Slashdot Mirror


User: fluffy99

fluffy99's activity in the archive.

Stories
0
Comments
1,632
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,632

  1. Re:Can anyone here actually pay attention? on Embedded Microchips In Virtually Everything · · Score: 1

    Quit shouting, it makes you look like a freaking idiot. Try reading http://www.foodproductiondaily.com/news/ng.asp?id=52356-long-distance-rfid , and http://en.wikipedia.org/wiki/RFID for starters. Or google and find the article when a guy build an rfid sniffer that could eavesdrop on an rfid exchange between a reader and chip from 30-meters away. It's not as implausible as you make it sound.

    Why bother putting cameras on all the street corners and deal with face recognition software to track people, like England? It's easier to put rfid readers on all the street corners and record all the rfid tags. The credit card companies are starting to put rfid in the credit cards and those would be damn easy to track or copy if you're a thief. Or similar to http cookies, notice the combination of size 11 purple nikes, walmart brand socks, size large fruit of the loom mini-briefs, and trojan condoms in the wallet passing by the scanner.

  2. Re:As eerie as it is... on Classified Cyber-Security Directive Puts NSA In Charge · · Score: 1

    Read what I wrote again. It didn't dispute that they fall under the Secretary of Defense and were not technically a DOD agency. While they do fall under the Secretary of Defense, and have military personnel, they are outside of the normal DOD functions and function a bit more like a sole-source contractor for the functions they provide the military (intel, comsec, IA functions). They provide services to the army/navy/airforce but do not answer directly to them.

  3. Re:As eerie as it is... on Classified Cyber-Security Directive Puts NSA In Charge · · Score: 1

    They aren't a DOD agency in the normal sense. They have a flag officer, but they are outside of DOD for all intents and purposes. The DOD already has a joint network protection group (JTF-GNO) and they are monitoring and protecting their networks across the three branches fairly well now. NSA provides input and expertise, but they aren't doing any of the actual work. The agency that is supposed to be doing this is DISA, but their too screwed up to do anything but manage the telco stuff (and poorly at that). This initiative is probably aimed at all the non-military Federal governments that have a crappy track record of protecting and monitoring their networks. If I had to guess, I'd say the initiative calls for putting all of the federal agencies on their own network and get down to a couple of easy to monitor and protect, internet access points like the DOD did.

    Personally, I'm all for having NSA monitor for attack activity and actually having the ability to stop an ongoing attack originating from outside of the US. One problem is that these attack can, and frequently do, originate from compromised computers within our borders. At that point, it becomes a question of whether you call it monitoring or spying.

  4. Re:Fewest Admitters = Fewest Flaws on Microsoft Says Vista Has the Fewest Flaws · · Score: 1

    You'll get it if your system doesn't have the proper print driver and needs to pull it from the print server. A print server with malicious drivers is very obscure and little considered way of hacking. A major company I known got stung this way, when an admin user connected to an untrusted windows print server which provided a nice custom set of unsigned print drivers to the client computer.

  5. Re:I, for one on Malware Distribution Through Physical Media a Growing Concern · · Score: 1

    Given how aggressively the Chinese are spying on the US govt and commercial industry, it wouldn't surprise me to see malicious code on computers and devices shipping from China. It wouldn't be common stuff that the a/v vendors have signatures for either. I'd guess this was suspected by the govt at some point because there was a brief ban on buying systems from Lenovo. First think I do with any new computer is to nuke and reinstall from a known good source. At the very least this dumps all the adware/spyware that come preinstalled.

  6. Re:Registries and stupid ideas on Malware Distribution Through Physical Media a Growing Concern · · Score: 2, Interesting

    IF you have thousands of machines, it's likely you have Active Directory by now. Simply set the autorun, as well as the tons of other security settings, in a group policy and be done with it.

  7. Re:Autorun is evil on Malware Distribution Through Physical Media a Growing Concern · · Score: 1

    Can I have some of what you're smoking? Linux is infamous for forcing the user to chase down so esoteric option in a text config file. Of course, Windows is really confusing - it's called hold down shift when you insert the USB key (something they stole from Mac, btw).

  8. Re:far too dangerous for kids on How to Say Goodbye to Old Hard Drives? · · Score: 1

    I'll say. Usually when I destroy a hard drive, I'd rip out the magnets, bend the platters and throw it in the trash. I found out the hard way about the glass platters when one shattered instead of bending. Pulling that chunk out of my thumb hurt like hell and bled like crazy. Worst part was having to dig around and make sure all the pieces were out. Now I whack the platters to see if they shatter first. If they dent instead then it's safe to fold them up like a taco.

  9. Re:Papers please on National ID Cards Mandated in the US, If You're Under 50 · · Score: 1

    You forgot requirements on data storage and accessibility for the new US Gestapo. Effectively it is a national ID. All the licenses will look similar and Homeland Security will have access to all the data. The govt can't directly require the states to do anything with drivers licenses, but they've found another loophole to coerce the states into giving them what they want. The other way to strongarm the citizens and states is to make it difficult to get a passport but allow state drivers licenses to function as passports if the states conceded to the government. For other stuff like national speed limits, and the "no child gets ahead" program, the govt holds funding hostage unless the states comply. Personally, I'm tired of a federal government that keeps blackmailing the individual states. It's a complete violation of the intent of the 10th Amendment. http://en.wikipedia.org/wiki/Tenth_Amendment_to_the_United_States_Constitution

  10. Re:Linux ACLs on Mastering POSIX File Capabilities · · Score: 1


    It's only too complicated on Linux. Heck, I'm be thrilled if Samba handled file permissions correctly let you change permissions without having to ssh in and do it as root. No problem though, I run my file servers on Windows where I don't have to mess with such crap.

    Goof ups similar to your VMS example are very easy to run into under both Linux and Windows too. Try using the EXT extended attributes to apply acls. A few setuid tools totally ignore them, and they disappear with back and restore. Plus you need to be root to use them in the first place. Another good example is users setting file permissions on a MS Word file. Next time the user saves the document it will assume the default permissions of the folder it's in (because word saves a a temp file, deletes the original and renames the temp file). Maybe I'm making the case that permissions should be kept simple, but there are too many cases where you need complex ones.

  11. Empty Promise on Clinton Would Crack Down On Game Content · · Score: 1

    Given how few of the campaign promises they even have the power to deliver, much less the ones they even remember after getting elected, why worry? It'll just be another forgotten promise thrown out there for the gullible folks who believe the candidates. To truly figure out what a president/senator/representative nominee will do, just look at their voting record and the campaign contributors list. They don't give a crap about their promises or morality.

  12. Re:security through instability on Firefox Susceptible To QuickTime Security Flaw · · Score: 1

    What like FireFox doesn't crash and burn anytime a plug-in misbehaves? FF is worse than IE in that regard, especially with plugins like Adobe Acrobat reader. Isn't the FF fanclub party line that instabilities and crashes are caused by misbehaving extensions and plug-ins.

  13. Re:Half and Half on Stalwarts Claim Asus eeePC Violates GPL · · Score: 1

    They are under no obligation to distribute the source with each computer. They do have to make it available which can be via written request if need be.

  14. Re:The Aptera is cool looking on 6 Major Pre-Production Electric Vehicles Compared · · Score: 3, Insightful

    You must be one of those math impaired folks as well. Even if you had perfect efficiency and as much sun as Australia, and no rainy or cloudy days you can still only get 1kw/sq-meter. That just isn't that much to make a difference for a car.

  15. Re:The model, from BFFM on The Obesity Epidemic — Is Medicine Scientific? · · Score: 1

    Sorry Tony is just a full of crap. Claiming that veggie oil gets stored as fats because it starts out as a fat? I guess he doesn't understand the whole blood sugar, glycogens, and insulin thing. Body builders are a poor example to follow for dieting. They basically crash diet just before the competition and rebound immediately afterwards - exactly what most people want to avoid.

  16. All calories are note equal! on The Obesity Epidemic — Is Medicine Scientific? · · Score: 1

    Go lookup how calories (really kcals) are determined for foods. They figure out how much thermal energy they get by burning the food and then apply fudge factors for the type of food. For example wood burns great but is scaled down as it's not terribly absorbable into the body. In somecases, they simply look at the food content and make estimates based on the percentage of fats and sugars. The set of fudge factors used is probably not a bad estimate for most people. However, it's entirely likely that this model doesn't fit a significant portion of the population. Some folks might be really good at storing sugars or fats, in which case that 300 calories marked on the box might really mean 600 calories for this person.

    So while it is true that calories_in minus calories_out is true, it's not that simple. You have to account for absorbtion efficiency and how many calories end up in the toilet.

  17. Re:Why would anyone want to "upgrade" ever again? on Vista at Risk of Being Bypassed by Businesses · · Score: 1

    Mainstream support for XP ends April 2009. Extended support which includes security fixes, knowledge base info, and the ability to buy hotfix support goes out to 2014. This assumes that Microsoft doesn't change those dates to force update of Vista. Extended support for 2000 ends July 2010. I can see upgrading 2000 to XP as security support is likely to go away before Windows 7 is rolled out. Windows XP plays with AD much better than 2000, but I have zero reason to upgrade anything in my network to Vista.

  18. Hushmail isn't secure - they use Outlook! on Hushmail Passing PGP Keys to the US Government · · Score: 1, Flamebait

    Would you trust a secure webmail company that uses Outlook? This certainly looks like a printout from Outlook to me. http://blog.wired.com/27bstroke6/files/hush_klp.pdf

  19. Re:Polymorphic? on World of Warcraft's Brand New Rootkit · · Score: 1

    http://en.wikipedia.org/wiki/Polymorphic_code The code isn't truly self-modifying in the polymorphic sense. It's not changing form while doing the same function. It's updating a portion of itself from a web site. This is no different than Adobe Acrobat or Firefox checking for updates and automatically installing them (OMG! Firefox can install code on my machines!) The difference is that not everyone gets the same update, so all the WoW installations are not doing checksums or detections the same way.

  20. Re:Plot Points Are Not Facts on Rowling Sues Harry Potter Lexicon · · Score: 1

    Philosopher's Stone was the original title the book was released under in Europe.

  21. Polymorphic? on World of Warcraft's Brand New Rootkit · · Score: 1

    I think the author needs to see what polymorphic really means, aside from being a virus related buzzword. A program being able to dynamically update itself from a server is not polymorphism. I think we just have a cheater bent out of shape that he can't write a single cheat tool that will work across multiple systems.

  22. Re:ISPs won't implement it anyway. on Tools To Squash the Botnets · · Score: 1

    Even more to the point, please refer to http://www.cybertelecom.org/ci/esp.htm. Specifically, the ISPs want to provide only "basic" service. As soon as they start doing anything with the "format, content, protocol or similar aspects of the subscriber's transmitted information", that becomes "enhanced" services which do not enjoy common carrier status under Title II of the Communications Act. Still, it's a hotly debated subject as far as the ISPs are concerned. They don't want to do anything that jeopardizes the status quo.

  23. Re:ISPs won't implement it anyway. on Tools To Squash the Botnets · · Score: 1

    Maybe because they fall under the definition as described in 47 U.S.C. 153(h)? http://www.cybertelecom.org/notes/telecom_carrier.htm

  24. Re:what's the world coming to? on Take Two Settles Hot Coffee Suit For Millions · · Score: 1

    Yeah, the same parents who thought a game centered around thugs and car-jackings was just fine.

  25. ISPs won't implement it anyway. on Tools To Squash the Botnets · · Score: 1

    The major ISPs do not want to implement any kind of IDS or traffic monitoring. Why? Because they really enjoy their status as common-carriers. It absolves them of any blame for how the end users use the internet. If they start examining and filtering traffic even for legitimate reasons like detecting malicious traffic, they put that distinction in jeopardy. People and potentially the civil courts would assign the Telco the responsibility of policing their traffic. People would start suing the Telcos because they didn't detect that joe-blow had his computer compromised or they didn't detect and squash the DDOS attack directed against some company. Next step is forcing the Telcos to listen to all phone calls for the words 'bomb' or "Allah is great". Afterall that's NSAs job. :}