Slashdot Mirror


User: trifish

trifish's activity in the archive.

Stories
0
Comments
850
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 850

  1. And this is actually quite innocent on Pirated Android App Shames Freeloaders · · Score: 3, Insightful

    People need to realize that pirated software really is a major malware distribution channel today, and has been for several years.

    Tell your nephew that 90% of the cracks or keygens she downloads will also install a Trojan sending her passwords and credit card numbers back to the botnet masters.

    And this is not a "genuine advantage" marketing fluff -- it is hard reality.

  2. Re:And ActiveX on RSA Says SecurID Hack Based On Phishing With Flash 0-Day · · Score: 1

    You're fixing the thing at the wrong level. Try the element sitting behind the keyboard.

    (Hint: No matter how hardened your OS/browser is, there will always be unpatched security issues in them, and therefore 0-day exploits -- and yes, even in bare sans-Flash Linux or Firefox. The common element, the thing that always works for the attacker, is social-engineering, like in this case.)

  3. Re:Thanks again ADOBE on RSA Says SecurID Hack Based On Phishing With Flash 0-Day · · Score: 5, Insightful

    .. for the all-present loophole known as FLUSH (and as Flash in your HQ) and also to MicroSoft for their mega-secure OLE, etc, etc

    Sad part is trying to live without Flush and MS, is darned near impossible. The other massive and all-present loophole, also (hmm, note this) from ADOBE if PDF..... they should stick to writing PhotoShop and can all the other stuff they have tried and messed up.

    You're kidding right? The attack did not succeed because of Flash or Microsoft. It succeeded because social engineering (phishing being the kind thereof) simply works. And it will work even if the employee is running Linux without Flash. Why? Because (wait for the suprrise here) -- drumrolls -- Linux has 0-day exploits too.

  4. Re:Silly terrorists... on Convicted Terrorist Relied On Single-Letter Cipher · · Score: 2

    Shhh. Terrorists should actually keep rolling their own crypto. Many innocent lives will be saved. ;-)

  5. Re:Fuck... on Comodo Says Two More RAs Compromised · · Score: 1

    is there any reason to give these guys a second chance

    Actually, a third chance. They had a similar problem a couple of years ago.

    (That's why I've had their certs blacklisted since then. Once a CA loses trust, it can't be restored. And it shouldn't.)

  6. Re:I think they did the right thing - BOTH times on Mozilla Says It Erred On SSL Attack Disclosure · · Score: 3, Informative

    You didn't get what they did wrong. The knew about the issue 10 days before they disclosed it (and they were in fact forced to disclose it by a blogger). During that period, the affected unsuspecting people in Iran may have been exploited, snooped, arrested and/or executed. That's what they apologized for just now. But apologies won't help those victims (if there are any) a bit.

  7. Re:There's a slight problem though on RMS On Header Files and Derivative Works · · Score: 1

    The article summary ends with the nonsense that "This should help end the recent FUD about the Android 'clean headers.'"

    The FSF is nothing but a *biased* bystander. So their opinion is irrelevant at best (and misleading at worst). And it follows that their opinion therefore can't "help end the recent FUD".

  8. There's a slight problem though on RMS On Header Files and Derivative Works · · Score: 1

    The FSF is NOT the copyright holder of the Linux _kernel_ (or most of it).

  9. Re:Sad state of deletionist wankers on Old Man Murray Entry Deleted From Wikipedia · · Score: 4, Interesting

    You know what should make your scratch your head? The problem you have just described at the same time happens to be the very essence and fundamental principle of Wikipedia. That anyone, including stupid morons, trolls with hidden agenda (competitors), and outright psychopaths can edit it any and every second, repeatedly and infinitely.

    It follows that Wikipedia is, and has inherently been from the very beginning, a fundamentally flawed experiment. Thanks god Google is starting to realize this and is moving the Wikipedia result to SERPS position #5, while the first 4 links point to the authoritative or official site (if one exists).

  10. Re:Important not not authoriative on Happy 10th Birthday To Wikipedia · · Score: 1

    What's stopping you from fixing it?

    Primarily, lack of persistence to "fight" the trolls who have nothing better to do with their lives than to squat their pet articles to "preserve and protect" their versions of the articles forever.

  11. Balance on Trend Micro Chairman Says Open Source Is a Security Risk · · Score: 0

    First, everyone knows how much harder reading reverse-engineered code is compared to skimming a nice commented code.

    Second, like it or not, but in some situations, security-through-obscurity actually works (i.e. increases the security). For example, on servers which the attacker can access only via the web browser and the web application UI.

  12. Just die on Wikipedia Meets $16M Budget Goal · · Score: -1, Troll

    andnothingofvaluewillbelost

    (Plenty of karma to burn, so feel free, I don't care.)

  13. Just when you thought the Middle Ages were over... on UK Gov't Wants To Block Internet Porn By Default · · Score: 1

    ...

  14. Re:Yo, Jimmy, I've got an idea: on Should Wikipedia Just Accept Ads Already? · · Score: 1

    Consensus means that everyone agrees. Otherwise, it may just be the case of the majority of the people (idiots) trying to argue with a lonely expert. Therefore, the analogy does not work whether it was meant sarcastically or not.

  15. Re:Yo, Jimmy, I've got an idea: on Should Wikipedia Just Accept Ads Already? · · Score: 1

    attitude of the admins, that they are the expert and even if 50 editors disagree, it doesn't matter
    Umm, if the admin is a real expert, and the 50 people are not, then it should not matter that the 50 people disagree with the expert. That's why we have experts. To educate the less knowledgeable.

  16. Why the fancy name? on Microsoft Builds JavaScript Malware Detection Tool · · Score: 1

    And why not integrate it with the decent Microsoft Security Essentials?

  17. Re:But outside the US? on Google Says 3rd Parties Would Be Liable For Java Infringement · · Score: 1

    It's my understanding that if you want to preserve your rights to assert a defense, you have to assert it up front.

    Only trademark rights have to be asserted / actively defended (for example, Google opposing the verb "to google" being added to renowned English dictionaries, so as not to lose the trademark as Xerox or Kleenex).

    However, copyright and patent rights do not have to be asserted or defended to remain valid.

  18. Sun monetized Java too on Oracle To Monetize Java VM · · Score: 1

    They bundled the spyware Google Toolbar with it (optional, but opted-in by default in the installation options).

  19. Re:Justifying piracy. on Porn Maker Sues 7,000+ For Copyright Infringement · · Score: 1

    It's a pity you posted this as Anonymous Coward. I'm sure lots of people would have wanted to add you to their friends list. Because this was one of the most well written posts I've seen on Slashdot in a long time. Thanks for taking the time to write it and thanks to the mods who modded it up, and not down (as one would have expected).

  20. Umm on Hiding Backdoors In Hardware · · Score: 1

    So what exactly is new here? I thought most ./ readers already knew that you have to trust the hardware you use...

  21. Ah, so they're re-inventing the wheel again... on iPhone Jailbreak Modified Into CC Sniffing Malware · · Score: 1

    Obviously, if you're going to use pirated or [i]any[/i] other illegal kind of software, you are owned by the malware that comes with it 90%. (That's why I stopped using pirated Windows ten years ago when internet-aware malware became popular -- I didn't want to share my credit card numbers and passwords with the pirates.)

  22. Not a surprise on Hard-to-Read Fonts Improve Learning · · Score: 5, Insightful

    Instead of skimming, you are forced to actually read every word.

    Skimming is for getting an idea of what to expect to learn. Reading is for the actual learning.

  23. Re:This won't be in the public domain on Orchestra To Turn Copyright-Free Classical Scores Into Copyright-Free Music · · Score: 1

    There is no way to "create" a work into the public domain.

    I call bullshit. This is the first time EVER (seriously) I've read anything like that and I think I know quite a lot about IP and licensing.

    Do you know of any US law that forbids the author from WAIVING his/her copyrights? What happens after he/she waives the rights? The work should be instantly in the public domain! Refute my arguments, please.

  24. I smell troll on EU Surveillance Studies Disclosed By Pirate Party · · Score: 1

    surveillance could (or should) be implemented across Europe

    So how is it? Could or should? That is a world of a difference. If you don't know what you're talking about, don't talk about it. Otherwise, you're just another troll.

  25. Oh the irony on Assange Rape Case Reopened · · Score: 2, Interesting

    What made me laugh in the Bloomberg article was this gem of irony:

    "Assange is also disappointed that his name was released to the media, he said."

    (!)