Slashdot Mirror


User: ArsenneLupin

ArsenneLupin's activity in the archive.

Stories
0
Comments
4,557
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 4,557

  1. Re:"competing freeware program" on RealNetworks Sues Dutch Webmaster Over Hyperlink To Freeware · · Score: 1

    Blame US laws, not RealNetworks.

    Why should US laws apply to the Netherlands?

  2. Re:nginx has its problems, too. on Apache Warns Web Server Admins of DoS Attack Tool · · Score: 2

    Cant someone who pulls off a privelege escalation escape the chroot?

    Yes, he can. Basically, the trick is to do another chroot to a subdirectory, but without doing the chdir. So now the attacker is in a situation where the current directory is above the root. Here he can keep doing chdir(".."); until he reaches the real root, and then all he needs to do is chroot(".");.

    What's worse, this exploit is due to the way how chroot is spec'ed, thus it can't really be fixed by the kernel.

    So yes, you can escape a chroot jail if you've got root. However, the point of the chroot jail is to prevent attackers from gaining root in the first place, by confining them to a minimal and more controllable environment which has no spare crowbars lying around.

    Moreover, other confinements, such as BSD jails, containers or zones may not have the problem outlined above.

  3. Fuck you shima is so yesterday.. on Fukushima Robot Operator Tells His Story · · Score: 0

    ... today is North Anna, Virginia

  4. Re:I hate kids like this! on 13-Year-Old Uses Fibonacci Sequence For Solar Power Breakthrough · · Score: 1

    wooosh!

  5. Re:I'm confused on Apple Patents Cutting 3.5mm Jack in Half · · Score: 1

    ... and without a credit card, you'll have trouble attracting jacks to your plug...

  6. Re:Why not 100% wireless? on Apple Patents Cutting 3.5mm Jack in Half · · Score: 1

    Does this mean that he is a jack rather than a plug?

  7. Re:I'm confused on Apple Patents Cutting 3.5mm Jack in Half · · Score: 1

    you hit the nail on the head: with Apple, looks are everything. Function is only an accessory.

  8. Re:I'm confused on Apple Patents Cutting 3.5mm Jack in Half · · Score: 1

    And I'm going to put this exposed, surface mount, powerful magnet in my pocket with all the other flotsam? I don't think so.

    Why? Are you concerned that it will attract your jack, errr, sorry, plug?

  9. Re:I'm confused on Apple Patents Cutting 3.5mm Jack in Half · · Score: 1

    So, it would be more correct to say "plugging off"?

  10. Re:I'm confused on Apple Patents Cutting 3.5mm Jack in Half · · Score: 1

    A "jack" is a female fitting.

    So, where does the phrase "jacking off" come from?

  11. Re:Or... on Moon Younger Than Previously Thought · · Score: 1

    God just made it that way. He's makes moons however he wants.

    Exactly. So why do religious fundamentalists think it's wrong to shoot a rocket at these moons? After all, God himself made the moons such they want a rocket!

  12. Re:It's a crime to attempt a crime, or incite othe on UK Men Get 4 Years For Trying to Incite Riots Via Facebook · · Score: 1

    just planning a crime isn't a crime everywhere though.

    And that's a good thing too. We don't really want to condemn murder mystery authors doing research for a book that they are writing.

    Or fireman having an exercise of how to react to a bombing (Some amount of planning must have preceded the fake bombing to make it realistic enough for the exercise).

  13. Re:This is ridiculous on Hackers Get Their Own Scoreboard and Rankings · · Score: 1

    Not that I hack, but I've had friends who were very good hackers that wouldn't tell me ANYTHING they had done.

    So, how do you know?

  14. Re:I hope they throw the book at him on Fired Techie Created Virtual Chaos At Pharma Co. · · Score: 1

    There are no circumstances in which doing the equivalent of burning down your former place of employment is a legitmate move in a dispute.

    Yes, burning down your place of employment should only be done in context of insurance fraud, or to help them save costs of properly disposing of dangerous goods. But never for petty revenge!

  15. Re:One by one? on Fired Techie Created Virtual Chaos At Pharma Co. · · Score: 1

    I initially read this as "Never plug this in!", would have been more funny that way. Indeed if someone did plug it in (and someone would... idiots are everywhere...), Mr Cornish would have been able to share his punishment with whomever disregarded this clear instruction...

  16. Re:earthquake aftershock prediction? on Santa Cruz Tests Predictive Policing Program · · Score: 1

    ... and more importantly, how can a simulation intended to a physical phenomenon be applied to a social phenomenon governed by an entirely different mechanisms?

  17. Re:Make CA's more liable on Can We Fix SSL Certification? · · Score: 1

    A CA is an insurance company, and should be regulated as such.

    This might work when you can put a clear price-tag on a breach, but this is rarely the case.

    Just imagine the Syrian government eavesdropping on a protester's private facebook communications via a forged certificate, and using the intelligence gained to arrest and torture the protester. How could any money paid by an "insurance" compensate for this?

  18. Re:Bzzzt on Can We Fix SSL Certification? · · Score: 1

    No CA...show my id

    And guess who issued that id? A trusted third party, namely the government.

  19. Re:No on Can We Fix SSL Certification? · · Score: 1

    Does it? A botnet that gains access to a WoT (due to one person being a moron) can easily change that -- suddenly 90% of your friend's friends

    This could be addressed by the WoT software making sure that most paths of trust are independent from each other, i.e. don't pass all through the same person.

    say that cheap-rolex.in is a trustworthy site

    ... and this is the real danger! That almost nobody understands what the system is for, and issue certificates willy-nilly because they don't understand what they are for. And as misunderstanding about this whole CA and WoT business is rampant, you may indeed have more than one person who issues me an id card with Richard Stallman's name on it but my photo, simply because they think RMS is a trustworthy chap...

  20. Re:No on Can We Fix SSL Certification? · · Score: 2

    Just ask everybody you trust today whether they've ever visited diamonds-usa.com and think it's a trustworthy site.

    ... and thus making useless to them any sites that you visited.

    Congrats, you just proved brilliantly why a "web" of trust can't be trusted, even if it's only one hop "deep". Yes, I am aware that is actually the point you are trying to make, but you probably didn't intend to make in this way...

    You may trust your friends' integrity and honesty, but you better won't trust their knowledge about what a certificate actually means.

  21. Re:Can't they moderate their own wall? on Drug Companies Lose Special Protection On Facebook · · Score: 1

    Dead people don't go to job interviews

  22. Re:Obligatory DHMO comment on Drug Companies Lose Special Protection On Facebook · · Score: 1

    Quick, mod this interesting!

  23. Re:And the sad part is... on Driver Using Two Cell Phones Gets Year-Long Driving Ban · · Score: 1

    Do you think the cost of preventing drunk driving also exceeds the safety benefits?

    Yes.

    (Apart from it not being a "cost" for the state... Indeed, in both cases, the fines actually bring in revenue, rather than being costs...)

  24. Re:Diving with your knees is not dangerous on Driver Using Two Cell Phones Gets Year-Long Driving Ban · · Score: 1

    Just be sure to keep your knees together...

  25. If he didn't use his knees to steer... on Driver Using Two Cell Phones Gets Year-Long Driving Ban · · Score: 1

    ... then what body part did he use?