Slashdot Mirror


User: Cairnarvon

Cairnarvon's activity in the archive.

Stories
0
Comments
272
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 272

  1. Re:MD5+SHA1? on MD5 Proven Ineffective for App Signatures · · Score: 1

    Similarly, since ROT13 is such a weak encryption, why not just apply it twenty times? It's bound to be stronger, no?
    Okay, stupid example, but you can't assume just piling on additional algorithms is going to make things more secure. While it's probably reasonably safe for MD5+SHA1, you're almost certainly much better off just using, say, SHA-512 instead.

  2. Re:Holy Crap on BBC Creates 'Perl on Rails' · · Score: 4, Funny

    If it was meant to be easy to understand, we wouldn't have called it "code".

  3. Re:how, exactly on Texas Science Director Forced To Resign Over ID Statements · · Score: 1

    What magical fairyland do you live in where religion does not make claims about reality? Trying to hide behind "faith" does not make these claims immune to scientific investigation.
    The fact that creationists are trying to explicitly sell many of them as actual science doesn't help.

  4. Re:Stop misusing "Network Neutrality" on EFF Releases Software to Spot Net NonNeutrality · · Score: 1

    Python scripts aren't software now?

  5. Re:The glass is half empty? on FBI's Bot Roast II Sees Great Success · · Score: 1

    The same questions could be asked about alcohol and cigarettes. Do you support outlawing those as well?
    And don't forget, the first thing that happens when drugs are decriminalised is a massive drop in price.

  6. Re:Uhhhhh on How to Deal With Stolen Code? · · Score: 1

    Comments posted on forums that don't explicitly state in their rules that all comments are licensed in this way or that are automatically considered copyrighted by the comment author, and just using the code in your own product is a copyright violation.

    There's a difference between posting some code for public discussion and granting people a license to use said code in whatever way they like, including commercial products.
    It's no different from taking a lengthy essay someone posts on a forum and publishing it under your own name. It's theft, plain and simple.

  7. Re:Credibility? on Using Google To Crack MD5 Passwords · · Score: 2

    Perhaps he has better things to do than audit the complete WordPress codebase?
    If he'd written his own software, you might have half a point (though only half of one; perfectly secure apps, especially perfectly secure web apps, are always a pipe dream).
    If he'd been a victim of the same exploit several times in a row, then you might have a full point.

    You can't blame a person for being a victim of a zero-day exploit in someone else's software, especially if the software is as complex as a blogging/CMS platform.

  8. Re:MD5 Lookup Site & Names on Using Google To Crack MD5 Passwords · · Score: 5, Insightful

    He didn't write the WordPress software, and presumably doesn't have the time to audit every bit of code it uses.
    I doubt Bruce Schneier himself audited the entire Movable Type codebase, which he uses for his blog. Does that make Schneier "not much of a security researcher"?

  9. Re:What about us on Are Aliens Living Among Us? · · Score: 1

    It's called panspermia, and there are a number of problems with it. The fact that it's popular among some religious cults doesn't help.

  10. Re:disable trackpads? on Vista at Risk of Being Bypassed by Businesses · · Score: 2, Informative

    It's about Zonk for some reason considering the fact that out-of-the-box Vista won't let you disable trackpads on laptops to be more important than its millions of other failures, as if people are switching away from Windows just because of that feature.

  11. Re:And that is the problem on People Believe NASA Funded As Well As US Military · · Score: 1

    The EU is as much of an economic bloc as the US is.

  12. Re:Not really an issue on US Control of Internet Remains an Issue · · Score: 1

    China's Great Firewall is completely irrelevant, because we aren't talking about turning over control to China (or Saudi Arabia, or whoever), we're talking about turning it over to the international community. That's what GP meant when he said it was a red herring, because it is.

  13. Re:That works both ways. on How Fast is Your Turnaround Time? · · Score: 1

    Maybe the customer is being unreasonable. Maybe the developer is being unreasonable. It isn't possible to determine which from either person's viewpoint.

    Considering that the developer is generally far more familiar with the product than the customer and as such has a more realistic view of what is and isn't doable, it's nearly always fair to say it's the customer who's being unreasonable, and not the developer.

    Saying that it isn't possible to determine from either person's viewpoint is like saying that if a scientist says the universe is billions of years old, and your crazy uncle says it's six thousand years old, we can't rightly decide who to believe. Some opinions just count for more.

  14. Re:Fuck Veterans Day on Google Honors Veterans Day, Finally · · Score: 1

    The Cold War had winners? News to me.

  15. Re:Patriots are Idiots. on Google Honors Veterans Day, Finally · · Score: 1

    Bullshit. One is a euphemism for the other, and the fact that so many people try to gloss over that (or genuinely don't see the problem with nationalism in the first place) is frightening.

  16. Re:I see the same logo. Whats all the fuss? on Google Honors Veterans Day, Finally · · Score: 1

    That may have something to do with the fact that today is November 12th. Veteran's/Armistice Day was yesterday.

  17. Re:what's the big deal? on Microsoft's Treatment of Google Defectors · · Score: 5, Informative

    Switzerland has a lower unemployment rate than the US. 3.3% compared to 4.7%.

  18. Re:what's the big deal? on Microsoft's Treatment of Google Defectors · · Score: 1

    Presumably these resigning employees are grown men and women, and not petulant children. I'd expect them to be mature about it.
    And sue them if they weren't and did any actual damage.

  19. Re:Again, Not to be flamebait on Germany Implements Sweeping Data Retention Policies · · Score: 1

    It isn't. The English-speaking world is still comfortably ahead, in the West.

  20. Re:At least they saw it coming on Germany Implements Sweeping Data Retention Policies · · Score: 1

    The sad part is that you probably aren't even trolling, but seriously believe that if our government is anything but totalitarian the country really will turn Islamist (or that the US really is a better place to live than anywhere the GP could emigrate to).
    Enjoy your Kool-Aid.

  21. Re:Just use Identity... on NIST Opens Competition for a New Hash Algorithm · · Score: 1

    Take the first half of the 256-bit hash and you have a stronger 128-bit hash than a 128-bit hash using the same algorithm.
    I hope you don't actually believe that.
  22. Re:I know I'm paranoid, but... on NIST Opens Competition for a New Hash Algorithm · · Score: 1

    Even if that were plausible, it'd definitely be a risk worth taking. Cryptographic methods that are kept secret are never as secure as methods that are scrutinised by thousands of cryptanalysts around the world, as even the NSA itself has experienced on more than one occasion. Cryptographers, more than anyone else, are very much aware of the fact that security through obscurity just doesn't work.

  23. Re:Congress is useless. Why bother. on EFF Documentation Victory in Telco Spying Case · · Score: 1

    You wish. The ORB poll two months that put the Iraqi civilian death toll since the invasion at a million and the Lancet study in October 2006 that put it at 650,000 are both talking about excess deaths; that is, above and beyond what they would have been under Hussein's rule.
    Even if you consider those numbers to be too high (and you'd better have a good reason for believing so besides not wanting to believe them), there's absolutely no denying the fact that the civilian death rates have skyrocketted since the US invasion.

  24. Re:What a crock on Seagate Offers Refunds on 6.2 Million Hard Drives · · Score: 1

    Anyone that knows enough about computers to know that GB, MB, and KB are usually base-2 should also know enough to check whether the HDD measurement is in base-2 or base-10.
    Good luck doing that without buying the damn thing, or hearing it from someone else who had to buy it to find out. That's the whole point of this lawsuit: it wasn't indicated on the box whether it was base-10 or base-2.
    The fact that most non-computer people wouldn't be able to tell the difference doesn't excuse what is essentially a scam, and even if you think the IT industry is misusing kilo-, mega-, and giga-, that doesn't change the fact that that's how it's being used, and Seagate is taking advantage of that to rip off their customers.
  25. Hardly new on Students Assigned to Write Wikipedia Articles · · Score: 3, Interesting

    When I took Japanese History two years ago, we were given the assignment to pick a random topic related to Japanese history, research it, and write a Wikipedia article on the subject.
    This worked well for Japanese History because the English language Wikipedia didn't have too many articles at the time, and even the articles it did have were fragmentary and for the most part abandoned. I'm not sure how easy it'd be to do with more "mainstream" articles. You'd get more feedback from other Wikipedia users, sure, but you'd also be providing far less of the content.