Slashdot Mirror


User: SwashbucklingCowboy

SwashbucklingCowboy's activity in the archive.

Stories
0
Comments
645
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 645

  1. Lobbyists

  2. Re:Issue is more complicated on Linux Kernel Dev Sarah Sharp Quits, Citing 'Brutal' Communications Style · · Score: 1

    You don't have to be nice, but be respectful. The problem is Linus has cultivated an environment where there is no respect for a person for just being a person. He only respects people that agree with him and think the way he does. Basically, it's an easy way to rationalize being an asshole and it being okay.

  3. Re:Priorities on Obama Administration Explored Ways To Bypass Smartphone Encryption · · Score: 1

    There will always be "baddies" no matter how good the world is.

  4. At Least Someone in Government Has a Brain on Obama Administration Explored Ways To Bypass Smartphone Encryption · · Score: 1

    "Any proposed solution almost certainly would quickly become a focal point for attacks."

    Glad someone realized that!

  5. Re:testimonial privilege is not immunity though on Phone Passwords Protected By 5th Amendment, Says Federal Court · · Score: 1

    True, which is why you need to use a password that's long enough that it can't be brute forced. I use an 18 character password that includes non-ASCII characters. Good luck brute forcing that before I'm dead.

  6. If the Air Force Won't Fly Them on The WWII-Era Inspired Plane Giving the F-35 a Run For Its Money · · Score: 1

    Then the Army should tell the Air Force to take a hike and fly them itself.

  7. Re:How is this possible? on Symantec Subsidiary Thawte Issues Rogue Google Certificates · · Score: 1

    "Someone would have to deploy these certificates on a service that was either a Google property or was masquerading for a Google property"

    No, they wouldn't. They could do on an internal network and test there.

  8. Where were the keys stored? on 2.4 Million Customer's Records Stolen From Carphone Warehouse · · Score: 1

    Doesn't matter if they were encrypted if they decryption key(s) were also stolen...

  9. It's Even Worse for Insurance Companies... on Will Autonomous Cars Be the Insurance Industry's Napster Moment? · · Score: 4, Insightful

    With automated cars, taxis will become much less expensive meaning that fewer people will buy cars so fewer people will need insurance. 20 years from now things are going to be VERY different...

  10. Shouldn't be dogfighting anyway on Test Pilot: the F-35 Can't Dogfight · · Score: 1

    But not having enough room in the cockpit to turn your head is bad. Really bad.

  11. Re:Feh. The Java sandbox, Part II on WebAssembly: An Attempt To Give the Web Its Own Bytecode · · Score: 1

    But one set of injected code works everywhere with this. Not so with JavaScript.

  12. New Thing for Hackers to Attack on WebAssembly: An Attempt To Give the Web Its Own Bytecode · · Score: 1

    Great... Just what we need... Another virtual machine for hackers to attack...

  13. Re:2 factor authentication would have. on Encryption Would Not Have Protected Secret Federal Data, Says DHS · · Score: 1

    Air gapped is good - very good. But not full proof.

  14. Re:2 factor authentication would have. on Encryption Would Not Have Protected Secret Federal Data, Says DHS · · Score: 1

    Don't get cocky kid. In the RSA breach the hackers went after material used in SecurID (RSA's 2FA product). They're going after phones with the 2FA apps on them too.

    Yeah 2FA is good security practice and its use will it make it significantly harder to breach a system using legitimate credentials, but the notion that it's full proof (or fool proof) is a myth.

  15. It's Better and Worse Than This... on Report: Aging Java Components To Blame For Massively Buggy Open-Source Software · · Score: 1

    It's better in that just because a component has a vuln doesn't mean that vuln is exploitable in all situations. Unfortunately, people are TERRIBLE at determining if a vulnerability is potentially exploitable or not.

    It's worse in that the data in the NVD is often wrong and has lots of missing versions. For example, CVE-2013-5960 says "The ... in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.1 " and it lists the affected versions only as 2.0.1. The description is wrong (the issue was fixed in 2.1.0) and the list of versions is incomplete as there are more versions that are affected. Another example, CVE-2014-3604 says "Certificates.java in Not Yet Commons SSL before 0.3.15 ..." and then lists the affected versions as 0.3.15 - which is the version it was fixed in and it doesn't list the versions that were actually affected.

  16. Re:The root cause : poor unit testing on Report: Aging Java Components To Blame For Massively Buggy Open-Source Software · · Score: 1

    Sorry, but no, it's not that simple. Lots of vulnerabilities come into a project because of dependencies that are poorly managed. Project A depends upon project B which in turn depends upon project C and C has the vuln. All the unit testing of A in the world will not turn up that vuln. That requires system testing and that's a lot more involved.

  17. Car ownership will plummet on Self-Driving Cars To Transform Insurance and Other Industries · · Score: 1

    Taxis become much more economical when you don't need a human to drive it any longer.

    Imagine the social upheaval of all those now unemployed taxi drivers. And will people in the future understand Scorsese's film?

  18. Love Pipes on Yahoo Killing Maps, Pipes & More · · Score: 1

    Losing it sucks. Not sure how to replace it.

  19. Principal Needs to Talk to an IP Attorney on Student Photographer Threatened With Suspension For Sports Photos · · Score: 1

    After a five minute discussion the principal will be apologizing to the student and his family.

  20. Re:The two things that have led me to oppose the D on Dzhokhar Tsarnaev Gets Death Penalty In Boston Marathon Bombing · · Score: 0

    There is disagreement over that.

    "The new deterrence research has been discussed favorably and uncritically by national news outlets and has been declared persuasive in leading academic journals and by prominent scholars and jurists. Legal academics, such as Professors Cass Sunstein and Adrian Vermeule, both of the University of Chicago, find the new deterrence evidence "powerful" and "impressive." They couple it with "many decades of reliable data about [capital punishment's] deterrent effects" as the "foundation" of their argument, which holds that since "capital punishment powerfully deters killings," there is a moral imperative to aggressively prosecute capital crimes. Prof. Becker concurs, finding the evidence "persuasive," while Judge Richard Posner brushes aside worries about the possible execution of the innocent as we ramp up executions to achieve even greater deterrent effects. Twice, authors of some of the articles have appeared before the U.S. Congress, stating the case for deterrence."

    https://www.law.columbia.edu/l...

  21. "Why don't these companies provide verification" on Ask Slashdot: How Does One Verify Hard Drive Firmware? · · Score: 1

    Because it's never been an issue before.

  22. Re:How is this even necessary? on FBI Attempts To Prevent Disclosure of Stingray Use By Local Cops · · Score: 1

    Great line from Sneakers!

  23. Re:90 days is really long on Google Releases More Windows Bugs · · Score: 1

    "90 days is really long."

    Cow manure.

    It's short when fixing vulns in an OS and delivering a real product.

  24. Re:Hope the trend continues. on Google Releases More Windows Bugs · · Score: 1

    90 days is not a lot of time.

  25. Re:Hope the trend continues. on Google Releases More Windows Bugs · · Score: 1

    "Google doesn't care about Microsoft's internal BS. Why should it?"

    Because releasing that data two days before Microsoft releases a fix makes the world less secure, not more secure. The point of doing that security research is to make the world more secure, then Google does stupid shit and does the opposite.