Slashdot Mirror


User: Paul+Crowley

Paul+Crowley's activity in the archive.

Stories
0
Comments
1,017
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,017

  1. WPA2-AES-CCMP on CCC Hackers Break DECT Telephones' Security · · Score: 1

    WPA2 with AES-CCMP is designed by people who actually know what they're doing.

  2. Re:Insurance? on How Do I Prevent Lan Party Theft? · · Score: 1

    I wonder if the database knows how long it took to exhaust the three-digit ID space?

    I too can't resist the temptation to scan a thread that talks about low UIDs to see if I can trump the lowest one offered. You never win for long though, as I've observed before. Well, I don't anyway, maybe you do...

  3. Here's how they knew it was a honeytrap operation: on UK PM's Aide Loses BlackBerry In Chinese Honeytrap · · Score: 5, Funny

    They know what the aide looks like.

    ba-dump *tsssh*!

  4. Re:Oh, it gets even better... on Jack Thompson Served With Order to Show Cause · · Score: 1

    Did I miss the /. story about this wonderful letter? It's green ink for the Internet Age! It couldn't do better if it were in Comic Sans.

  5. It's called "jurisdiction shopping" on Are Wikileaks Servers In a Nuclear Bunker? · · Score: 1
  6. Re:Which is worth more... on Qmail At 10 Years — Reflections On Security · · Score: 1

    OK, so as the GP poster said, the PDF under discussion says no such thing. I'm glad to hear another PDF does though.

  7. Re:Qmail going public domain? on Qmail At 10 Years — Reflections On Security · · Score: 1

    That's great news! It isn't anywhere in the PDF btw - you may owe an apology to a Slashdot poster. Thanks!

  8. Re:wow on Slashdot Turns 10 But You Get The Presents · · Score: 1

    Weird - I always lose those whenever I try and join in!

  9. Re:hmmmmmm on The Soldier of the Future · · Score: 1

    I've also often wondered why the military don't go down this route so thanks for shedding some light on it. But I'm not sure I follow your argument. If the unhardened devices are a third the size, cost, and weight of the hardened ones, and we ship three unhardened devices in place of one hardened one, surely the shipping costs and such stay the same?

  10. Re:No no no to your "No no no" on Debian win32-loader Goes Official · · Score: 2, Funny

    Never start this game - you always get trumped :-)

    *waits*

  11. Re:Our research group will answer questions soon.. on Ultra-low-cost True Randomness · · Score: 1

    First, I'm sorry to bring this comment to your attention:

    http://it.slashdot.org/comments.pl?sid=292837&cid=20543831

    I've only looked at one of them:

    http://www.patentstorm.us/patents/6738294.html

    Second - what can you say about NH as an entropy distiler? Are there any nice provable properties that follow from it being a universal hash function?

    Thanks for doing interesting work!

  12. This is essentially a password cracker on SHA-1 Cracking On A Budget · · Score: 1

    He's not looking for collisions - he's looking for preimages of a given hash. Since he can't search a large enough space to find a preimage of an arbitrary hash, the most useful application of this sort of thing is password cracking - given the hash of someone's password, search the space of plausible passwords until you find one that matches the hash (taking salt into account as appropriate). Fun but not too advanced.

    Shame - what I was really hoping to read was that he'd implemented the latest collision-finding attacks on SHA-1 on FPGAs. It won't be long before we have our first real-live SHA-1 collison, and it'll be interesting to see whether it's done with special hardware like this, general purpose processors, or perhaps something curious like PS3s or video hardware.

  13. AES - how is speedup achieved? on AMD Unveils SSE5 Instruction Set · · Score: 2, Interesting

    I've just paged through the spec PDF, and I can't work out for the life of me how these instructions help you implement AES. In normal implementations AES does sixteen byte-to-word table lookups per round and these lookups take nearly all the time; they also open up a host of vulnerabilities in side channel attacks. To avoid these lookups you have to have a way of doing the GF(2^8) arithmetic directly, and I can't see any way these instructions will help.

    Anyone got any guesses? Someone who understands Matsui's recent work on bitslice AES implementations better than I do? Will this implementation be resistant to lookup-based side channel attacks?

  14. Re:how on earth? on Playing Music Slows Vista Network Performance? · · Score: 4, Funny

    Yeah, I resisted for like about three minutes.

  15. Re:how on earth? on Playing Music Slows Vista Network Performance? · · Score: 1

    It's weirdly tempting. I have learned that if I play, someone with a lower user ID than mine will always come along to play too...

  16. Re:The decline of ethics????? on Consumerist Catches Geek Squad Stealing Porn · · Score: 1

    I took some pornographic photos of a lover dressed in a schoolgirl uniform once. She looked so convincingly underage that the last photo in the series was her holding up her student pass. Her old student pass, that is - she'd graduated with an honours degree the previous year, and was something like ten years older than the photos made her look.

    Of course I was using a digicam, but I was paranoid...

  17. Re:Or 672 blade servers and 5000 cores on Stanford Gets First Sun Blackbox · · Score: 1

    HP blade servers are 6U and fit up to 16 HP ProLiant BL30 or BL35p server blades

    http://h18004.www1.hp.com/products/quickspecs/1233 0_div/12330_div.html

    You can get at least dual-core dual-processor BL35p units

    http://www.google.co.uk/search?q=bl35p+dual-proces sor+dual-core

    Not sure you can get quad-core yet, but I can't imagine that'll be long when quad-core processors are getting more commonplace.

    I think you can't quite hit these numbers - you have to put some extra support hardware in each rack. But it's not far off.

  18. Or 672 blade servers and 5000 cores on Stanford Gets First Sun Blackbox · · Score: 2, Interesting

    You could fix six 6U blade units into each of the seven general-purpose racks, and put sixteen blades into each. Put two quad-core processors on each blade, get 5376 processors into the rack. That should put you somewhere interesting in the Top500.

  19. As a phrase that gets 0 hits on Torvalds vs Schwartz GPL Wars · · Score: 1
  20. Re:A problem of abstraction on Far-Fetched Time Travel Concept Receives Private Funds · · Score: 2, Interesting

    Yes - a Type One Plot. Another example is Greg Egan's Hundred Year Diaries.

  21. It's nonsense on New Anti-Forensics Tools Thwart Police · · Score: 4, Insightful

    Encrypt once using a good algorithm. Multiple encryption is Hollywood-style security.

  22. The point is that not all radiation is ionising on BBC Kicked out of School Over Wi-Fi Scaremongering · · Score: 1

    The point isn't that WiFi is identical to light bulbs - it's ridiculous to miscronstrue him so - but that in the popular imagination "radiation" means scary ionizing radiation associated with nuclear fission and suchlike, while WiFi is "radiation" only in the same very general scientific sense that the light from a lightbulb is, and so to use the word 19 times in the programme (rather than, say, "radio waves") is scaremongering.

  23. High UID peons on The Clueless Newbie Rides Again · · Score: 1

    WTF? You don't expect me to go RTFA do you? That's what all those high UID peons are for. Someone post a cogent summary. Let me know when you get back, will you? Ta!
  24. Guns are more suited than games to honesty on PC World Editor Resigns When Ordered Not to Criticize Advertisers · · Score: 1

    This is guesswork, so tell me if I'm off base, but I suspect there are differences between the gun and games markets that make the former more suited to a magazine such as you describe.

    First, the gun market isn't so mad about novelty. A magazine could wait until a gun is on the shelves before reviewing it and the review would still be interesting to readers. Games magazines have to get the games early, so they're already getting too close to their subjects.

    Second, you can do a really thorough test of a gun in an afternoon. An afternoon playing a game won't tell you much about it.

    Third, gun buyers are generally richer than games buyers. Taken together with point two, this means that a gun review magazine could raise the money needed to do the tests entirely from the cover price, while that would be hard for a games mag.

    These probably aren't the only differences, but suffice to say that I'm not surprised that there are better reviews out there for guns than for games.

  25. Schneier didn't invent the firewall on Do We Really Need a Security Industry? · · Score: 1

    A lovely idea, but no. I don't think he's even particularly expert in that area - at least, I've never seen any papers from him about it. He's a cryptographer.

    http://en.wikipedia.org/wiki/Firewall_(networking)