Slashdot Mirror


User: Arancaytar

Arancaytar's activity in the archive.

Stories
0
Comments
3,630
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 3,630

  1. Re:I guess? on Fatal Flaw Discovered In Invisibility Cloaks · · Score: 4, Interesting

    Depends on the size of the missile...

  2. Re:I think you are: on In Defense of Jailbreaking · · Score: 1

    Apple sells lovemaking devices now?

    Where do I get one?

  3. Re:Comparison to Greece? on Microbe Mat the Size of Greece Discovered In the Sea · · Score: 1

    And how much surface area is that in unfolded libraries of congress, anyway?

  4. Begin secret project: Voice of Planet on Microbe Mat the Size of Greece Discovered In the Sea · · Score: 0

    Eternity lies ahead of us, and behind
    Have you drunk your fill?

    It really would be amazing if such an organism gained sentience...

  5. Re:It doesn't matter on Newspaper Death Notices May Be a Dying Business · · Score: 1, Insightful

    Well, newspapers are dead - Netcraft just confirmed it.

  6. Re:Sometimes on Become an SSLAdmin In a Few Easy Steps · · Score: 2, Informative

    You are right, the SSL certificate is not used to intercept the connection. It is merely used to disguise an intercepted connection as a genuine one.

    The interception itself can be done by many different technical means, including DNS poisoning/spoofing, packet sniffing on a wireless network, etc. These aren't always trivial or feasible - but the risk of them is the reason SSL certificates exist in the first place.

  7. Re:Sometimes on Become an SSLAdmin In a Few Easy Steps · · Score: 4, Informative

    In a nutshell:

    When you log in to your email account, the server sends you a certificate to confirm that it does indeed belong to the email provider and not an eavesdropper.

    By registering an email account like "admin" or "ssladmin", an attacker could contact certification authorities and request a new certificate pretending to be a staff member of the service.

    They could then use that certificate to intercept and redirect your connection to their own server, intercepting passwords and emails, while your browser will still tell you that you are connected with a genuine mail server.

  8. Re:Damn typical on At Last, Flying Cars? · · Score: 1

    Yeah, dammit, like that darpanet thing. That would have been cool.

  9. Every consumer has to realize: on Web Coupons Tell Stores More Than You Realize · · Score: 2, Insightful

    No advertiser will give you stuff for free. Your discount is paid for with your personal data.

    What is in fact despicable, though, is when you are not told exactly what this data is going to be. There is nothing wrong with selling your email address (hell, I'd sell my own by the bucket-load if I got something for them; I have good filtering anyway), but you deserve to know in advance what it is you are selling. It's your right as a seller.

  10. Re:Blackboard on 3rd Grader Accused of Hacking Schools' Computer System · · Score: 1

    It's a web portal, so it's a good guess they're using *some* SQL database server.

    But I also read the technical requirements document to find out, and they seem to support Microsoft's SQL Server as well as Oracle as a backend.

  11. Law of Nature on Is the Tide Turning On Patents? · · Score: 1

    because they involved a law of Nature

    I support the ruling, but that sounds like a weak justification. Every technological discovery involves the laws of nature, whether it be the force of gravity, the propagation of electricity or radio waves. The entire field of engineering is the field of using the laws of nature to accomplish a purpose.

  12. Re:constitutional law professor on Google Backs Yahoo In Privacy Fight With DoJ · · Score: 1

    A pity Sergey Brin was born in Russia. If this trend continues, I'd vote for him next time round.

  13. Blackboard on 3rd Grader Accused of Hacking Schools' Computer System · · Score: 3, Informative

    Is the proprietary online education platform with an apparent side job as a patent troll, if memory serves.

    Given its closed nature, I wouldn't be surprised if their software is full to the brim of SQL injection, XSS and CSRF vulnerabilities that an interested elementary school student can exploit.

  14. Great! on Woman Claims Wii Fit Caused Persistent Sexual Arousal Syndrome · · Score: 1

    So that means men can use the Wii Fit without risk!

  15. No moon? on Obama Outlines Bold Space Policy ... But No Moon · · Score: 2, Funny

    No moon? That's a space station?

    (Millions of geeks suddenly sighed at the pun and were silenced.)

  16. If you want to see the future on Entertainment Industry's Dystopia of the Future · · Score: 1

    Imagine the RIAA stamping on a customer's face. Forever.

  17. What am I working on? on How Many Hours a Week Can You Program? · · Score: 1

    Maintaining antiquated code on a platform with no appreciable version control and clueless superiors? 20 hours per week, tops.

    Writing something well that will be useful and is actually interesting? A hundred, easily.

  18. Wilfull ignorance of technology and medicine on Girl Claims Price Scanner Gave Her Tourette's Syndrome · · Score: 0, Troll

    Thank you again, pseudo-science.

  19. Re:Naturally, the passwords were not in clear on Apache Foundation Attacked, Passwords Stolen · · Score: 1

    And how does a salt help when they can get the salt?

    The salt is not intended to remain any more secret than the hash itself. It also is not designed to ensure security in spite of a breach, just limit the consequences (much like password aging).

    Dictionary attacks become disproportionally, infeasibly expensive with a known salt.

    Instead of looking for the hash in a pregenerated dictionary (which is easy to find, for example gdataonline.com for MD5, 10^9 entries), the entire dictionary must be regenerated for each hash. That's 10^9 hash operations to attempt to guess a single password.

    It won't stop an attacker determined to get at a single password no matter the cost, but it will stop attackers who skim the database for easily cracked passwords.

  20. Re:Diabolical Intentions on Library of Congress To Archive All Public Tweets · · Score: 1
  21. taking off the training wheels on Twitter Grows Up, Adds "Promoted Tweets" · · Score: 1

    We used to call this kind of thing "jumping the shark".

    (Or "selling out to the Man", but it's hard to say that with a straight face.)

  22. Formula to calculate losses by piracy on Feds Question Big Media's Piracy Claims · · Score: 1

    Let A be the profit our product is supposed to be making. A = USD 1.213*10^9, a number arrived through careful examination and economic theory, as well as the realization that I really like money.

    Let B be the profit our product is actually making. This is obviously unrealistically low; we deserve to earn far more money than that. Also, I like money (see A).

    The losses due to piracy are calculated by subtracting B from A.

  23. Ironic Juxtaposition on Please Do Not Change Your Password · · Score: 4, Interesting

    1. Apache Foundation Attacked, Passwords Stolen

    2. Please Do Not Change Your Password

    Slashdot is awesome today!

  24. Re:Serious Question on Apache Foundation Attacked, Passwords Stolen · · Score: 1

    Yeah - other than the passwords, an OSS foundation doesn't really have any secrets to steal. However, how disciplined is the average person about password hygiene? These passwords will grant access to many accounts in many places, compromising emails, systems and possibly other large user databases via admin accounts.

  25. Re:Lord of War Quote on Will Adobe Sue Apple Over Flash? · · Score: 1

    Only if you build yachts! :P