Slashdot Mirror


User: Paul+Crowley

Paul+Crowley's activity in the archive.

Stories
0
Comments
1,017
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,017

  1. Re:Use a more realistic model of politics... on Defending Earth From Asteroids With MADMEN · · Score: 1

    Clearly my karma whoring skills have grown fuzzy over the years :-) or most likely, I just didn't get in early enough.

  2. Re:shouldn't ATM machines be designed better? on Visual Autopsy Of An ATM Card Skimmer · · Score: 1

    Nitpick: you don't encrypt things with private keys. This confusion arises because of a neat symmetry in the way the RSA operation works. However, in practice the way you encrypt with RSA is completely different to the way you sign with it, and of course RSA is by no means the only public-key primitive.

    In this instance I guess it would be a zero-knowledge challenge-response identity protocol, as another poster indicated.

  3. Re:Microwave/Thermal cracking on Visual Autopsy Of An ATM Card Skimmer · · Score: 1

    The tamper resistance of these cards can be defeated, but I think you'd have a hard time getting the information out using a small, disposable bit of electronics in the brief time you have access to the card.

    Especially since, to work properly, the card has to be in contact with the *real* reader, and thus not with the fake one. The cute thing about swiping is that you can read the magnetic strip as it goes by.

    If you could get prolonged access, I think Differential Power Analysis would be more fruitful than a fault-based attack.

  4. Re:Search engine spam is the key... on Search Beyond Google · · Score: 1

    That tactic won't work against PageRank - the "tiny sites" will have low rank, so they won't help increase the rank of the site they link to.

  5. Re:Very, very familiar. on Orwellian Tech Support · · Score: 1

    I'll buy this if all impediments to me switching providers in a day are removed. For dial-up Internet, I'll take a no tech support service so long as it's providing nothing but access (no email, Web hosting or suchlike) and I pay by the day or by the minute. That way, if your service breaks I can just try another provider and forget about you.

  6. Re:Today only, free access courtesy of Slashdot on Orwellian Tech Support · · Score: 1

    Yes! Thank-you! Catch-22 is a much better comparison than 1984.

  7. Google already does what you propose on Search Beyond Google · · Score: 1

    What you're describing is the basis of PageRank: links from sites with high Google karma will increase your Google karma, but a link from a site with zero karma will have no effect. You don't have to eliminate the cycles in the graph before you iterate - instead, you have a fixed "signal strength" reduction which guarantees that the iterations will converge on a single solution. It's an eigenvector finding problem. Read the original PageRank paper, or the explanation in Raph Levien's PhD. thesis.

  8. Use a more realistic model of politics... on Defending Earth From Asteroids With MADMEN · · Score: 1

    No-one is going to spend billions of dollars up front on a device that would protect us in the unlikely event of an impending asteroid collision. I'd recommend anyone wanting to do conceptual design to solve this problem assume that *no* precautions have been taken in advance, the asteroid has been discovered by an amateur astronomer about as late as you might expect... but that, in the remaining few weeks, the budget with which to build and launch their rescue plan is a few trillion dollars.

  9. Re:Anyone who intimately knows 5 on Perl's Extreme Makeover · · Score: 1

    Naah, learn Python. :-)

    But if you already know Python and are interested in getting into Perl, learn 5 now. 6 is designed for the people who know 5, and it'll be a GOOD LONG WHILE before 6 is the recommended version, so learn 5 and then see if you can get involved in making 6 happen faster.

  10. What's the security like? on Rob Enderle Announces Death of Bluetooth · · Score: 2, Insightful

    I'd use Wireless USB in preference to Bluetooth if they can get the crypto and security right. The key exchange is messed up, the encryption they used has real problems, and they elected not to include the most important component - strong authentication - meaning that it's possible (for example) for someone to inject false keystrokes if you use a Bluetooth keyboard. (about Bluetooth security Schneier talks about the keyboard injection attack)

    What I want to hear is that David Wagner, Ross Anderson and Don Coppersmith have been called in to design the security for this new protocol. Then we might see something half decent.

  11. Re:Project competition on Mandrake Blocked By XFree86 4.4 License · · Score: 1

    No, this is free software. Those who don't like the license change would always have the option of forking at the point before the change, and indeed it seems OpenBSD plan on doing exactly that. TBH I suspect that will be the major route for a while because it will take freedesktop.org a little while to be really ready for prime time.

  12. Re:Reverse psychology... on Toy Penguins and Male Egos Drove Linux Acceptance · · Score: 1

    Thankfully, this is bull. I'm a nice guy and I've never found it got in the way of getting laid a lot - quite the reverse.

  13. Disagree entirely on What to Get My Geek for Valentine's Day? · · Score: 2, Informative

    First, most people are voyeuristic enough to enjoy watching other people having sex. But in practice two of you tend to gang up on a third and do things to/with/for them, and all three roles are fun.

    Larger groups are fun too, but it doesn't seem to come down to pairing up usually.

  14. Re:Actual Performance Difference on Windows XP 64-Bit Customer Preview Program · · Score: 2, Informative

    Bignum math would benefit enormously, but it's an atypical application...

  15. Why not Rabin? on Crack the Code and Win a Million Bucks · · Score: 1

    I don't really understand why anyone uses RSA ever. For both signing and encryption there are Rabin variants faster than RSA provably as hard as factoring (and thus definitely at least as secure as RSA if not more so).

    And yes, this is a "fair" contest. I'm glad that Slashdoteers have got the message that cracking contests are generally bullshit, but this is one of the exceptions - this prize genuinely fosters research rather than trying to take its place.

  16. Re:ECC is cool but RSA better on Crack the Code and Win a Million Bucks · · Score: 1

    You can do ECC without infringing Certicom's patents pretty easily. Look for Roger Schafly's postings on the subject in sci.crypt.

  17. Re:eh, hum.... on Kodak To Stop Selling Film Cameras In U.S. · · Score: 1

    As well as giving you your coordinates in space, GPS receivers can report time very precisely.

  18. Re:Algorithm for spotting UK/EU currency... on Photoshop CS Adds Banknote Image Detection, Blocking? · · Score: 2, Funny

    Thanks! Let me just print that out for future reference.

    Hmm, seem to be having problems...

  19. Re:Are there any known MD5 collisions today? on Finding MD5 Collisions With Chinese Lottery · · Score: 1

    http://www.cs.berkeley.edu/~daw/my-posts/crypt-col lision

  20. Re:Are there any known MD5 collisions today? on Finding MD5 Collisions With Chinese Lottery · · Score: 1

    It is necessarily true that there are infinitely many MD5 collisions, by the pidgeonhole principle. However, there may be specific 128-bit strings that have 0 or 1 MD5 preimages.

  21. Re:imdb.com description on Asimov's "I, Robot" Gets Movie Treatment · · Score: 0, Troll

    Is it not bleeding obvious that the writer was taking the piss?

  22. Eddie Izzard is a straight transvestite FWIW on Eddie Izzard As ... Doctor Who? · · Score: 1

    For the record, Izzard is heterosexual.

  23. Wagner has read it but has he blessed it? on GBDE-GEOM Based Disk Encryption on FreeBSD · · Score: 1

    I'm not really convinced by the cryptography in this paper. It's good that Wagner has read it but I wouldn't interpret that as meaning he's put his seal of approval on it.

    Incidentally, I presented a paper on disk sector encryption at FSE 2000, you can read it here:

    http://www.ciphergoth.org/crypto/mercy/

  24. Re:I congratulate you sir on Groklaw Sends A Dear Darl Letter · · Score: 1

    That'll be because we all karma-whored ourselves into the stratosphere back when the system was comprehensible...

  25. Re:The Real Problem on Linux Crypto Packages Demolished · · Score: 1

    Any protocol based on IP has to handle out-of-order, missing, and duplicated packets. Using IPSec, you know that you do not have to deal with fabricated packets, and that an attacker cannot directly know anything about the content of the packets, only the timing and length.