Slashdot Mirror


User: hawkinspeter

hawkinspeter's activity in the archive.

Stories
0
Comments
1,930
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,930

  1. Re:Also affects Linux - patch now! on Apple Pushes First Automated OS X Security Update · · Score: 1

    That's reassuring, but I wonder why Apple have rushed out this update. How many OSX users run a public NTP server?

  2. Re:Also affects Linux - patch now! on Apple Pushes First Automated OS X Security Update · · Score: 1

    Okay, not an open port, but if you request a time update wouldn't an attacker be able to respond with a spoofed malicious packet? By sending out a request, the (stateful) firewall will usually allow a response back. I'm not an expert, so I'd be interested to see if someone more knowledgeable could explain that in more detail.

  3. Re:Also affects Linux - patch now! on Apple Pushes First Automated OS X Security Update · · Score: 2

    Yes, but often the easiest way to set up a time server is to sync with a time server on the internet (e.g. ntp.pool org). As far as I can tell, a big reason for people to use NTP is that they don't have a reliable atomic clock of their own, so they sync with other people who do.

  4. Re:Put restrict ... noquery in your ntp.conf file on Apple Pushes First Automated OS X Security Update · · Score: 3, Interesting

    I hadn't spotted the "restrict ... noquery" mitigation (which luckily I already had in place), but wouldn't servers still be susceptible to spoofed packets from one of the trusted servers?

  5. Re:Also affects Linux - patch now! on Apple Pushes First Automated OS X Security Update · · Score: 1, Insightful

    Really, what's one of those?

    If you close all your NTP ports you're not going to be able to sync with a time source on the internet. Once you allow responses to your NTP queries, then you can be spoofed and compromised.

  6. Also affects Linux - patch now! on Apple Pushes First Automated OS X Security Update · · Score: 5, Informative

    This is a major bug in NTPd, so if you're using it on Linux, you'll want to patch it too (or switch to openNTP which isn't affected). The big problem is that it can be exploited with a single (specially crafted) UDP packet, so it's easy for malicious actors to probe lots of machines with very little overhead.

  7. Re:is it just... on Pirate Bay Domain Back Online · · Score: 1

    You're right, I can see it now. It definitely wasn't there yesterday as I was looking for it to see if it would get submitted.

  8. Re:is it just... on Pirate Bay Domain Back Online · · Score: 1

    You don't have to be running a public NTP server to be affected.

  9. Re:Who will get on North Korean Internet Is Down · · Score: 0

    The U.S. by the look of things. I think it'd be a bit heavy-handed to call it a proportional response though as Sony is a lot smaller than a country.

  10. Re:is it just... on Pirate Bay Domain Back Online · · Score: 1

    You're welcome. I just switched to openNTPD as I mainly use Ubuntu and they don't seem to have patched NTPd yet.

  11. Re:Another paleo-wanker... on How Venture Capitalist Peter Thiel Plans To Live 120 Years · · Score: 0

    I don't know why you're so bothered about it. If you don't like, you don't have to follow it (I don't). Look at it this way, the "paleo" people are testing if the paleo diet works and after several years we should get some free statistics on whether it makes any difference to health.

    But yes, you're right about eating a balanced diet. That's the easiest, healthiest diet we know of for now (or maybe eat Japanese food; they seem to live a long time).

  12. Re:I plan to live forever on How Venture Capitalist Peter Thiel Plans To Live 120 Years · · Score: 1

    You don't necessarily need that. If we can figure out how to extend our lives by 15 years, then we've got another 15 years to wait for another advancement. Rinse and repeat.

  13. Re:is it just... on Pirate Bay Domain Back Online · · Score: 3, Insightful

    Not quite. Maybe some people think that we should feel bad for going there, but not me (I think human culture is based on sharing whether allowed or not).

    off-topic rant, but why are submissions about the NTP flaw disappearing? I heard about the latest CERT advisory for NTP and saw that there was a slashdot submission about it, but it later disappeared. I submitted a story earlier today (bored at work), and it's now disappeared from the "submissions" list. Here's the link if you're curious: http://slashdot.org/submission...

  14. Re:I believe in Darwin on Researchers Accidentally Discover How To Turn Off Skin Aging Gene · · Score: 1

    You might find that an advantage, but the genes only care about reproduction. Maybe if perfect skin helped you take care of younger relations, then it could be selected for.

  15. Re:I believe in Darwin on Researchers Accidentally Discover How To Turn Off Skin Aging Gene · · Score: 1

    It's quite likely that it would have some consequences (our bodies are very complicated systems), but it wouldn't have been subject to selective pressure if it only has a major affect after child-bearing age. There's no advantage (in terms of gene replication) in a 60 year old having perfect skin if they're not going to be having any more offspring.

  16. Re:Mixed Feelings on Sony Reportedly Is Using Cyber-Attacks To Keep Leaked Files From Spreading · · Score: 1

    If Sony were at all concerned about the safety of their employees' private data then they would have taken steps to protect it BEFORE they were hacked. Sony have an abysmal history of computer security and this latest travesty is them trying to close the stable door after the horse has bolted in an attempt to stop their chickens coming home to roost.

  17. Re:My personal favorite of the past few years... on Excuse Me While I Kiss This Guy: The Science of Misheard Song Lyrics · · Score: 1

    Rihanna's "We found Dove in a soapless place".

  18. Re:Insulator, Isolator on 45-Year Physics Mystery Shows a Path To Quantum Transistors · · Score: 4, Informative

    I think you're confused about isolator/insulator. Wires are commonly wrapped in insulation (e.g. rubber) to prevent them conducting. You can also put insulation into your walls to reduce heat loss.

    An isolator is typically a mechanical switch that would completely disconnect an electrical circuit.

  19. Re:Removed after Initial sales spike on Australian Target Stores Ban GTA V For Depictions of Violence Against Women · · Score: 1

    Do you mean like the Call of Duty series?

  20. Re: Innaccurate on Australian Target Stores Ban GTA V For Depictions of Violence Against Women · · Score: 1

    When you write $100.000 do you mean $100 or $100,000? I can't figure out why you've got three zeroes after the decimal point unless you're using it instead of a comma.

  21. Re:Over what time interval? on The Sony Pictures Hack Was Even Worse Than Everyone Thought · · Score: 2

    If the disks were members of a RAID set, then you'd have to steal them all at the same time otherwise you'd have inconsistent filesystems. With a bit of skill, you could probably read some data, but you'd be better off transferring data over a network as that wouldn't involve physical access to a server room (which typically have some kind of monitoring cameras installed).

  22. Re:Ignored? on Hawking Warns Strong AI Could Threaten Humanity · · Score: 1

    However, if you had two AIs and one of them was focussed on replication, I'd imagine we'd end up AIs competing for resources.

  23. Re:Yawn ... on Microsoft Azure Outage Across the Globe · · Score: 1, Troll

    Don't forget leap years - 365 was quite accurate the last time Microsoft forgot about February 29th.

  24. Re:Yawn ... on Microsoft Azure Outage Across the Globe · · Score: 2

    I'm disappointed that they edited out my original comment: "Office 365 (maybe an optimistic name)".

  25. Re:I see why the boson is a "God Particle" on Elusive Dark Matter May Be Detected With GPS Satellites · · Score: 1

    Yes, they used faith rather than science, even though they were supposed to be conducting scientific experiments. Just because they were doing it wrong doesn't mean that you can extrapolate that to people who do it right.