they weren't Pros. The contest was open to anyone who preregistered and you got to keep the knife after the contest. Not only that there were several restrictions on the contest. First you have to live in the UK, preregister and you only get two hours. Because ya know the bad guys always tell you who they are and always give up after two hours. Oh, and you have to be present to win, no Internet based attacks, you can only use Windows 64bit or whatever Linux flavor they are providing and of course you have to give up your exploit if you win. All that and more for a measly hundred thousand pounds? Yeah, no thanks, but hey it makes for great publicity and it is a cool knife.

    So called "Hacker Challenges" are not a valid security assessment.

    - Space Rogue

  3. One way to do it. on California To Move To Online Textbooks · · Score: 2, Informative
    Not all textbook companies are money grubbing thieves and some Professors are starting to wake up to that. This is my textbook for my Business Finance Class I am taking at U Mass Lowell Online

    Fundementals of Financial management

    Basically a free book with ads online, a printable PDF version for a small fee ($9.95), a slightly larger fee ($14.95) without the ads and a modest printing cost for the full book ($24.95).

    I got the printed book version. Pretty nice book to. It has no bar code but it does have an ISBN and it is marked "Not for Resale" But at under $30 including shipping I don't really care if I can resell it or not.

    This business model seems to be new in the area of text books but I like it and hope it takes off. - SR

  4. Re:30 mins might be optimistic on Could the Internet Be Taken Down In 30 Minutes? · · Score: 5, Interesting
    Actually if I remember correctly the specific flaw that we discovered waaay back in the olden days of 1999 (or was it 98?) was with the Border Gateway Protocol which would cause a cascade router failure. We estimated best case scenario that large chunks of the Internet could be unreachable for up to 12 hours and worst case could be down for several days.

    The really funny thing about all this is that after Senator Thompson and the Government Affairs committee was finished pimpimg us out as media whores several unrelated people approached us and said "Hey, where you thinking of taking the net down this way..." And we would say "No, that's not what we thought of but your idea would probably work just as well."

    The thing is many of those ideas are still valid. The global Internet network is a rickety piece of technology held together with bubble gum and bailing wire. If it wasn't for the fact that people are actively trying to keep it operational I fear it would fall apart under its own weight in a very short amount of time not to mention if someone actually wanted to take it down.

    - Space Rogue
    http://www.lopht.com
    http://www.spacerog.net

  5. Re:My experience.... on Next Pwn2Own Contest Targets IE8, Firefox, iPhone · · Score: 0


    Real hackers aren't in it for the money.
    - SR

  6. Re:There's no way they'll abuse this on Washington State Wants DNA From All Arrestees · · Score: 5, Informative
    Yup, just like they did in Massachusetts

    State hits crime lab on DNA cache, Some files improperly kept, IG says
    The State Police crime laboratory is storing the DNA profiles of hundreds of people whose crimes do not warrant it, according to an investigation of the historically troubled lab, raising the specter of what one civil libertarian called a "shadow DNA database."

    - SR

  7. Re:WarCloning? on WarCloning, the New WarDriving? · · Score: 1, Informative
    No. I know your being funny, or at least modded that way, but the correct prefix is 'war' as in WarDialing, as in War Games (the movie), which is were the term comes from. "WarCloning" is a perfectly acceptable term.

    - SR

  8. This is BS on Obama Staffers Followed Palin's Email Lead On Inauguration Day · · Score: 1
    I am an IT Manager. There is no excuse for not having email accounts, at the very least, created prior to a new employees first day.

    I get notification from my HR department about new employees at least two weeks prior to their start date. In that time I and my staff create email accounts, domain accounts, set network permissions etc... Then on their first day everything is set and ready to go. Occasionally employees are actually given web access to email before they officially start work (but not before paperwork is signed). Our employee manual specifically forbids using outside email services such as Google, Yahoo, etc... for corporate email. Not so much for security but for auditing and accountability reasons.

    There is no reason why the outgoing IT staff at the White House could not, at the very least, create email accounts for the incoming administration prior to their arrival. I sincerely hope that when the time comes for the O-Man and his cohorts to leave office that they don't go through this same mess. Inexcusable.

    - SR

  9. Twitter is already down on The Web Braces For Inauguration Traffic · · Score: 1

    Twitter is already down and it is not even 11AM EST yet.

    Granted twitter goes down ALL the time so that is not saying much.

    - SR

  10. Re:Except weight and mileage DOES count... on Oregon Governor Proposes Vehicle Mileage Tax · · Score: 1
    fuel efficient cars weigh less

    Common misconception.

    Toyata Prius Curb Weight 2000-2003 NHW11 = 1254.2 kg (2765 lb)
    Toyota Corolla LE Curb Weight 2009 = 2745 lbs

    - SR

  11. Re:I forget... on Microsoft's "Dead Cow" Patch Was 7 Years In the Making · · Score: 4, Informative

    According to Google, 1997. Yeah, over a decade ago.

    CIFS: Common Insecurities Fail Scrutiny

    - SR

  12. Veracode on Creating a Security Test Environment? · · Score: 3, Informative
    You can buy a service to test your apps for you.

    Veracode

    Based on its breakthrough binary analysis technology, Veracode offers the world's first subscription-based security testing service that provides organizations with the only automated and independent assessment of security risks in applications, whether those applications are built in house, purchased as commercial off-the-shelf software or developed offshore.

    Disclaimer: I know the founders but I am not involved in the company at all.

    - SR

  13. Re:mp3s on Seagate Ships Billionth Hard Drive · · Score: 1

    I remember buying a computer 10 years ago, and 4 GB was more than enough.

    You must be new here. :P

    My first hard drive was a Seagate. All 20MB of it. For $500.

    It was for my Mac SE. You were supposed to remove one of the 800K floppies to install it but I left both floppy drives in and still managed to squeeze the drive into place. I remember thinking that it was a pretty neat hack. Then I promptly partitioned the drive into two 10MB chunks and copied ALL of my floppies at the time onto ONE of the partitions and ran a BBS off the other one.

    Now I feel old, thanks.

    - SR

  14. Name Change on Ask the Air Force Cyber Command General About War in Cyberspace · · Score: 3, Informative

    General,
    Perhaps the reason you are having difficulty in attracting top talent is partly due to the name of your unit. Cyber Command? Sorry, but that just sounds soooo 1980's. How about Electronic Defense Command or something, anything without the word 'cyber' in it. Seriously, have there been any thoughts about a name change?
    - Space Rogue

  15. Physical Fitness on Ask the Air Force Cyber Command General About War in Cyberspace · · Score: 5, Interesting
    General, You were recently quoted in Wired as having said "So if they can't run three miles with a pack on their backs but they can shut down a SCADA system, we need to have a culture where they fit in." Is this an accurate quote? As a former member of the US Army I must say that passing a PT test is not very difficult and the suggestion that some soldiers should be exempt from basic minimum requirements is rather upsetting. Are you actually advocating the relaxation of military physical fitness standards for 'cyber warriors'? Would this not create a double standard and animosity between the cyber command and other sections of the military? Surely there must be other recruitment incentives that can be applied to attract the talent you need.

    - Space Rogue

  16. w00t comes from the dance scene of the early 90s? on 'w00t' Named 2007 Word of the Year · · Score: 1
    This article claims that w00t originated in the dance scene of the early 90s.

    The story of woot, as we know it, is simple. There were two similar songs on the charts that year. In April "Whoot There It Is" by 95 South (Ichiban Records) was the number seven best-selling song in Central Florida, according, to the Orlando Sentinel. "Whoomp! (There It Is)," by Tag Team (Life Records) out of Atlanta showed up at number 15 on Billboard's R&B singles 27 May 1993 and stayed for 45 weeks on the Billboard top 100, where it reached number 2. It was the more popular of the two songs.

    Elsewhere woot is claimed to come from root, the user name given in Unix-based operating systems to the administrator's account. This lacks any supporting evidence at all, except for dubious claims of "I remember," and is rebuffed here for the sake of completeness.

    Wasn't there a hacker group known as w00t around that time frame as well? Whatever happened to them?

    - SR

  17. ebay's Power Seller program on The Canadian Taxman Goes Browsing on eBay · · Score: 2, Informative
    According to eBay
    http://pages.ebay.com/services/buyandsell/welcome.html

    How do I qualify?

    Each month eBay automatically sends email invitations to qualified sellers. To qualify, members must:

    Have been an active member for 90 days
    Average a minimum of $1000 in sales per month, for three consecutive months
    Achieve an overall Feedback rating of 100, of which 98% or more is positive
    Have an account in good financial standing

    Although that is direct from the eBay site it is not 100% accurate. My experience indicates that invitations to the Power Seller program are based on quantity of items sold and not dollar amounts. Somewhere between 3 and 5 items per month for three or four consecutive months will trigger the invitation email. I get invitation emails quite a bit but never have I sold $1000 worth of stuff in any month let alone three consecutive months.

  18. ebay Statement on Ebay Hacked, User Info Posted · · Score: 5, Informative
    http://www.ebaychatter.com/the_chatter/2007/09/trust-safety-fo.html

    Trust & Safety forums issue this morning

    Some of our readers may have learned of an issue that occurred early this morning on one of our discussion forums. I've been talking with our Account Security and Legal teams, and I'd like to share some more details about this incident.

    Very early this morning, a malicious fraudster posted on the Trust & Safety forum on eBay.com posing as approximately 1,200 eBay users. The fraudster made these posts in a way that was intended to appear as though he logged in with their accounts. The posts contained name and contact information, which appears to be valid, and could have been secured as part of an account take over.

    The posts ALSO appeared to contain credit card information -- however, these credit cards are not associated with financial information on file for these users at eBay or PayPal. We're in the process of reaching out by phone to these members to, so that if the information is valid somehow -- regardless how this fraudster acquired the information -- these members can take the steps they need to take to protect themselves.

    eBay and our forums vendor, LiveWorld, began taking steps to remedy the situation within an hour after it started. As things evolved behind the scenes, a decision was made to make the the Trust & Safety forum unavailable to our Community. It's still temporarily inaccessible, as the teams work on this issue.

    I'll update this story later as we have more to share.

  19. Re:frequency on Sophisticated, Targeted Breakins Uncovered · · Score: 1
    Hewlett-Packard declined comment, while officials with other companies couldn't be reached for comment. A Department of Transportation spokeswoman said the agency couldn't find any indication of a security breach.

    It was not clear whether the hackers used information stolen from the personal computers

    Officials with Yahoo weren't available for comment.

    An FBI spokesman declined comment, saying it is agency policy to neither confirm nor deny whether an investigation is ongoing.

    Seems like a whole lot of nothing going on. You would think they would wait until they could get at least one external confirmation before press time. Shoddy reporting.

    - SR

  20. Adafruit? on Open Source Laser Business Opens In New York · · Score: 1

    Adafruit? haha Lemon, that's a good name. But your still Lemon! - SR

  21. Re:The default password is... on Googling for ATM Master Passwords · · Score: 2, Informative
    That is the Triton manual. That machine requires a power cycle to get to the admin interface.

    Try this instead http://www.wegrowbusiness.ca/manuals/

    The Tranax Mini-Bank 1500 doesn't require a power cycle.

    - Space Rogue

  22. Stop referancing HNN on The Founders of Whitedust · · Score: 3, Insightful
    At the same time there was something that had personally been bugging me since @stake took over hackernews and that was the lack of centralized INFOsec information; people had tried to produce a site along these lines but had either become totally bias, or been maintained badly (lack of updates etc). I saw what I considered a gap

    Gap in the market? In order to have a gap in the market you must first have a market. Why do you think that @Stake, Guardent, Foundstone, et al never made it to IPO stage? Because the bubble burst or because the market wasn't there? They were all in trouble well before the dot bomb. Sure they got bought out because they did have some cool tech, doesn't mean any of them where actually making money. Since there is no market for security specific products there definitely is no market for security news and information. Don't believe me? Look at your own home page, how many stories have comments on them? Ummm, that's right, none. You've been online a year but can't garner enough traffic to warrant any comments? Either you really suck at marketing or no one is remotely interested in your content. (I won't even mention your crappy website design.)

    Oh, and just let HNN die in piece. Stop resurecting it every other month. I mean its been what? Six years now? Jeez, let it go.

    - Space Rogue

  23. Re:Personal question for Space Rogue on Symantec Restricts Crypto Export · · Score: 2, Interesting

    Both.

    I wasn't around when @Stake was bought by Symatec. I was around for L0pht's sell-out to @Stake.

    There were two issues back then, one we were greedy, we all were. We all saw $$ signs and ran towards them. However it wasn't just the money (Which really there wasn't that much of but some of us got more than others.) We had grand visions, "Make a dent in the Universe" and all that. We were niave and believed them. It took me a few months to see the writing on the wall, then HNN got canned and I saw the @Snake for what it was.

    I sit here and wonder what could have been. At the time L0phT was pretty much self sufficient and growing. But I hvae no one but myself to blame, well for most stuff. Ah, well, like I said nothing but the memories of a bitter old man.

    - SR

  24. LC5 - L0phtCrack on Symantec Restricts Crypto Export · · Score: 5, Interesting
    It is quite a shame to think of what could have been only to see what has become.

    Yeah, I know, I'm partly at fault. Still, things could have been great.

    But hey, we were all just a bunch of FBI Snitches anyway. Which if true means that there is probably a secret back door in L0phtCrack and still in LC5 that transmits all cracked passwords direct to the FBI so that they can get into any server anywhere. Of course if that is true (and of course it is) DHS and Symantec should actively promote the use and distribution of LC5. All the more passwords they can get. Whatever.

    - Space Rogue
    L0pht Heavy Industries
    Whacked Mac Archives
    Hacker New Network
    Sell Out
    FBI Snitch

    (Pay no attention to this rambling bitter old man.)

  25. The list on MGM's DVD Class Action Settlement · · Score: 0, Redundant

    My apologies for the formatting. Just a quick copy + Paste 10 TO MIDNIGHT 1969 1984 24 HOUR PARTY PEOPLE 3 STRIKES 8 HEADS IN A DUFFEL BAG ABOMINABLE DR. PHIBES, THE ACROSS 110th STREET ALICE ALICE'S RESTAURANT ALL DOGS GO TO HEAVEN ALL DOGS GO TO HEAVEN 2 ALL OR NOTHING ALPHABET CITY AMAZING GRACE AMERICAN BUFFALO AMERICAN NINJA AMERICAN NINJA 2 & 3 AMITYVILLE HORROR, THE AMOS & ANDREW ANGEL LEVINE, THE ANGEL UNCHAINED/CYCLE SAVAGES ANGELS AND INSECTS ANNIE HALL ANOTHER WOMAN ASSASSINATION AT FIRST SIGHT AT FIRST SIGHT/KILL ME AGAIN AT THE EARTH'S CORE ATTIC, THE/CRAWL SPACE AUDREY ROSE AUTUMN IN NEW YORK AVANTI! AVIATOR, THE BABETTE'S FEAST BABY BOOM BACK TO SCHOOL BAD INFLUENCE BAGDAD CAFÉ BANANAS BAR GIRLS BARBERSHOP BASIC TRAINING BASKET, THE BEAT STREET BELIEVERS, THE BENNY AND JOON BENT BEST SELLER BILL AND TED'S BOGUS JOURNEY BILL AND TED'S EXCELLENT ADVENTURE BILLION DOLLAR HOBO, THE BIODOME BIRDCAGE, THE BIRDMAN OF ALCATRAZ BLACK CAESAR BLACK MAMA, WHITE MAMA BLACK ROBE BLACK STALLION 1 & 2, THE BLACK STALLION RETURNS, THE BLACK STALLION, THE BLUE SKY BLUE STEEL BODY OF EVIDENCE BORN ROMANTIC BOUND FOR GLORY BOXCAR BERTHA BOXING HELENA BREAKER! BREAKER! BREAKHEART PASS BREAKIN' BREAKIN' 2: ELECTRIC BOOGALOO BREAKING IN BREATHLESS BREATHLESS/RED CORNER BREEDERS BRIDE WORE BLACK, THE BRIGHT LIGHTS, BIG CITY BROADWAY DANNY ROSE BUCKTOWN BULL DURHAM BUSINESS OF STRANGERS CADILLAC MAN CAMILLE CLAUDEL CANDYMAN 2: FAREWELL TO THE FLESH CARRIE - 25TH ANNIVERSARY CARRINGTON CATCH THE HEAT CAVEMAN CHARLES BRONSON CHATO'S LAND CHEECH AND CHONG CORSICAN BROS CHERRY 2000 CHILDREN'S HOUR CHILD'S PLAY CHOCOLATE CHOOSE ME CHRISTINA'S HOUSE CITY OF INDUSTRY CITY SLICKERS CLASS CLASS/YOUNGBLOOD CLEAN SLATE COCA COLA KID, THE CODE OF SILENCE COFFY COLORS COMING HOME COMPANY BUSINESS COOLEY HIGH CORNBREAD, EARL, AND ME COTTON CLUB COTTON COMES TO HARLEM COUCH TRIP COUNT YORGA, VAMPIRE COURAGE MOUNTAIN CQ CRIME AND PUNISHMENT IN SUBURBIA CRIMES AND MISDEMEANORS CRYBANSHEE/MURDERSRUEMORGUE CUBA CUTTERS WAY CUTTING EDGE, THE CYBORG DARK HALF, THE DE SADE DEAD MAN WALKING DEAD OF WINTER DEATH WARRANT DECAMERON, THE DEFIANT ONES DELIRIOUS DELTA FORCE DELTA FORCE II DERANGED/MOTEL HELL DESERT HEARTS DESPERATE HOURS DESPERATELY SEEKING SUSAN DIGGSTOWN DILLINGER DIRTY ROTTEN SCOUNDRELS DIRTY WORK DISTURBING BEHAVIOR DOGS OF WAR, THE DOLL'S HOUSE DOMINICK AND EUGENE DONOVAN'S BRAIN DOUBLE IMPACT DR. NO DR. PHIBES RISES AGAIN DUEL AT DIABLO DUNWICH HORROR, THE EASY MONEY EAT, DRINK, MAN, WOMAN ECHO PARK EDDIE AND THE CRUISERS EDGE OF SANITY EIGHT MEN OUT ELECTRA ELMER GANTRY EMPIRE OF THE ANTS END, THE ENTERTAINER, THE EQUUS EUROPA EUROPA EVE OF DESTRUCTION EVERYTHING YOU ALWAYS WANTED EXTREME ADVENTURES OF SUPER DAVE EXTREMITIES EYE FOR AN EYE EYE OF THE NEEDLE FALCON AND THE SNOWMAN, THE FATAL BEAUTY FATAL INSTINCT FAVOR, THE FELLINI'S ROMA FIRES WITHIN FIRST POWER, THE FISH CALLED WANDA, A FIVE ON THE BLACK HAND SIDE FLAMINGO KID FLAWLESS FLED FLIGHT OF THE INNOCENT FLIRTING FLUKE FLUKE/NAPOLEON FOUR WEDDINGS AND A FUNERAL FOXES FOXY BROWN FRANKIE & JOHNNY FRENCH LIEUTENANT'S WOMAN, THE FRIDAY FOSTER FRITZ THE CAT FROGS FROM RUSSIA WITH LOVE FULL MOON IN BLUE WATER FUNNY THING HAPPENED ON THE WAY, A FUZZ FX FX2 GANGSTER NO. 1 GET SHORTY GETTING EVEN WITH DAD GHOST WORLD GIRL WITH GREEN EYES GOLDFINGER GOOD WIFE, THE GORKY PARK GREAT BALLS OF FIRE GREAT TRAIN ROBBERY, THE GREAT WALL, A GREGORY'S GIRL GUY THING, A HAIR HANDMAID'S TALE, THE HANG 'EM HIGH HANGING GARDEN HANNAH AND HER SISTERS HANNIBAL HANNIBAL/SOL HAPPY ACCIDENTS HARLEY DAVIDSON & THE MARLBORO MAN HAUNTED HONEYMOON HEART OF DIXIE HEAVY TRAFFIC HELL UP IN HARLEM HENRY V (K. BRANAUGH) HERO AND THE TERROR, THE HIDDEN AGENDA HIGH SEASON HIGH SPIRITS HOLCROFT COVENANT, THE HOLLYWOOD SHUFFLE HOM