Slashdot Mirror


User: Schraegstrichpunkt

Schraegstrichpunkt's activity in the archive.

Stories
0
Comments
2,694
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 2,694

  1. Re:The problem is .... on PHP Application Insecurity - PHP or Devs Fault? · · Score: 2, Insightful

    It all comes down to knowing what you're doing in the language you're coding in. If you're not good enough to sanitize, error check, bounds check, mem check, fault check, and whatever the hell else could go wrong, you have no business coding.

    "Sanitized" is a generous way of saying "not binary-safe", which also means "not internationalized" and "doesn't work in edge cases". Most of the time, if you have to \"sanitize\" input, instead of accepting and properly encoding <em>any</em> possible input, you\'re doing something wrong.

    As for error checking, bounds checking, "mem checking" (what is that? avoiding memory leaks?), "fault checking" (how is that different from error checking?), etc, those are tasks that a computer can do much more reliably than any person. If, realizing that, you still can't see how hopelessly stupid your argument is, then I suspect you're the one who has no business coding.

    You would totally fail at investigating plane crashes.

  2. Netcraft confirms it, Windows is dying on Microsoft Worried OEM 'Craplets' Will Harm Vista · · Score: 1

    Windows is never going to be ready for the desktop, because you have all the incompatibilities generated by the different OEM "distributions", and those that only serve to confuse users. When you're using "Windows", you expect to be using Windows not "HP Windows" or "Dell Windows" or "MDG Dollar-a-Day Windows". The only way Windows is ever going to be useful on the desktop is if all the vendors can agree on a single environment.

    Go Microsoft!

  3. Re:The problem is .... on PHP Application Insecurity - PHP or Devs Fault? · · Score: 3, Informative

    Blah blah blah. I've written code in both PHP and C, and writing secure code in PHP is harder, because you have to work around the insecure C code it's written in. No amount of rhetoric is going to convince me otherwise, because writing PHP code is my job, and I know better.

  4. This is easy to test empirically on PHP Application Insecurity - PHP or Devs Fault? · · Score: 4, Interesting

    Take 100 programmers selected randomly, and instruct them all to write a given application, but have 20 of them write the code in PHP, 20 write the code in Python, 20 write the code in Java, and 20 write the code in C++, and 20 write the code in Perl. Then analyze the resulting code.

  5. Re:One would hope... on Supreme Court Clears Patent Invalidity Suits · · Score: 2, Insightful

    The one catch: As a patent holder I'm not required by law to license to you. I believe I can even revoke (or refuse to renew) your license. So patent holders could use that as leverage to prevent suits by declining to let people license the patent while they were actively challenging it in court.

    I'm not sure the judge would be impressed with that.

  6. Re:Perl & CSV on Is the One-Size-Fits-All Database Dead? · · Score: 1

    Yeah, Perl sucks. He should have written it in PHP instead... ;-)

  7. According to the CBC... on Bugged Canadian Coins? · · Score: 1

    ... nothing to see here. Move along.

  8. Re:Motive??? on Bugged Canadian Coins? · · Score: 1

    To look like an RFID without being one, the coin would not only have to resonate but also transmit a 128 bit number.

    It does: It emits a special, scary-ghost-sound "OooooOoooooOooooooooOooooooOoooo" number.

  9. Re:We need a new checkbox when posting to /. on What Does Your Dead Man's Switch Do? · · Score: 1

    Oh crap, right.

    The weird thing is that I've seen your sig before, but I forgot about it when I wrote that post.

  10. Re:False alerts on What Does Your Dead Man's Switch Do? · · Score: 1

    PGP doesn't prevent people from causing your "I'm still alive" emails to mysteriously disappear.

  11. Re:False alerts on What Does Your Dead Man's Switch Do? · · Score: 1

    You're sending your passwords over email? And you use email to activate it, eh? What's your username? iMaple? Okay.

    <clickety-click>

  12. Score -1 Tasteless on What Does Your Dead Man's Switch Do? · · Score: 1

    Why not make a system that, after you've passed away, pretends to be you from beyond the grave?

    Is that you, lilo?

  13. We need a new checkbox when posting to /. on What Does Your Dead Man's Switch Do? · · Score: 4, Funny

    [_] No Karma Bonus [_] Post Anonymously [_] Post Humously
  14. Re:Ah ha! on Pillars of Creation Destroyed · · Score: 1

    That's why what you describe as "speaking strictly" is pointless. Throughout your life, you have to make decisions. You can make these decisions entirely randomly, or you can base them on something. If you base your decisions on something, you can choose to base them on religion and evidence (theism) or on evidence without religion (atheism).

    Agnosticism is a convenient position to take intellectually, but as a world view it's somewhat hypocritical, since it's totally useless as a decision-making tool.

  15. Re:Ah ha! on Pillars of Creation Destroyed · · Score: 1
  16. Re:Ah ha! on Pillars of Creation Destroyed · · Score: 1

    No.

  17. Re:Ah ha! on Pillars of Creation Destroyed · · Score: 1

    I think that quote is from James Randi.

  18. Re:Let me start you off... on Open nVidia Linux Driver Pledge Nearly Complete · · Score: 1

    You don't have to get the entire driver functioning perfectly. You just have to get something that plays TuxRacer and maybe Quake 3 well enough to make the card more useful than a paperweight.

  19. Re:HP's involvement in writing the binary-only dri on Open nVidia Linux Driver Pledge Nearly Complete · · Score: 1

    they could get it by taking a few dollars off of every employees salary.

    What an excellent strategy for losing your best employees!

  20. Re:What is wrong with the proprietary driver? on Open nVidia Linux Driver Pledge Nearly Complete · · Score: 1

    Maybe it is, so when your machine is compromised, your files will be corrupted faster. Yay!

    Seriously, not everybody who wants 3D acceleration is willing to make the same performance-security trade-offs as NVidia's salespeople are.

  21. Re:What is wrong with the proprietary driver? on Open nVidia Linux Driver Pledge Nearly Complete · · Score: 1
    You're not supposed to use the NVidia installer. You're supposed to use module-assistant:

    aptitude install module-assistant ; m-a update ; m-a a-i nvidia
  22. Re:What is wrong with the proprietary driver? on Open nVidia Linux Driver Pledge Nearly Complete · · Score: 1

    1995 called. They want their ignorance of what free/libre and open-source software is about back.

  23. Re:thickness is the key issue on Nano-Scale Optical Co-Axial Cables Announced · · Score: 1

    ... So you did.

  24. Re:i've seen this before on Fedora Core and Fedora Extras To Merge · · Score: 3, Funny

    I think the DOJ refers to that as "bundling".

    Been there, done that, dismissed.

  25. Re:It would be nice on Fedora Core and Fedora Extras To Merge · · Score: 3, Interesting

    If your machine locks up regularly, then perhaps you should look to something other than blaming Fedora.

    Indeed. Clearly, it's the fault of the people who made gcc 2.96. *ahem*

    It may be your configuration, your hardware, or various other causes, but if you're going to complain about Fedora, at least complain about the *valid* deficiencies...

    If Fedora ships with a configuration that's unstable on particular hardware, and Debian doesn't---and you're not a developer---then choosing Debian is a smart and cost-effective solution. What do you expect?