Slashdot Mirror


User: TSHTF

TSHTF's activity in the archive.

Stories
0
Comments
28
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 28

  1. Re:My college did it easier on Inside the Great Firewall of China's Tor Blocking · · Score: 4, Informative

    Tor has changed since you read last... "Bridges" were added to Tor and are not listed in any central directory.

    Tor bridges

  2. Half-assed apology on Cnet Apologizes For Nmap Adware Mess · · Score: 1, Flamebait
    What a half assed apology. They didn't apologize for fucking up, but instead the unrest they caused.

    The bundling of this software was a mistake on our part and we apologize to the user and developer communities for the unrest it caused.

  3. Easy fix below on AWS Load Balancer Sends 2 Million Netflix API Reqs To Wrong Customer · · Score: 1

    Use rewrite rules to do a 301 redirect to goatse.cx when the host is api.netflix.com!

  4. What to do when a vulnerability is found? on Security For Open Source Web Projects? · · Score: 3, Informative

    I highly recommend you read the announcing security vulnerabilities section of Producing Open Source Software book. You'll probably want to read the whole thing, however!

  5. Technical details here on How To Evade URL Filters With (Not-So) Fancy Math · · Score: 4, Informative

    The linked article is next to worthless. The real details are in this blog post.

  6. Netbooks aren't DME on Why Are Digital Hearing Aids So Expensive? · · Score: 4, Informative

    On a recent flight, I heard an older man talk to the woman he was sitting next to about this same issue.

    Hearing aids tend to be classified as DME (durable medical equipment). Medical equipment has a higher support cost than netbooks, and the insurance companies are happy to pay. The cost of entry in the DME market is much higher the netbook market.

    Although there is a huge market for the product, the liabilities involved in selling these products significantly raises the risk, and therefore the price, in such products.

  7. Nice response from an Ubisoft rep on Ubisoft's Authentication Servers Go Down · · Score: 5, Interesting
    It's worth looking at how a Ubisoft rep replies to a post that gives users information on how to use the now-broken service:

    Please do not post about illegal activities and or downloads.

    The response summarizes the situation appropriately:

    WTF I posted a link to google that shows how to play since UBIcraps servers are down and you call it ILLEGAL activities? RAbble rabble! I will never buy another ubisoft product and I advise you to do the same!

  8. Amazon AWS? on Long-Term Storage of Moderately Large Datasets? · · Score: 4, Interesting

    It might not be the cheapest option, but with Amazon's AWS, you can snail mail them a copy of the drive with the data and they're store it in S3 storage buckets.

  9. Re:Google? Privacy? on New Chrome Beta Adds Privacy Controls, Translation Option · · Score: 4, Informative

    You don't have to "trust" their browser at all.

    The source code for Chrome is freely available. If you find any features that are unfriendly towards privacy, you're free to modify the source.

  10. Re:History being made. on Another ACTA Leak Discloses Individual Country Data · · Score: 5, Insightful

    I think people are upset because this accord is being hammered out in secret behind closed doors, and citizens of the affected countries are only aware of progress on the treaty through leaks.

    There's a correct way to "come to grips" with these problems, and that way is by discussing these issues in the open, and allowing for review and comment on what's going on.

  11. Just walk away on Another ACTA Leak Discloses Individual Country Data · · Score: 5, Insightful

    I don't think there's much chance of changing the American negotiators views on this, but I'm still going to contact my representatives in Congress. Nothing will likely come out of it. If you are a /.er in a more reasonable country, say New Zealand or Canada, I beg you to contact your MPs and demand transparency in this process. We shouldn't have to find out about the progress of negotiations through leaks.

  12. Re: As usual, please refrain from blindly chiming on Mozilla Accepts Chinese CNNIC Root CA Certificate · · Score: 4, Informative

    Opera trusts CNNIC also.

  13. Re:Wait, what? on Gmail Moves To HTTPS By Default · · Score: 1

    Not always the case anymore. Web browsers and servers have implemented persistent connections (keep-alive) for a while. It's in the RFC.

  14. Paywalls suck on Citibank Denies Reported Breach Linked To Russian Gang · · Score: 5, Informative

    Article is behind a paywall. Search for it with Google News, and the WSJ will let you read it all.

  15. Re:Anonymous Coward on Google Attack On the Mobile Market Rumored · · Score: 2, Interesting

    It would just go over the air as data. For example, 1500 minutes of G729a voice uses (4.12kB/s * 60 seconds * 1500 minutes) = 370 MB

    The question is what kind deal Google could cut with the carriers to provide nothing more than 370MB a month of data transit.

  16. Re:"High-tech phone service?" Maybe if it worked.. on Google Attack On the Mobile Market Rumored · · Score: 2, Informative

    Here's another data point for a random end-user: I've used Google Voice to the tune of approximately 1200 minutes per month for the last four months and haven't experienced service issues with receiving calls or placing calls. I've made very few international calls, however.

  17. Re:Linux PC on Home Router For High-Speed Connection? · · Score: 1

    The Cisco ASA 5505 is a good choice, but prepared for a bit of a learning curve. For ASA 8.2, the command reference guide weighs in a 3534 pages. If the command-line scares you away, the integrated web management (ASDM) works well for what it is. The 5505 has no fan, provides an 8 port switch (including 2 PoE ports), and is probably slightly greener than an old box running Linux.

  18. Re:Of course there isn't a problem on Fedora 12 Lets Users Install Signed Packages, Sans Root Privileges · · Score: 1

    Because the package management system runs as root, may install setuid files, or system daemons which contain vulnerable code; an unprivileged user cannot normally do this.

    Sure - only signed packages can be installed - but signing a package won't make those pesky buffer overflow vulnerabilities go away.

  19. Of course there isn't a problem on Fedora 12 Lets Users Install Signed Packages, Sans Root Privileges · · Score: 5, Insightful

    Certainly there can't be a problem here, says the Fedora team. According to the release notes, there are 15,000 packages which can be installed by these unprivileged users. That's a lot of fscking code -- surely some of it is poorly written. Consider this scenario: Package X suffers a critical {local, remote} root vulnerability. If the vulnerability isn't public, any local user (and maybe remote ones too!) has root. If the vulnerability is public, there is often a long window between downstream fixes and Fedora fixes. In either case, this is a security issue. The Fedora team really should have put this in the release notes and reconsider this implementation in the first place.

  20. Re:Instead of referring to just "Blue Hippo" on BlueHippo Scam Collected $15M, Only Shipped One PC · · Score: 5, Informative

    From the court documents linked in the article: Joseph K. Rensin is the sole owner and shareholder of BlueHippo Funding, LLC. FTC 26. Mr. Rensin acted as Chief Executive Officer of BlueHippo from its inception in 2003 until July 20, 2009. See FTC 28 at 7-8; FTC 22G at 3. As CEO, BlueHippo's corporate officers, including the Chief Marketing Officer, reported directly to Mr. Rensin. FTC 28 at 20-22. In addition, Mr. Rensin was involved in BlueHippo's day-to-day operations, "manag[ing] the overall structure and direction of the business" and "overseeing the senior management team in formulating strategy." Id. at 22; FTC 22G at 3.

  21. RTFM for more DoS suggestions on How To DDoS a Federal Wiretap · · Score: 1

    Great paper. Cisco is also nice enough to write up about their "Lawful" Intercept products. For example, in Configuring Lawful Intercept Support, they kindly warn the end-user that "To maintain VXSM performance, lawful intercept is limited to no more than 60 active calls." Thanks for the suggestion!

  22. Security clearances? on DHS Wants To Hire 1,000 Cybersecurity Experts · · Score: 2, Insightful

    This paragraph from the article is probably the most interesting point:

    "Another item of great importance is a security clearance to do the work. This is where you will get only one brand of thinking; DoD or DoE clearance. This will prohibit the security "black hat" types from ever being involved in the project without coming from the DoD or Energy."

    This will limit the pool of resources to such an extent to make the project worthless.

  23. I wouldn't recommend Websense on Porn Surfing Rampant At US Science Foundation · · Score: 5, Informative

    I wouldn't recommend Websense to anyone. They have a long history of stealth web robots which intentionally disobey the robots.txt standard.

  24. Re:A Decision The Swiss Will Rue on Swiss Open Source Decision Going Microsoft's Way · · Score: 1

    Maybe I've been smoking crack, but I find the resources on MSDN to be more than adequate, if you can find the proper one. The shortcomings of MSDN tend to relate to search and relevance IMO, but the information is out there.

  25. Re:They Did Not 'Look At The Options' on Swiss Open Source Decision Going Microsoft's Way · · Score: 1

    You must be new here. You expect us to read an article before bashing Microsoft?