Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×

Comment The article is on dice.com. (Score 5, Insightful) 547

The purpose of the article is to make dice.com (/.'s owner) appear to be a place where people can go to read articles about job skills and such.

.
The purpose of the article is not to convey any manner of knowledge on the subject.

It's chewing gum for the job seeker, no more, no less.

Comment Apple has no problem leaving old hardware behind (Score 1) 554

My Mac is no longer supported (hasn't been for a couple of releases) by OS-X because the CPU doesn't do 64-bits. It's not even 10 years old yet, and it isn't supported by OS-X.

.
It was the first Apple computer I bought. It will be the last Apple computer I ever buy.

Comment Shared hosting (Score 2) 41

...Since attackers are systematically scanning all available addresses in the IPv4 space...

If your site is on a server that does shared (or virtual) hosting, then IP address scans will usualy not trigger shellshock from your site because your site needs to be accessed via its URL. Accesses via IP address will usually go to a main site on that server, and that main site may not have any exploitable content.

... On one hand, that's a lot for a machine no one knows anything about; on the other, it indicates that attackers haven't wholesale dumped other methods in favor of going after this particular bug....

This is a straw man. Of course the bad guys are not going to walk away from all the other exploits in their toolbox. No one said they would.

Most of the shellshock accesses I see are just scans, i.e., the bad guys are building an inventory of what hosts are vulnerable. I haven't seen too many (i.e., only a very few) attempts to take over the host.... yet.

Comment Re:Apples and Oranges (Score 4, Insightful) 81

... BASH and OpenSSL are more key infrastructure bits than Xen is. What I mean is that they are integrated into FAR more devices and systems making a silent patch nearly impossible.

Quite correct.

.
Just try to estimate the number of devices affected by Heartbleed and Shellshock. It's probably in the billions.

As a case in point, a single Zen installation can host hundreds, maybe even thousands, of vulnerable installations of Shellshock and Heartbleed.

It is truly an apples and oranges comparison.

Comment Re:Bruce Perens (Score 1) 240

When Bruce Perens was getting questions from slashdot, I asked whether Obamacare should have mandated the use of open source software....

Easy to ask, difficult to do.

.
Obamacare barely passed when Congress considered it. If such an open-source requirement were in the law, then lobbyists from EPIC-type companies would be all over Congress, and Obamacare would have never passed.

Companies pay lobbyists to make sure Congress passes laws that put money into the companies' coffers. Things like cost-efficiency are not part of that equation.

Slashdot Top Deals

We are experiencing system trouble -- do not adjust your terminal.

Working...