Slashdot Mirror


User: frankie

frankie's activity in the archive.

Stories
0
Comments
1,460
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,460

  1. Re:Your wish has been granted: on U of Wisconsin's Mac OS X Security Challenge · · Score: 1

    "average Joe" doesn't have to know what any of these words means

    1. When the Software Update box pops up, click the blinking blue "Install" button
    2. Don't touch anything in the "Sharing" System Preferences (ports closed by default)
    3. Still don't touch anything in the "Sharing" System Preferences (firewall on by default)
    4. When you receive a file that claims to be pictures (or movies, or music), and when you try to open it a box pops up saying "You are about to open this application for the first time, do you really want to?", click Cancel

    A better version of #4 would be appreciated, but it must be accurate and specific. "Don't be an idiot" is too vague and difficult to accomplish.

  2. Re:Perhaps with a desktop Mac on Mac OS X Security Competition Ends in 30 Minutes · · Score: 2, Informative

    Yes, OSX Server ships with some remote admin ports open. Apple assumes that anyone who shells out the extra cash for Server should at least poke around Server Admin.app (or Terminal if you prefer) for a few minutes. sshd and ipfw are easily controlled by either method.

  3. One thing people don't mention... on ArsTechnica Reviews The Intel Mac Mini (Core Solo) · · Score: 5, Insightful

    ...is that the OLD mini G4 had damn poor graphics of its own. Remember, we're comparing to a 32MB (yes, 32) ATI 9200.

    For example, MacWorld's game benchmark results. In UT 2004 (at default quality settings) the new mini gets a pathetic 10-12fps ... whereas the old mini got 14fps, gee so much better.

    Also, the new mini will get FASTER in the months ahead. For starters, upgrading to paired DIMMs will use the dual-channel bus, which is always a boost for shared-memory IGPs. Secondly, the Intel compilers for Mac are on the way.

    Sure, a mini with GF 6200 or Radeon X200 would be better, but GMA950 is not the apocalypse some have been claiming.

  4. When Firefox doesn't have a feature you want... on Mozilla Announces Extend Firefox Contest Winners · · Score: 2, Informative

    ...just add an extension! The Nightly Tester Tool does exactly what you ask.

  5. A few minor details on Japan's New Supercomputing Toy · · Score: 1
    1. It's the fastest in Japan , aka should beat Earth Simulator (40TFlops, ranked #7 last November).
    2. It's basically yet another IBM Blue Gene, but with a much weaker Hitachi attached to it.
    3. #1 ranked BlueGene/L running at Livermore hits 280TFlops.
    4. IBM PPCs dominate the high end of the Top500.
  6. The #1 reason why articles like this are BS... on 'Infectious' Open Source Software? · · Score: 3, Insightful

    Yes, if you paste OSS code into your software project, you will need to follow their license. As opposed to copying proprietary source code ... which will merely LAND YOU IN COURT for piracy, hacking &/or theft of trade secrets. See, isn't that a much better option?

  7. Re:Modern D&D makes me feel old on Dungeon Masters in Cyberspace · · Score: 1

    As a fellow old-school RPGer (mid-1970s) I have to ask, what do you say is wrong with DND3 relative to its ancestors?

    Personally I think DND in general has some major problems(*), but D20/DND3 is a gazillion times better thought-out than any of DND, BDND, ADND, XDND, or ADND2.

    (*) = AC & HP are wrong in their entirety, spell memorization by level is annoying, class feature progression is too rigid, etc.

  8. Re:Symantec? on Computer 'Worms' Turn on Macs · · Score: 1

    Hell yes. My organization has a WORLDWIDE license for Symantec AV (including FREE use on all personal PCs) and most of our Mac User Group uninstalled it (or at least the resident part) after the latest vulnerabilities.

  9. Re:As keeper of the Terry LePore fan page... on Florida Voting Machine Logs Reveal Anomalies · · Score: 1

    Wow, that's flat-out wrong in so many ways, I am in awe.

    1. Pat Robertson wasn't on the ballot.
    2. Both Pat Robertson and Pat Buchanan happen to live in Virginia.
    3. Pat Buchanan's last Florida visit was on Oct 19 (2000) to 3 cities nowhere near Palm Beach.
    4. Pat Buchanan himself stated that the anamolous votes ought to have been for Gore.
    5. There were 19000 miscast Gore votes (BTW, the same bad design was used in 1996; Dole lost 14000 votes).

    Of course, why should silly inconvenient facts stand in the way of a truthy intellect like yours?

  10. As keeper of the Terry LePore fan page... on Florida Voting Machine Logs Reveal Anomalies · · Score: 1

    ...I'm seeing at least one major misperception here. These possibly-fraudulent votes were cast in Florida's 2004 election, which was not significantly disputed. The big Palm Beach voting debacle was the 2000 election, using decrepit punch card machines and a foolish staggered two-column layout. Terry bought these paperless electronic machines in 2002 as a response to the chad backlash. She was then voted out of office in 2004 due to her demonstrated and repeated incompetence.

  11. Disable auto-open is NOT sufficient on Mac OS X Struck By Severe Security Hole · · Score: 1
    Auto-open prevents zero-click execution (or perhaps one-click, depending on how you enumerate), but a substantial two-click problem remains:

    1. You have a downloaded zip file. Extract it, OS X is invulnerable to zip files.
    2. You have an extracted media file. View it, OS X is invulnerable to media files.
    3. Oops, that media was actually a shell script in disguise. PWN3D!!!

    The actual vulnerability is NOT the auto-open, it is the concealment of zipped metadata. Apple needs to fix the problem by default disallow of downloaded or archived "Open With" settings.
  12. Yep, this is a genuinely bad bug on Mac OS X Struck By Severe Security Hole · · Score: 4, Informative

    Quick point of order: the bug doesn't execute automatically if you turned off the "Open Safe Downloads" preference. However, it's still really Really REALLY bad.

    Explanation: Apple recognizes a particular folder within a zip archive as resource forks. This way you can correctly upload/download old-style apps and/or OSX metadata. The latter feature is where the problem occurs.

    If you take a shell script, rename it to a "safe" file extension (such as mov, jpg, etc), then change its metadata (aka the "Open With..." setting) to Terminal.app instead of the expected default application, you now have a shell script that looks like an ordinary media file.

    If you then use OSX built-in BOMarchive command, you have a zipped shell script that looks like a "safe" download.

    End result: arbitrary shell script execution (under OSX default settings) upon visiting a malicious URL.

    Conclusion: remote metadata should not be trusted. This bug would not occur if downloaded files could only belong to their default app.

  13. mod that junkie down on Maryland Governor Wants Voting Paper Trail · · Score: 1

    Apparently neither the parent poster nor several moderators have any freaking clue what the words Voter Verified Paper Trail actually mean.

  14. as a Marylander and TrueVote supporter... on Maryland Governor Wants Voting Paper Trail · · Score: 5, Informative

    The whole issue of verified voting has been mired in stupid partisan squabbling for over 4 years. The entire Demoblican duopoly deserves large shares of scorn, blame, and (in a much better universe than this one) defeat at the polls.

    1. Shortly after the Florida chad fiasco of 2000, our elections administrator Linda Lamone decided to buy DRE machines from Diebold. Voter advocacy groups weren't loud enough ($$$) to block it.
    2. TrueVote eventually started building momentum & influence, but neither Lamone (D) nor Erlich (R) were interested.
    3. Once the voting population finally made themselves heard, the state legislature (both sides) voted in favor of fixing the machines.
    4. Diebold then laughed at Maryland for failing to request paper trails previously.
    5. This week, after Erlich realized that this issue could help his reelection bid, he came out in favor of fixing the machines too. So here we are.
  15. Re:Wouldn't it have been easier? NOPE on Cedega 5.1 Released · · Score: 1
    if companies such as id or Bioware can release Linux clients for their games

    ... except for two significant details:

    1. John Carmack is a programming god who loves OpenGL for philosophical reasons, and therefore intentionally writes highly portable code. Most other companies do not have anyone who even vaguely approaches that description.
    2. Bioware committed to writing ONE triple-compatible game (NWN) before they even started coding, however the Mac & Linux clients came out LONG after the Windows release, and the toolset remains Windows-only. Furthermore, none of their followup titles are *nix-compatible. If Bioware could release Linux clients for their games (plural), then perhaps we should consider why is it that they DON'T?
  16. Re:anti-competitive bundling (OS-PC) on OSx86 Cracked Again · · Score: 3, Insightful

    If Apple had 90%, 80%, or even just approaching 50% of PC marketshare, we could start talking about antitrust concerns. Until then, go away.

  17. Re:What are those 0.6% evil sites doing? on Firefox Users Surf Safer · · Score: 1, Redundant

    Whoops, should have RTFAed. They intentionally used unpatched browser versions to maximize infections. That's really sucktacular of them. They should have at least included a fully updated XP SP2 IE in its default "secured by Microsoft" state, as an experimental control.

  18. What are those 0.6% evil sites doing? on Firefox Users Surf Safer · · Score: 0

    Exactly what tricks are those sites using, that they still infect a supposedly locked-down and updated IE6? Or conversely, what vulnerable IE setting did the researchers fail to fix?

    Seriously, what is really going on there at the html level?

  19. One more thing... on Apple Switched Chips Too Soon? · · Score: 1

    Since I don't see any replies with hard science yet, guess I'll give it a go. This "method of altering silicon" appears to be just a combination of multiple already-extant technologies:

    1. 65nm. IBM, Intel, AMD, et al, already use this fab.
    2. Strained Silicon. IBM already uses this on the G5, probably others as well.
    3. SOI. AMD has been doing this since 2003.
  20. Re:You want to talk ice cores? on More Bad News About Global Warming · · Score: 1

    Then my statement is probably true, because that was exactly the case. A few of the past 400 millennia had temperatures 2-3 C higher than the latest one, and during those times CO2 levels were around 300 ppm (compared to about 275 ppm from 1000-1800 AD).

    Thanks to man-made emissions, CO2 is now 380 ppm and rising fast. The parameters of normal variation no longer apply.

  21. You want to talk ice cores? on More Bad News About Global Warming · · Score: 1

    You ignore that the industrial age has pushed CO2 levels way Way WAY beyond anything seen in the past 400000+ years, and that CO2 correlates very well with temperature over the same timeframe. Natural variation is one thing, but these huge man-made changes worry the $#!+ out of folks like me.

  22. Re:Thankfully, we have swing voters. on Both Parties Ignore the Facts · · Score: 1
    ...except that the vast majority of swing voters in America are uninformed consumers who pick whichever candidate has the better smile, slogan, and/or smear campaign. The number of voters who rationally compare the viewpoints of each candidate, and select the one most likely to help the country, is most likely smaller than the number of active posters on Slashdot.

    Think about the disturbingly large percentage of "undecided" voters who thought that Bush supported gun control, or Kerry wanted lower taxes, or many many other examples.

  23. Yes, it is opt-out-able on Google News Leaves Beta · · Score: 4, Insightful
    Would it be fair use to photocopy headlines

    Would it be fair if I chopped off your head for making a bad analogy? Signs point to yes.

    If a company wants to have an internet presence it has to be searchable by Google

    Guess what? The standard Google search (web pages) and Google News are two separate systems, with independent opt-out mechanisms. So your site can remain searchable without participating in Google News.

    If you are actually whining "I want my articles to get links in Google News, but I don't want them to use any specific words or phrases from my site" then you're being a psychotic dork.

  24. Re:why are they calling it x64? on Windows Vista x64 To Require Signed Drivers · · Score: 3, Insightful

    Why is this so difficult for so many people to figure out? Microsoft doesn't want to play favorites in the x86 war. They don't want to say either "x86-64" or "EMT64" and offend the other chipmaker, so they just call it generic "x64". It's obvious.

  25. Freescale 8641D on What is the Intel Switch Costing Apple? · · Score: 3, Informative

    Freescale's e600 dualcore G4 has been "in the pipeline" for the past 2 years with no sign of pouring out. On paper it should compare quite favorably to Yonah ... if it ever ships. Yonah has a slight advantage in that department.