Slashdot Mirror


User: J0nne

J0nne's activity in the archive.

Stories
0
Comments
215
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 215

  1. Re:More old news on Malicious Injection — It's Not Just For SQL Anymore · · Score: 3, Informative
    3) Do not send SQL parameters to your page in GET statements!!!!!! Either use session variables or POST statements, session variables are best.

    Using POST instead of GET doesn't make *any* difference. You can fake a POST request just as easily as a GET request. Please stop telling people that a POST is more secure...
  2. Re:Where? on How to Prevent Form Spam Without Captchas · · Score: 1

    You only see them when posting as AC (when not logged in). There's probably one when signing up for an account too.

  3. Re:What every home needs on Linux-powered Robots From France? Oui! · · Score: 1
    A surly, chain-smoking robot, to not do the work you need to get done around the home, which you cannot fire. Sign me up!

    And here I was, thinking it was an ob. Futurama reference. But you had to ruin it by making it a French joke...
  4. Re:Firefox Slashdotter Extension on Firefox Usage Climbing · · Score: 1

    slashdotter does this? I thought it was just one of the changes that happened with the new css...

  5. My bank on Phishers Defeat Citibank's 2-Factor Authentication · · Score: 2, Informative

    My bank requires you to install some java software + some keys in your C:\ or /home/ before you can use online banking (and it's protected by a password).

    It's a bit complicated to set up (especially in Linux, although the instructions were good enough to figure it out), but I don't see how phishing would work with this system. An attacker would have to trick the user into sending the 3 files with keys + entering his password.

    You could get what you need easily with a trojan and keylogger, ofcourse (well, good luck tricking me into installing a trojan on Ubuntu), but sending e-mails with 'please enter your password' won't do a lot for a phisher. Besides, I don't even think my bank has my e-mail address, and I would find it very suspicious if I ever received an e-mail from them.

    Phishing works because some banks apparently set up their online banking systems in the same way as slashdot, with just an username and password. That's fine for unimportant stuff, but when handling money, a login/password just won't cut it.

  6. Re:Article is incorrect on Linux/Mac/Windows File Name Friction · · Score: 1

    That would be stupid.

    Unless you plan on not having any applications installed, you'll find that you'll end up with 2 'my documents' folders, which will confuse the hell out of any user. Some programs don't follow that setting and use the hardcoded path.

  7. Re:I don't use the Search Engine feature on Firefox 2 Alpha 2 Reviewed · · Score: 1

    Rightclick somewhere on your chrome (like next to 'file' 'edit' 'view', etc), select 'customize', and drag the search box off your gui.

    Just in case you didn't know that yet, because I kinda like the search box myself (even though I use the address bar search too in some situations).

  8. Re:Warning on Can You Spoof IP Packets? · · Score: 1

    Heh, I just had this happen to me while reading the summary...

  9. Re:Whatever...try thinking right on Windows Vista To Make Dual-Boot A Challenge? · · Score: 2, Informative

    Nobody in their right mind would run his OS on fat32, but if you're planning on dual-booting, you probably already have made an extra FAT32 partition, in which you dump the stuff you want shared.

    You can even mount it in your home directory for easy access. (And on Windows you just use X:\ as your 'my documents' folder).

    And I don't get your ranting about the security of NTFS vs. FAT32. With NTFS, anybody can boot Knoppix with captive NTFS (or a Windows-based LiveCD, if those exist) and overwrite explorer.exe with anything he likes. You're screwed if somebody has physical access, no matter what the OS or Filesystem is.

  10. Re:Why? on Microsoft Releases Critical IE Patch · · Score: 2, Informative

    The IETab extension can switch the rendering engine within Firefox. You can even add a list of websites that should always use IE's engine. This way your users won't have to start IE seperately (and probably won't even notice the switching of the engine).

    I'm not sure if you can install it automatically (through sms or whatever it's called), so it might not be practical if you have to install it on a lot of computers.

  11. Re:mozilla.org ignored for cache link insert? on Slashdot Firefox Extension · · Score: 1

    it's because the coral cache doesn't work with https (for obvious reasons).

  12. Re:slashdot DNS is OPEN! on DDoS Attacks Via DNS Recursion · · Score: 1

    Obviously that is the thing causing the slashdot effect...

    And to say CmdrTaco blamed it on us, the innocent readers with souped up Firefoxes and Reloadevery extensions...

  13. Re:Slightly off topic but .... on Does Using GPL Software Violate Sarbanes-Oxley? · · Score: 1

    Who can recommend a good book on IT 404?

    I searched Amazon, but all I got was 'File not found'...

  14. Re:Why not a community based p2p client/network ? on Razorback2 Servers Seized · · Score: 1

    Yep, you're right.

    I don't see eDonkey going down in the near future either, as there are still other servers, and there's kad in case somebody manages to shut down all servers.

    So the completely decentralised networks that are hard to shut down are:
    -gnutella (the original, still going strong after 6 years)
    -G2
    -Ares
    -Fasttrack (yes, that network is still running, despite being a heap of crap)
    -eDonkey (with kad, i don't see anyone shutting that down)
    -WinMX (used to rely on central servers, and when those went down, someone else just started running those servers)
    -All those anonymous P2P projects that nobody cares about (freenet,mute, ants, ...)
    -and i'm probably forgetting some

    And regarding legal use: I primarely use P2P as a source for free software, so I don't have to wade through badly designed websites that let you click 20 links before you finally get to the download.

  15. Re:Antivirus is NOT useless on January 2006 Virus and Spam Statistics · · Score: 1

    It's just that people do fall into that trap of trusting their antivirus. Why would you pay for an antivirus application which will probably screw up your system more than an infection, if you can keep your computer clean by following some simple guidelines?

    I see computers with P4's that run the speed of a PIII just because they're running Norton's crap. And those computers are infected with tons of adware too, because Norton won't do anything to stop those.

    I just have Clamwin on my system as a regular application, it doesn't hook into the system, and doesn't do real-time scanning. It doesn't suck resources, I don't even let it start up with Windows.

    Running an antivirus application is just not worth it. They suck resources and money out of you wallet, and it won't even protect you when the next worm hits because worms spread faster than anyone can produce antivirus definitions.

  16. This proves antivirus is useless on January 2006 Virus and Spam Statistics · · Score: 5, Insightful

    If this report proves anything, is that running antivirus software is not good protection. You have to educate users not to open suspicious attachments, not to run IE, and to keep their systems updated (every modern OS does this automatically! Windows also does this since SP2). A firewall and/or NAT router is always a good idea too.

    I don't run antivirus (except the occasional ClamWin run if I downloaded something I don't trust completely), and I manage to keep my computer clean just by following the above rules. Antivirus won't protect you from ad/spyware anyway, and these things have become worse than viruses.

    If the antivirus vendors can't keep up with new viruses, you might aswell stop paying for antivirus. After all, it won't protect you.

  17. Re:What i am waiting for on 360 Sales Slow, Chip Blamed For Issues · · Score: 1

    Infineon Technologies, makers of the xbox360 chips, can't deliver chips.
    Infinium Labs, scammers behind the most famous vaporware after Duke Nukem Forever, can't deliver console.

    Coincidence? I think not... ;)

  18. Don't buy those MP3's if your smart on Using Watermarks to Combat Piracy · · Score: 1

    Not only because that would be supporting DRM peddling assholes, but you have to be even more careful with these files than with DRM'ed files. You are now liable AND tracable if an mp3 you bought somehow gets shared online. It doesn't take a whole lot for that to happen.

    Maybe you happened to leave a windows(Linux/BSD/Mac) share open on a hostile (college/company) LAN? Maybe you lost your iPod with those tunes you bought, and somebody else is happily sharing "your" MP3's on p2p networks? Maybe the PC repairman decides that he'd like a few of your mp3's for personal use when you brought your pc in (it's not like *he* could get in trouble, there's no way to trace it back to him)?

    You have to keep an eye on your files, and your system constantly to make sure none of your mp3's gets away, or otherwise you can expect a huge fine in your mail when you least expect it. Buying those MP3's is even more risky than just downloading and sharing them online like many do now.

  19. online!=always available on Online Ajax Pages The New Web Desktop? · · Score: 3, Insightful

    If you rely on webapps exclusively, you can't reach your information all the time. Your internet connection could drop out, or you could be someplace without an internet connection (wardriving might be easy, but I never find an open access point when I need one).

    Webapps complement regular apps, they don't replace them. It's good that websites are finally feeling more like real applications, and it's nice to be able to reach your information from everywhere, but they'll never replace them completely.

    Why does one technology have to kill the other technology? Both can coexist fine. I use Gmail, but I still use Thunderbird to read and send my e-mail when I'm at my computer.

  20. Re:My favorite quote on Opera CEO on Devices, Linux, and Web 2.0 · · Score: 1

    now that I have RTFA, that wasn't the full quote, apparently.

    Another product I'm proud of is IBM ThinkPads. If you have a technical problem and Windows won't start, there's a rescue system. That rescue system is running Linux and Opera. I'm kind of proud of that; if Microsoft fails, you have a rescue system with Linux and Opera.

    I guess that is quite nice.

  21. Re:My favorite quote on Opera CEO on Devices, Linux, and Web 2.0 · · Score: 1

    Except that I don't see where Opera fits in there. Why would you get Opera if you can get Konqueror, Firefox/Seamonkey or any of the other browsers? Opera is not a necessity, it's just one of the choices you can make for a browser.

  22. Re:Story is inaccurate... on IE7 Bug Reports Flooding In · · Score: 1

    ...he lists workarounds as 'Firefox'

    Maybe he was going for the +5 Funny mod...

    These 'workarounds' get posted here on any IE related story.

  23. Re:Hmm on US Missile Shield already Defeated? · · Score: 2, Funny

    They just mix some vodka in the rocket fuel.

  24. Re:Trackmania Nations? on Boing Boing Threatened By Software Creator · · Score: 1

    Replying on my own post:
    I did some research, and apparently they really did include it on that free game. I even had that crap on my system :(.

  25. Trackmania Nations? on Boing Boing Threatened By Software Creator · · Score: 1

    glop.org lists Trackmania Nations as containing starforce. Is this true? Trackmania Nations is a game that was released for free downloading by Nadeo, so copy protection on that seems like a weird thing to do...

    Does anyone know more about it?