Slashdot Mirror


User: ronkronk

ronkronk's activity in the archive.

Stories
0
Comments
15
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 15

  1. Re:DISASTROUS NEWS ! on Microsoft Plugs a Record 26 Security Holes · · Score: 5, Interesting

    I remember when Windows 95 came out, with its weak, obviously-an-afterthought "web browser" (IE 3.0). It was painfully obvious that Microsoft had missed the Internet boat, and shortly thereafter, Bill Gates sent his historic all-hands memo pointing the company in the direction of the Internet.

    It took them some time to get it right, but eventually IE took over. Now, you'd have a hard time finding a Microsoft product more complex than Minesweeper or calc.exe that doesn't connect to the Net somehow. And let's not forget that Netscape provided Microsoft with some much-appreciated help in taking over the Web, by screwing up their own release schedule so badly that there never was a Netscape 5.0.

    Flash-forward to a couple of years ago, when Bill sent out yet another all-hands memo, pointing the company in the direction of security. At first, we all laughed. But now it's becoming more and more obvious that they're taking security every bit as seriously as they once took the Internet. They are aiming to be the top of the heap in security, and they've got drive, ambition and aggression.

    Make no mistake, this kind of event is exactly what a company that wants to get secure should be doing. Thomlinson's comments about how seeing their code exploited "hits people in the gut", and the fact that "he was glad to see the crowd of engineers taking things personally" -- these things are right on the money. These things say to me that, within a few years, we're going to see some really damn secure stuff coming out of Microsoft.

    In the meantime, Firefox exploits are cropping up at a seemingly greater pace. This worries me. It looks like a repeat of 1997, when Netscape lost huge amounts of ground to IE by producing a product that wasn't as good as the competition. SP2 wa s huge leap forward in security for Windows and for IE, and Blue Hat makes it obvious that Microsoft is just going to get better at it. In the meantime, Firefox appears to be standing still on the security front, or maybe even losing a little ground. Sure, it's still miles ahead of IE's security, but if IE keeps up the pace, it will overtake Firefox sooner or later -- probably sooner.

    Is there any way the Firefox development team (and the OO.o team, and anyone else who's working on high-profile F/OSS projects) can take a lesson from Blue hat? Can we get together events like this of our own?

    If we don't, I can already see that by 2009 or so, at the latest, I'll be telling clients to go with Microsoft products, because they're more secure than F/OSS. And I don't want to see that happen.

  2. Re:Soo.. on The Diebold Voting-Machine Hack · · Score: -1, Offtopic

    Ruh-roh!

  3. Re:The box was not production hardware... on The Diebold Voting-Machine Hack · · Score: 4, Interesting

    I've seen plenty of pro-Microsoft and pro-Diebold posts get modded up. All you have to do is have a clear point, and show it. You didn't manage that. You said the fraud happens, and it doesn't make a difference if we can trace it or not.

    It does make a difference. With a punch card, or a paper ballot, or even a mechanical voting both anyone can trace when fraud has occured. And in those cases we implement some security, track where the fraud came from (if we can) and redo the election.

    With the current generation of electronic voting machines, we can't do that. I don't care who makes a good machine, but Diebold hasn't made one. And they've defended that design as if they think it is a good machine. Geeks don't like people who pretend a bad design is a good design. We'll tear into them. If they routinely defend bad design by saying it is good design and overlooking what we think are obvious flaws we'll notice, and start to expect that. Until they change, a group that decides who they like on the technical ability of a company won't like them. They are lying about their technical quality; at least in our eyes.

  4. Re:Soo.. on The Diebold Voting-Machine Hack · · Score: -1, Troll

    Note: I have been working on voting integrity issues in North Carolina for a little while now, and advised the committees that drafted the bill in question.

    The state passed a pretty comprehensive election reform bill, which included the provision that all vendors must hand over all code that runs, is installed on, or is otherwised used in the operation of the voting machines. No if, ands, or buts.

    Our State Board of Elections did not like this. They want paperless voting machines, and badly. Like a six-year-old that's been told to clean up its room, they're dragging their feet on enforcing these (and other provisions). When writing the Request For Purchase (bid requirements), some staffer added a "clarification" that the vendors only had to hand over "available" software, and simply explain why they couldn't hand over the rest. In other words, "Here's why I'm going to be breaking the law today."

    Lawmakers were not happy. The SBOE, however, didn't particularly care. They didn't see a problem with only handing over a portion of the code, and wanted to interpret the law as loosely as possible.

    Diebold pointed out that "available" was different than "everything", and actually got a restraining order that prevented the state from suing them for not complying with any of the new provisions of the law. This case essentially overturned that ruling, saying "Uh, no, you actually have to comply with the law." Technically it says, "Ask your lawyers for legal advice, not the court, we're not going to pre-judge the law before there's an actual conflict (i.e., you actually get sued for violating these provisions."

    So Diebold is going to take their ball and go home, since they would actually have to play by the rules. Oh well.

    On a side note, I didn't see any evidence that Diebold actually tried to get a Shared Source license from Microsoft, which would actually let them escrow the code. Maybe Diebold didn't actually want to escrow, well, anything?

    Imagine that.

    -jdm

  5. Money more important than a fair vote? on The Diebold Voting-Machine Hack · · Score: 4, Insightful

    Man Diebold looks slimier and slimier every passing week, but I'm more disturbed by Joe Demma's, Salt Lake's chief elections officer, response to Bruce Funk's actions. Granted, Funk acted by going around Demma by calling in Black Box Voting to check the Diebold machines, when presumably Demma is supposed to be responsible for that (just my guess as he's the chief elections officer).

    However, Demma seems more incensed at Funk because he may cost the state $40,000 for Diebold's astronomical recertification fee. He doesn't seem to be worried that people might not trust these machines. He doesn't seem to care that a state officer was worried enough to call in a non-profit third party to verify the integrity of these machines. I mean, these things could possibly affect the outcome of a vote, the foundation for a democratic republic! But instead of worrying about these machines he's clearly more upset about the $40,000 and Funk not talking to him about his concerns regarding the voting machines.

    And of COURSE Diebold is going to tell you the machines are fine and fair. Sheesh, they want to make money don't they?

    Isn't it great that chief elections officers have their priorities straight?

    Give me a ballot sheet and a pencil any day over these closed, proprietary black box machines.

  6. Re:Snake Oil on Killer NIC Hands-On Testing · · Score: 0, Redundant
    Ok, I'm in total agreement with everyone that the KillerNIC is smoke and mirrors. From my linux host, pinging my default gateway, I'm getting times of roughly 0.135ms... that's 135 micro-seconds. How in the hell is there any way to improve that? My Windows gaming box reports 1ms, but that's probably because it doesn't get any more granular than that. Even if they could reduce that latency to zero (impossible, because electricity/light doesn't travel that fast), no human can respond that fast anyway, so what's the use?

    I especially like this part of one of their answers:
    Simply running the 'ping' program is not sufficient, because it does not use your Network stack which can introduce tons of added latency.
  7. Re:MS up to its dirty tricks again. on Microsoft Attempts to Quash OSS Recommendations · · Score: 4, Interesting

    I'm South African, I haven't lived in SA for over 15 years, but I was an IBM mainframe operator there in the 80's and I still visit regularly and have family and friends there. The plus side of the racist white minority rule in SA is that the country got the best infrastructure in Africa, which it still has except that the current government caters to more than a small white minority and thus has other pressing problems as well to deal with.

    South Africa is the original home of Mark Shuttleworth and his foundation Ubuntu has an ongoing task in South Africa to teach and install Ubuntu in schools (Hint to Microsoft: It's one fuck of a lot cheaper than a Windows solution). I chat regularly with my mom down there who has a Windows PC. South Africa's biggest problem is a monopoly telecommunication company that refuses to allow competition or lower prices on internet access, thus ensuring some of the highest access prices in the world.

    However, if you go accross the border to the north, in Zimbabwe, which is in total financial ruin with an autocratic president who hates whites and the blames everyone but himself for the crap that is going on there, you'll find an infrastructure that was similarly built up by the original white minority government, but one that has almost no new investment since Mugabe came to power ensuring that growth in the IT sector there is non existent.

    And that is the case all over Africa, you have some countries which have fairly decent political systems, such as South Africa, Namibia, Botswana, etc and you have others which are either run by despotic tyrants, plagued by tribal warfare or thoroughly corrupt or a mixture of these.

    In those countries where there is a semi decent system, the education is usually quite good. In those which are chaotic the people are lucky if they can read or write and those who do know the internet, know it usually from an internet cafe.

    Linux has advantages due to its flexibility and low price. Claiming that teaching people Microsoft is better because there are more Microsoft trained people is only true if there really are trained Microsoft people around. Usually, the level of trained Microsoft people doesn't reach the level of even an MCSE, since we all know what an MCSE POS costs, so that advantage is null. Training people from scratch with Linux is in my opinion better since a basic grasp of Linux will enable someone to manage in extremely difficult circumstances where hardware and other constraints would make it extremely difficult to keep a system running with Windows.

  8. Alienware customer service on New Alienware PC an Overpriced Underperformer · · Score: 5, Informative

    In regards to Alienware's horrible customer service, I've got to weigh in. Last year I bought a laptop from them expecting a 15" 4:3 screen as pictured on their website when I ordered it. It took over a month to arrive, and what I got was a 15" widescreen with a 1680x1050 resolution -- I'm a young guy with decent vision (with corrective lenses) but this was too damn small for me and not what I ordered.

    Add to that my X, C, and V keys were DOA, and when I powered up the computer it informed me the CMOS battery was dead. Alienware advertises extensive power-on load testing -- if any of that were true, they would have found and corrected this problem as soon as they tried to power it up! Additionally the video card and wifi drivers were not installed, so their marketing B.S. about fine-tuning drivers for you is just that.

    To top this all off, I had to pay a 15% restocking fee to return my laptop for a refund. That was a $4k machine. Even after their false advertising as to the laptop design and absolutely no in-house testing -- despite the falsified testing sheet that came with it -- I lost $600 to them and it was two full months until I got the 17" Gateway laptop I now have. And it runs great.

  9. Comparison on Compress Wikipedia and Win AI Prize · · Score: 2, Informative

    There are some amazing compression programs out there, trouble is they tend to take a while and consume lots of memory. PAQ gives some impressive results, but the latest benchmark figures are regularly improving. Let's not forget that compression is not good unless it is integrated into a usable tool. 7-zip seems to be the new archiver on the block at the moment. A closely related, but different, set of tools are the archivers, of which there are lots with many older formats still not supported by open source tools

  10. Program Naming on First Impressions of Sabayon Linux · · Score: 5, Insightful

    Why do so many linux programmers insist on such crazy naming conventions. Sabayon? Changing a perfectly servicable and pragmagic GNOME Meeting to "Ekiga"?

    I use linux both at home and at work, so I'm not some anti-linux zealot or something- I think it's a legitimate question to raise. On my mac laptop, I have a handy app for browsing mDNS networks called Rendezvous Browser (since mDNS was once called Rendezvous).
    The name is simple and describes perfectly what the program does. On the other hand, 90% of the linux applications available have names that look like they were chosen by picking random letters and squishing them together.
    I'm sure that the programmers think they've very clever by choosing a name that means something in some obscure language- or they just thing the name sounds cool- but that simple lack of meaningful names is detrimental. If I start up a GNOME session and want to use network meeting functionality, how is there any possible way that I could guess that "Ekiga" is the application I'm looking for?

  11. The Secret to Advertising is one word: on Google Releases Analysis of Click-Fraud Detection · · Score: 1

    Don't. Not unless you can afford establishment advertising.

    Honestly. Advertising can work for the very select top tier products that become the establishment product, but in the long haul, there is only one way to make a product successful and profitable: quality.

    It doesn't have to be the best, it has to work in the customer's situation. If you sell service, do it happily and as close to perfection as possible.

    In all my years of being in business, I have never seen a good return on advertising that turned into a long run of regular customers. Sure, I may have seen some profits, but I also so many losses. I will never advertise again, I can't compete with Target or the like. What brings customers to my various businesses? Word of mouth. It spreads like wildfire when you perform a really good service or sell a great product.

    The web is in trouble as programs like AdBlock and the like gain use. I know many of you use AdBlock, but if you use it on a website you like, turn it off. Click the damn ads. How do you think that site is being provided for? I pay as a subscriber to slashdot, and this Christmas I'm planning on giving a dozen or so subscription gifts to people on here that I admire. Sure, Taco and the boys have some nice money now, but I love the site, and I will continue to support it.

    Advertising online doesn't work as well as many think it does. I've been watching the companies that have started to use AdSense within their catalogs (offering paid links to their competition). Only the top companies are making it big. I've spoken to some large bloggers (off the record) and their numbers in advertising don't make their blogging a real income. Yeah, there are a few who are making it big.

    Google is taking in the most, but they have to find ways to combat against AdBlock and other ways to avoid the advertising. I don't know how they'll do it, but as I find AdBlock being used on more and more systems, I know that Google won't remain the king.

    I do believe that sponsorship advertising of the web might work. Basically a monthly payment in order to say "Slashdot, brought to you by Microsoft" or something of the sort. Some podcasts I've listened to are receiving sponsorships, and they are't tacky ads but well thought out slogans or quick product placements.

  12. First to predict on Google Shies Away from Digital Music Sales · · Score: 5, Funny

    that a half-baked story predicting that Google will enter the wireless provider market in order to support the foray into their online music business. GMusic store will allow you search 7 billion recordings using lyrics, instruments used, and sound patterns.

    Also, in 3 to 6 months Microsoft will apologize to their employees, customers, and vendors for falling so far behind as an MVNP and music distributor. But Balmer will commit to catching Apple, Google, and AllOfMp3.com within the next 3 to 4 quarters. It's Microsoft's top priority next to releasing Longhorn, WinFS, security, DRM, the next version of SQL Server, Exchange 2007,.NET,.ORG, ethic, combinatorial global business synergies and leverage points and Windows on the Power PC.

    Lastly, Apple frustrated with the iPOD to car stereo interfaces and refusal by many automobile manufacture to integrate the iPOD directly into their automobiles will purchase an Korean automobile company and begin manufacturing iCars. These cars will include new design innovations including ergonomic steering wheels and see through dash panels. Initially the automobiles will run on Honda gasoline engines, but Jobs will announce in the first 4 years of production that the iCar (and soon to be released iSUV) will switch to Toyota engines that can run on electricity, gasoline, jet-fuel, whiskey, and the sweat of some breeds of Tibetan mountain goats.

    Step aside Dvorak I have spoken.

  13. Re:I know why google doesn't want in! on Google Shies Away from Digital Music Sales · · Score: 4, Informative

    Stop wasting time!
    ext:mp3

  14. SLASHDOTTED, ARTICLE HERE on Apple's DRM Is Bad For Consumers and Business · · Score: -1, Redundant

    Opinion: Apple's Copy Protection Isn't Just Bad For Consumers, It's Bad For Business

    Apple's copy-protection technology makes media companies into its servants. Other copy-protection technologies, like Blu-Ray and HD-DVD, are just as bad, says Internet activist Cory Doctorow.

    By Cory Doctorow
    InformationWeek

    jul 31, 2006 12:00 AM

    When it comes to anti-copying technology, there are two possible outcomes: either you have a popular single-vendor system that's bad for the industry and general public, or you have a multi-vendor system that's bad for the industry and general public.

    Apple Computer's iTunes is hailed as the first really "balanced" copy-restriction system. Unlike the copy-restrictions built into failed systems from the likes of Sony, Toshiba, and Microsoft, the anti-copying/anti-use stuff in iTunes doesn't seem to have deterred the public from buying iTunes music and the iPods that play it. Indeed, more than a billion iTunes have been sold around the world. That only amounts to a couple CDs' worth of tracks on every iPod, but still, that's not bad, especially in a field where the big success stories to date have been digital music stores that managed to go out of business without costing their backers too much.

    Steve Jobs and Apple managed to lure the music industry into licensing the copyrights for the iTunes Music Store even though the Store's use-restrictions are comparatively mild. There's a bit of region-coding -- you pay a per-download charge based on the country your credit-card is billed to. There's a bit of multi-use restriction -- only five CPUs can be registered to a given iTunes account at a time. There are some miscellaneous restrictions, including ones that are genuinely bizarre, like limiting the number of times you can burn a given playlist.

    Removing iTunes's DRM is pretty straightforward. It's time-consuming, but it's not too difficult. You just have to burn a CD with the tracks, re-rip the CD tracks as MP3s, and re-enter the metadata, like title and artist. This doesn't work as well for the expensive audiobooks Apple sells, which generally come in chunks too large to fit on a CD.

    So far, so good. The iPod is the number one music player in the world. iTunes is the number one digital music store in the world. Customers don't seem to care if there are restrictions on the media Steve Jobs sells them -- though you'd be hard pressed to find someone who values those restrictions. No Apple customer woke up this morning wishing for a way to do less with her music.

    But there's one restriction that's so obvious it never gets mentioned. This restriction does a lot of harm to Apple's suppliers in the music industry.

    That obvious restriction: No one but Apple is allowed to make players for iTunes Music Store songs, and no one but Apple can sell you proprietary file-format music that will play on the iPod.

    In some respects, that's not too different from other proprietary platforms, of course. No one but Microsoft makes Word. But there's a huge difference between Word and iTunes: Word is protected only by market forces, while iTunes enjoys the protection of a corrupt law that gives Apple the right to exclude competitors from the market.

    iTunes is protected by the anti-circumvention provisions in the 1998 Digital Millennium Copyright Act (DMCA), itself a law passed to comply with the 1996 UN World Intellectual Property Organization (WIPO) "Internet Treaties." The DMCA makes it a crime to circumvent "effective means of access control." That means that breaking the locks off a digital work is illegal, even if you're breaking the lock to accomplish a legal end.

    It's otherwise legal to back up a DVD, or put a song on a home media-server, or quote an ebook in a college essay. But if you have to break through some copy-restriction technology to do this, you're breaking the law.

    It doesn't even matter if you're the creator of the work the lock controls! You can't even access your own work on your own terms if you need

  15. Re:Your first mistake on Apple's DRM Is Bad For Consumers and Business · · Score: 5, Informative

    What will happen when Apple goes bankrupt? Or when the next generation of mini-players comes out with a new DRM?

    You must be thinking of the OTHER music companies, that re-authorize every month or what have you.

    If Apple went out of buisiness, you music would continue to play on your current Mac until the end of time.

    However, like you say eventually you'd want to move the music. Two options then:

    CD's - I can burn any ITMS song to CD as much as I like (limit of ten burns a playlist, but I can always make new playlists...)

    Hymn - I can convert protected AAC files into unprotected AAC files, which I can then play on anything that undrestands AAC (most PC players, not many portables) or convert it from there.

    So yeah I feel sorry for anyone buying music from anywhere other than ITMS or AllOfMP3.com. I still don't like to use AllOfMP3 though as I don't feel it gives artists as much as it should. Perhaps in the future I'll buy from ITMS, then buy the non-lossy version from AllOfMP3. Too much work though, so I probably wont...