Slashdot Mirror


User: skis

skis's activity in the archive.

Stories
0
Comments
37
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 37

  1. Turnstile voting on Another Election, Another Slew of Voting Machine Glitches · · Score: 1

    How does this idea sound? When you arrive at the voting place, a person checks your identification and makes sure you are at the correct voting place and you haven't already voted. For each contest on the ballot, there is a line of turnstiles you can pass through, one for each contestant (or yes/no/abstain for ballot measures). Once you make your first vote, there is another line of turnstiles for the next contest/ballot measure. This could be behind curtains to keep it almost 100% anonymous other than the person or people watching you to make sure you don't turn any turnstiles more than once. At the end of the day, the MECHANICAL turnstiles' counters are read.

  2. Re:Danger! Danger! on Privacy Group Calls Google Latitude a Real 'Danger' · · Score: 1

    They don't even need your Google login... they can use their own.

  3. Re:WTF is this article ACTUALLY about?? on Relentless Web Attack Hard To Kill · · Score: 1

    SQL injection does not exploit the SQL server at all, it exploits a vulnerability in the webapp that is sending the SQL query.

    If there is SQL injection in an INSERT or UPDATE query, the attacker might be able to insert javascript into the database which might then be sent back to the users in the place of real content (e.g. article text). Basically, persistant XSS via SQL injection.

  4. Re:this never gets old on Researchers Hijack Storm Worm To Track Profits · · Score: 1

    I don't know, but this is the first time I've ever seen the "Asshats" box NOT checked.

  5. Re:session-sharing with screen -x on (Useful) Stupid Unix Tricks? · · Score: 1

    'Ctrl+a' then 'd' for "detach"

  6. Re:Computer systems need security audits. on CSRF Flaws Found On Major Websites, Including a Bank · · Score: 1

    CSRF happens in POST requests as well. In fact, most public CSRF exploits I've seen have used POST forms in IFRAMEs automatically submitted using javascript (document.form.submit). This is another great reason to use noscript, because you are not going to know this is happening otherwise.

  7. Re:OWASP on Alarm Raised For "Clickjacking" Browser Exploit · · Score: 2, Informative

    Actually, the presenters were the ones that made that decision.

    So, after much deliberation we opted to pull our speech voluntarily, due to the extremely neutered information we'd have to be sharing. We'd much rather share the full breadth of what we found when it can be discussed more openly as to not diminish the danger of the flaw by only talking about small parts of the issue.
    -from ha.ckers.org

  8. Re:So don't use the trademark! on Chicago Law Firm Sues Over Hyperlink To Trademarked Name · · Score: 1

    Many websites nowadays are hosted using "Virtual Hosting". This means that there is more than one website hosted at that particular IP address, and the web server determines which data to send back to the user by looking at the Host: header in the HTTP request.

  9. Command and Control Center? on EA Hit By Class-Action Suit Over Spore DRM · · Score: 3, Funny

    Where's the command and control center of my computer? I don't remember putting that in there!

  10. Re:1and1 maybe? on Email-only Providers? · · Score: 1

    Only choose 1and1.com for email hosting if you aren't going to use their SMTP servers to send mail. 1and1's mail servers get blacklisted almost monthly.

  11. Re:Obligatory (with slight variation) on Nevada Businesses Must Start Encrypting E-Mail By Oct. 1st · · Score: 1

    Anyone else notice that the "Asshats" box is always checked whenever anyone posts one of these?

  12. Re:Security is not for the weak. on Researcher Publishes Industrial Complex Hack · · Score: 1

    Nice to meet you Kevin.

  13. Re:The Fastest HIPAA compliant Encryption Algorith on How Do You Deal With Sensitive Data? · · Score: 1

    I think that double rot13 would achieve a faster HIPAA complaint rate. EDIT: I read the subject again and realized it said compliant, not complaint...

  14. Re:So what's the problem? on SF Admin Gives Up Keys To Hijacked City Network · · Score: 1

    no service password-recovery

  15. Re:Long story short on Kaminsky's DNS Attack Disclosed, Then Pulled · · Score: 1

    Spraying end users with spoofed responses would not work because end users workstations do not talk to the authoritative nameserver directly. Additional Resource Records are only accepted if they are for the same second-level domain that you are asking about.

  16. Re:Just this night on The Very Worst Uses of Windows · · Score: 1

    At least it's correctly labeled as "a pos"!

  17. Re:silently dropping is not unexpected on Gmail, SPF, and Broken Email Forwarding? · · Score: 1

    Receiving MTAs should NEVER send bounces. That is the job of the sending MTA. One of the problems here is that gmail is reporting a 250 OK, so the sending MTA sees no error and does not send a bounce message.

  18. Re:wrong question on Hans Reiser Leads Police To Nina's Body · · Score: 1

    Didn't he have a book in his car titled something like How to Get Away with Murder?

  19. Re:Online postings **drove** her to suicide? on User Charged With Felony For Using Fake Name On MySpace · · Score: 1

    I agree. This is not The Happening. You cannot make somebody kill themselves over the Internet; although someone should start an RFC because that would be very useful.

  20. Re:Note to self on Huge Traffic On Wikipedia's Non-Profit Budget · · Score: 1

    George? Is that you?

  21. Re:But what does it have to do with the Bible? on RIAA Throws In Towel On "Making Available" Case · · Score: 3, Funny

    Religious typosquatters vs. technically-informed lawyer. Both are very rare.

  22. Re:Plugging the 'Leaks on Community Choice Award "Most Likely to be Shut Down By Govt" · · Score: 1

    Hey! I'm an insensitive clod you insensitive clod!

  23. Sinking Submarines? on Search For RMS Titanic Was a Cover Story · · Score: 1, Funny

    They were looking for the USS Thresher and USS Scorpion, two US nuclear submarines that sank during the Cold War. This is news? Aren't submarines supposed to sink?
  24. Re:Remembering a password on Comcast Briefly Loses Control of Its Domain Name · · Score: 1

    Because letterhead over fax is authentication... Actually this guy may have discovered their "part social engineering part technical flaw" by accident.

  25. It's not just a song on Motley Crue Single Does Better On Rock Band · · Score: 4, Insightful

    You can't play the song on the Rock Band game by buying it on iTunes... They aren't just buying a song to listen to, it is a different product.