Slashdot Mirror


User: Lobster+Quadrille

Lobster+Quadrille's activity in the archive.

Stories
0
Comments
577
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 577

  1. Re:why are people... on Utah Senate, House Pass Jack Thompson's Game Sales Bill · · Score: 2, Informative

    Admittedly, I haven't read the actual legislation, just news reports' summary of it, so I am likely misinformed, but frankly, I don't get it either.

    Several justifications were presented, but none sound plausible to me. Supposedly, Concerned Citizens think that underage people are going to nick drinks from the bar (has that ever happened in the history of bars?) When I was underage, I just had a friend buy the drink for me and bring it to the table, or better yet, get a bottle from the liquor store and mix it at home.

    I heard that one supporter of the bill said something to the effect of "when I go out to eat, I don't want to see people drinking". I think these people should stick to fast food.

    There is also the classic "if kids see people drinking, they'll want to drink," which I'd respond to with "so fucking what?"

    I don't think the legislation applies to bars, as it is theoretically all people of legal drinking age there anyways. I also think that existing restaraunts all get grandfathered in, so they don't have to renovate to add a mixing back room.

    At any rate, it's Utah, and yes, there is definitely a weird culture here. I still like it here, but I wouldn't mind a few changes either.

  2. Re:why are people... on Utah Senate, House Pass Jack Thompson's Game Sales Bill · · Score: 1

    Yeah, while I love living in Utah, the lawmakers seem to fall too easily to the "think of the children" argument.

    On a side note, the recently discussed bill involving bars keeping records of patrons' drivers licenses passed, along with one stating that restaurants can no longer mix drinks in sight of the patrons.

  3. Re:Why do I need Javascript to vote? on ISS's Node 3 Might Be Named "Colbert" · · Score: 2, Informative

    Sure there is- in the past, there have been plenty of exploits that tap into Firefox caches, saved passwords, history, and system settings (where all your personal information is really kept these days)

    Then there's all the XSS, CSRF, and clickjacking exploits that can compromise websites and services

    Let's not forget the fact that Javascript can just be annoying- preventing loops of popup windows and alert boxes is reason enough to disable javascript

  4. Re:Go look for another job. on Should Job Seekers Tell Employers To Quit Snooping? · · Score: 1

    "No company can say "no" to a *reasonable* request of police"

    Bullshit. Search and seizure laws apply on company property as well as personal. Nobody, cop or not, is going to search my office without a warrant and our lawyers on site.

  5. Re:Go look for another job. on Should Job Seekers Tell Employers To Quit Snooping? · · Score: 1

    "Drug use is among top culprits, because users need money for drugs and may steal big"

    We're talking about pot here, not crack cocaine. I know a lot of professional people who use it, and none of them steal money for drugs. It's like alcohol- if you can't afford it, you find a friend who can, or go without.

  6. Re:backups and Vernam algorythm on Securing PHP Web Applications · · Score: 1

    Here's another security tip- Don't ever listen to a person who obviously doesn't know what he's talking about.

    The amount of bad advice on this thread is astounding.

  7. Re:Community more unsecure than the language on Securing PHP Web Applications · · Score: 1

    1. Write bad advice
    2. People follow advice
    3. ...
    4. Profit!

  8. Re:No language is secure on Securing PHP Web Applications · · Score: 1

    ...And I haven't seen a human that could read that sentence.

  9. Re:what no AJAX on Securing PHP Web Applications · · Score: 1

    Ajax doesn't cause the sever-side security holes, it's the PHP scripts that handle it, and the same rules as always apply then.

    Ajax does have its own set of issues, but they're not PHP's problem, and thus, don't belong in a PHP book.

  10. Re:Can you just block by country? on Securing PHP Web Applications · · Score: 1

    Really?

    I've done forensics on a LOT of compromised sites, and the fact is that in 99.99% of cases, the cops don't care in any country.

    Unless there's major losses, particularly monetary, or it ties in with another investigation, nobody is even going to call you back.

    Sure, a major, targeted attack will get their attention, but you can bet they're using a small stack of proxies in that case.

  11. Re:Simpler method on Securing PHP Web Applications · · Score: 1

    ...Because Drupal is bulletproof

  12. Re:Just don't on Securing PHP Web Applications · · Score: 1

    Any non-trivial project with only one person working on it is going to have security holes. Without another person checking your work, you're bound to make mistakes.

    So why not have the guy checking your work be a "specialist" who knows what he's doing?

  13. Re:Schneier is the supergenius on Securing PHP Web Applications · · Score: 1

    "WPA2 is unproven while IPSEC, tls, ssl, and ssh all use proven encryption."

    Picking nits, I know, but I'm pretty sure Scheier would tell you that the only way you can prove an encryption is to prove it's weak.

  14. Re:Just don't on Securing PHP Web Applications · · Score: 1

    Small correction:

    It's always best to write your own sanitizers than to rely on what PHP provides (If you know what you're doing)

    There are a lot of issues that people overlook with character encodings and input mangling. I can't tell you how many PHP apps I've audited that had some guy's custom weak filter functions.

    Depending on your needs, there are a handful of really good sanitation libraries out there, but you're correct that they're not provided with PHP.

  15. Re:No he doesn't on Securing PHP Web Applications · · Score: 1

    Normally, yes. But Here's a guy who used CSRF to root a server.

    Exception, maybe, but I think it's about time people start taking those little client-side exploits seriously.

  16. Re:Just don't on Securing PHP Web Applications · · Score: 1

    As somebody who performs security audits on PHP apps for a living, you sir, don't have a clue. There are so many subtle issues with session manipulation, local system configuration, complex program logic, SSL implementation... The list is awfully long, and you couldn't put it all into a shelf of books.

    Though to be fair, if everybody did the stuff you mentioned, it would be a much better internet.

  17. Re:Enact the assault sword ban! on Man Robs Convenience Stores With Klingon "Batleth" · · Score: 3, Insightful

    I believe that Sikhs have a religious mandate to carry a sword with them at all times- something about always being ready to fight for God. In India they even allow them to carry the swords onto airplanes.

    Probably wouldn't go over so well here in the good old USA though... too many paranoid morons.

  18. Re:Amish on Midnight Commander Development Revived · · Score: 1

    Nah, nothing says buggy like a windows-based file manager.

  19. Re:Am I the only one here on Daemon · · Score: 1

    They're definitely worth a read, but the tech kind of takes over the story, and they're not well written.

    Still entertaining though.

  20. Re:To Answer The Question: +1, Informative on Daemon · · Score: 1

    You're totally right. I was out in the bad part of town the other day and every street corner had pushers peddling plasma screens and 14 year old girls turning tricks for cable.

    And have you seen the birth defects that TV causes? It's amazing that this stuff is legal.

  21. Re:CSI NY on Daemon · · Score: 1

    I didn't watch the show either, but I get the impression it wasn't so much a developer saying "here's a tool you can use next time you need to track IPs" as the resident techie saying "Sure, I can hack together a tool to track IPs, let me fire up my GUI editor"

  22. Re:Gestapo? on A Peek At DHS's Files On You · · Score: 3, Funny

    I maintain, that without the death camps, a very important piece is missing

    *sigh*.. fine, I'll set up a death camp. Will that make you happy?

  23. Re:Good time to start pumping out GHG then! on Is the Yellowstone Supervolcano About To Blow? · · Score: 1

    ...And yet the law of Fives is in fact 3 laws...

  24. Re:Simple Solution on Time Warner Recommends Internet For Some Shows · · Score: 1

    Johnathan, is that you?

    Shut the fuck up.

  25. Re:Language evolves - deal with it on Banned Words List Carries Its First Emoticon · · Score: 4, Interesting

    We have now created symbols that can represent simple meanings cross-culturally and cross-linguistically

    We had these thousands of years ago, on the walls of caves.