Slashdot Mirror


User: FormOfActionBanana

FormOfActionBanana's activity in the archive.

Stories
0
Comments
662
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 662

  1. Re:Faster than light? on Faster-Than-Light Particle Results To Be Re-Tested · · Score: 1

    At faster than light, the relativistic component of the space-time becomes imaginary. So... impossible.

  2. Re:obligatory wet blanket on High School Student Launches a Trash Bag Aircraft · · Score: 1

    What gets me is he didn't bother to record any height information.

    Also, in the video montage at 1:43 you can see he's basically on a (extended) vfr approach path to North Las Vegas airport.

  3. Re:Aircraft? on High School Student Launches a Trash Bag Aircraft · · Score: 1

    Who said anything about airplane?

  4. Re:"Reducing the number of container ship movement on Are Folding Containers the Future of Shipping? · · Score: 1

    What is a "bike"? Is that like a type of car?

  5. Re:The ships still have to go back on Are Folding Containers the Future of Shipping? · · Score: 1

    Shortage where? You mean nearly everywhere?

  6. Re:"Reducing the number of container ship movement on Are Folding Containers the Future of Shipping? · · Score: 1

    For a transoceanic trip at 20-30kts, I'm sure it's increased drag rather than inertia, that accounts for the energy cost. The hull rides lower in the water when carrying a greater load.

  7. Re:re C and C++ were disasters on The Rise of Software Security · · Score: 1

    Yeah, if anyone knows a way I can search the Google index for sequences like ">>" please let me know!

    I know I have seen this topic treated in books, but cannot find anything. I did find the following two links, however:
    http://stackoverflow.com/questions/2711780/question-about-char-input
    http://www.physicsforums.com/archive/index.php/t-8093.html

  8. Re:Let's not ask someone who has lots of credentia on The Rise of Software Security · · Score: 1

    I forgot important disclaimers!
    1. Cigital is my competitor, and
    2. I wrote the original Wikipedia entry for Gary McGraw

  9. Re:Let's not ask someone who has lots of credentia on The Rise of Software Security · · Score: 1

    Well, as promised, I really am happy to be proved wrong. You are correct, I was rude and as intelligent people have demonstrated, I could have disagreed, been corrective, and been instructive, without using rude language. I was wrong and my current "Flamebait" moderation is correct. So I apologize for that.

    You're also correct that Cigital has a super hokey website.

    I don't know if you've written any books on antivirus, but Gary McGraw has published 11 according to his Wikipedia page.

    Good luck with your consulting company. I think any intelligent customer shouldn't care how many years you've been in business. They should only worry about:

    1. Are you trustworthy? and
    2. Will you do a good job?
  10. Re:re C and C++ were disasters on The Rise of Software Security · · Score: 1

    Hmm, this operator is super difficult to Google for, that's for sure. The >> operator is unsafe to use when reading into a character buffer because it does not perform bounds checking on the size of its input. An attacker can easily send arbitrarily-sized input to the >> operator and overflow the destination buffer.

  11. Re:re C and C++ were disasters on The Rise of Software Security · · Score: 1

    Come back to me with an identity and I'll tell you about metaphor in the English language.

  12. Re:You're all wrong, and will be until about 2022 on The Rise of Software Security · · Score: 1

    Very interesting point. But a bit of a one trick pony.
    You really don't think cross site scripting or sql injection are a big deal?

  13. Re:Let's not ask someone who has lots of credentia on The Rise of Software Security · · Score: 1

    AllRIGHTY then. Thank you for contributing to pants.

  14. Re:re C and C++ were disasters on The Rise of Software Security · · Score: 4, Informative

    C and C++ ARE disasters. gets() and >> can NOT be used safely. Period. Tons of functions in the standard libraries have been rewritten with secure variants, to try to make it vaguely possible for developers to keep track of buffer lengths. Still, some APIs screw it up and it's nearly impossible for an intelligent human to get it right every time without static analysis tools to back him up.

    HTTP is not a disaster but it clearly was not envisioned with security in mind. All attacker provided data is strings, input data comes from a variety of sources; there are way more HTTP verbs than strictly necessary. The authentication provided with the spec is "encrypted" with Base64. Actually, if this protocol were designed today to its original form, it would be laughed out of its security architecture review.

  15. Re:Let's not ask someone who has lots of credentia on The Rise of Software Security · · Score: 0, Flamebait

    Well, what an ignorant fuckhead you are. Cigital is not a software company but a consulting company. Gary McGraw is the original "how to do it" software security guy, and he knows his shit.

    Go ahead, respond with a list of good books you've written and tell us about your AV (antivirus?) company. Your reply will constitute your Slashvertisement, and I'm always happy to be proved wrong. It's a win win.

  16. Re:A demonstration on why Slashdot has gone to Hel on Kepler Discovers 'Phantom' Exoplanet · · Score: 2

    Thanks... AC, for contributing almost nothing of value. I agree, but still.

  17. Inject stuff into kernel more easily on Windows 8 To Feature 'Fast Startup Mode' · · Score: 1

    This sounds like an interesting vector for injecting code into the running kernel. Shut down; remove disk; edit hiberfil.sys; reinstall disk; restart.

    I sure as **** hope there's a good quality digital signature on that file! As they're talking about speed, it doesn't seem like a huge probability.

  18. Re:lost index on After Firing CEO, Yahoo Puts Itself Up For Sale · · Score: 1

    I think back in the day it was an open web catalog project... or at least to get into the Google index, you had to be approved for inclusion into the open catalog. I cannot for the life of me remember what the name of this catalog project was... but I searched for my old homepage and found someone has hosted a virus-ridden mirror of the old index. My website is still listed here:

    http://www.puncat.com/Society/People/Personal_Homepages/index19.html

  19. Re:So when will Slashdot follow heise's example? on Heise's 'Two Clicks For More Privacy' vs. Facebook · · Score: 1

    Where you in April? We all got ponies here on Slashdot.

  20. Re:So when will Slashdot follow heise's example? on Heise's 'Two Clicks For More Privacy' vs. Facebook · · Score: 1

    Does Slashdot have a "like" button?? I thought that came with the ponies...

  21. Re:Condescending? on The Guardian and the Wikileaks Encryption Key · · Score: 1

    s/told/later told/

  22. Condescending? on The Guardian and the Wikileaks Encryption Key · · Score: 1

    Condescending? This is the word you use to describe the attitude toward the guy who told the password to the world?

  23. I don't get it... on Heise's 'Two Clicks For More Privacy' vs. Facebook · · Score: 2

    They embed a Facebook "like" button on their website... And then they decide it's creepy so they grey it out???

    When I think something is creepy I just remove it....

  24. Re:Some star had some plasma ripped off on Astronomers Find Unusual Star · · Score: 1

    Oh, then I guess all the Lagrange points must be unstable. Thanks for your input!!

  25. Re:Space junk on Chinese Want To Capture an Asteroid · · Score: 1

    I didn't RTFA. Sorry.