Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Comment Re:Not just your phone! (Score 0) 306

> see who accesses those shiny Tor gateways too.

Yup. People always seem to forget the utility of traffic analysis. Use Tor, encrypt everything, doesn't matter. Just using Tor is going to put you on the short list of people who bear additional attention. Either an paranoid, anarchist or pedo. Odds are more than one of those three. And while the libertarian side of me screams the coldly rational side does have to admit to the reality that it is also true. If I were a cop I'd be making that exact assumption and be right far more often than I was wrong. Playing those odds would lead to a high arrest rate and a promotion.

So how do we fix that problem. Hell, we can't even get more than a percent to even sign email yet with only a little effort from the few developers we could be encrypting most email by default. Default and entirely transparent are the keys to a more secure Internet. Wouldn't even matter a lot if the key management for those 'normals' wasn't perfect. Just getting to a point where most email traffic flowed from server to server unreadable would help. But yes my above observation about traffic analysis would still apply. That could be tackled once we had enough encrypted traffic we could hide things in the stream.

Comment Re:Leave you phone^W lojack at home. (Score 3, Interesting) 306

> Meanwhile I have good karma with a default score of 2 for being a complete tool.

Hey, I posted at +3 (Karma + subscriber) unbroken for pretty much the entire time the current slashdot model existed until a couple of months ago when I pissed off an admin or they totally redesigned the moderation system. Since there hasn't been widespread complaining I assume it is just me that is getting the special treatment. Mods can't really hurt you unless you are a totally usless user who never says anything worthwhile. The downmods get cancelled out by upmods on the good stuff and it all works out.

Comment Re:Leave it at home? (Score 3, Informative) 306

Not unless someone is doing something they shouldn't. Each device is assigned a unique 48bit MAC address at time of manufacture. Each one.

You buy a 24 bit prefix from IEEE (I think) and are then supposed to do your own accounting on the lower 24 bits to be sure you don't duplicate one. If you have ever looked up a MAC to see who made the device, that is how it works. The owner of the prefix is a published record.

Comment Re:Not just your phone! (Score 2, Informative) 306

> Law enforcement can track you and indict you simply because of a number on the backside of your car! You should probably just leave your car at home.

Yea, that is becoming a major nightmare. Until pervasive cameras it didn't matter much. The could put an APB on a plate number and still not have a very high success rate on the cops finding it. Now with cameras in every intersection that changes. They can get a big chunk of the same info collection that way that cell phone tracking gives them but it isn't quite as good. All tracking cars does is show where the car went, the camers may or may not give a good enough image to prove who was in it. And more than one person can be in a car at the same time. If you have phone data the cars don't add a lot.

Of course they require a lot less legal issues to make use of images already sitting on traffic and homeland security machines so they are starting there. Later they can supplement it with the cell tracks and the merged dataset will be very complete in the picture of where a person goes and what they are doing.

Comment Re:Leave you phone^W lojack at home. (Score 2, Interesting) 306

You are half right. Most people assume I'm a bible humping right winger, but in reality I'm an agnostic anti-idiotarian Libertarian. And this crap annoys my Libertarian tendencies. If I didn't need one for work I wouldn't carry a mobile device. But yea the hivemind has started demonstrating their tolerance and diversity bigtime on my ass of late. I just say "bring it bitches." because nothing says "I can't win an argument" like organizing a movement to silence the few of us around here who don't toe the Party line.

The lamers downmodding don't bother me, do wish the admins would lay off though and put my account back to normal. Since pissing one of them off a few months ago karma goes down far faster than it goes up. One downmod is usually enough to kill the posting bonus now. Still manage to average three replies per post though so it hasn't silenced me. Never saw that sort of heavy editorial hand back when Cmdr. Taco ran things so it is a bad sign of things to come.

Comment Leave you phone^W lojack at home. (Score 5, Insightful) 306

There, fixed that for ya. Amazing how they managed to get darned near 100% of the population to agree to carry around a tracking device with nary a peep. All it took was to be very careful to NOT talk about the tracking ability, keep news accounts of the police using the cell data off the front page and make the tracker shiny and useful enough. Do those things and not only will everyone carry one they will pay an average of $50/mo for the privledge. Land of the Free indeed.

Won't be long now before they decide they have the hook set deep enough they can start making more overt use of the location/activity data without many people ditching their tracker.

The carriers WILL start renting out access to track data for advertising purposes. They know where and when you are. They will be able to link that beyond your phone. Won't take much computation to get that localized enough to have a good idea which PC you use and then tie it to doubleclick and google's cookies. Then they know EVERYTHING. Combine a tracking cookie to hard billing quality identification data and the possibilities are truly limitless. Sure they COULD do that with Amazon but there is too great a chance of a user revolt. But people won't/can't give up their iShiny.

What law enforcement will do with the data is so obvious and so dark there isn't much point in hammering it again really. Especially combined with security cameras everywhere. Who cares if the image quality isn't good enough for a positive id or you were wearing a hoodie. It gives a time/location and the tracker gives them who was at that spot in spacetime.

Bust a drug dealer and you have probable cause to grab a trace on everyone who came in contact with that person for the last month. Crunch the numbers enough and lots of patterns emerge. Not quite precrime but close enough. You show up as having been in the room with a number of dealers and that will be your ass. Or be around a few people who later get busted for burgulary and how soon until that is cause for a search warrant on your place? Being able to effortlessly work backwards from a bust and turn up clues like that will change the law enforcement game entirely.

And now you see why AT&T yanked all their payphones and for some reason simply refuses to compete in the landline business, even with billions and billions in sunk costs for all that wire going everywhere. Eliminate hardlines and everyone MUST buy a cell. It is already sorta odd to encounter someone who doesn't carry one, eventually it will be reasonable suspicion of criminal activity. Wouldn't suprise me if they become the preferred physical identifier, i.e. 'your papers.'

Comment Re:Stupid and wrong (Score 1) 141

Without a special flash chip or adding another one your simple electrical fix isn't practical. The ESCD info typically gets reflashed on a pretty regular basis if anything in the machine changes. To save cost it is usually in the same physical flash with the BIOS. Also, your simple jumper would preclude lights out server management.

No, it has to be a gate that can only be cleared by a cold start once flipped on.

Comment Re:Stupid and wrong (Score 2) 141

You could still allow lights out. Most servers support boot over net so the BIOS is required to have a partial IP stack. Just allow bringing in the new BIOS via tftp from the IPMI remoted BIOS console if nobody is available to insert a USB stick and you don't want to allow reading it out of a FAT partition on the primary drive.. It could print an SHA-256 sum of what it downloaded to ensure you weren't hit by a man in the middle. Hell, it could even check a signature against a key in the current BIOS and warn if it was signed by someone else. Lots of possibilities. But if it is electrically possible to write the BIOS after the bootloaded is executed security isn't really possible.

Comment Re:In Other News... (Score 1) 585

What about her? She is a bored illionaire who was tapped to lead a doomed company in the almost pitiful hope her media hype can save Yahoo! from it's almost certain fate. It won't; you know that, I know that and she probably knows that. There won't be any needing to pull any allnighters, no death marches to release and if she can't (or doesn't want to) travel for a couple of months it won't really matter because she isn't expected to succeed.

If you are a normal person things are different.

Comment Stupid and wrong (Score 5, Insightful) 141

Locking the BIOS with signed updates and crap is exactly the wrong way to go. It means there will still be bugs to exploit. But the forces seeking to lock down the PC will advance yet another step under cover of security theater.

The correct solution is to give the machine a one way gate so that after POST the BIOS can't be updated, period. Electrically impossible. That would require an updater in the BIOS and either storing the extended config now flashed into the same chip with the BIOS to either go elsewhere or the flash chip to be smart enough to have a protected area and an unprotected area and only the protected area be unrevokable without a full reboot. It also should go without saying that the BIOS can't look at the unprotected area before the big switch to prevent buffer overflow attacks from getting into the BIOS while the flash is writable and/or stopping the user from invoking a clear extended data function.

A minimal rescue program in mask ROM would be gravy of course. Lets see the leet warez doodz get past that one. Wouldn't put anything past the NSA though.

Comment Re:Preference cascade (Score 0) 238

> Are you trolling? You actually think its a good idea to waste taxpayer dollars going after weed?

Doesn't really matter what I think. Or you. What matters is Congress has spoken on the issue in the form of making laws. If we don't like them we should take it up with them, I hear there is an election on; now might be a good time. The President doesn't get to decide which laws he will enforce, he swears an oath to faithfully execute the laws of the United States as written. Same goes for 'gay marriage', amnesty for illegals, card check, regulating CO2 as a pollutant and so on. We don't have a king, we have a president. And I can absolutely promise you will instantly agree with me the second Obama leaves office and a Republican administration is sworn in, whether that be this year or some later election.

Comment Re:What's the difference? (Score 0, Offtopic) 238

> Stuff like the voter id laws

Help me understand. Liberals tend to favor all sort of laws requiring ID. Can't f*cking buy a can of spray paint in Wal*Mart without having a picture ID anymore. Can't board a plane. Can't enter a federal building. Can't drive. Can't buy booze or smokes or a lotto ticket. And to carry a gun you need a second photo ID most places, if you can at all. Shall I continue? Point made? Thought so. So explain why I shouldn't think you guys are lying pieces of crap on this one and are just too scared to admit what you are really on about, you want to protect the sacred right of illegals to vote and for your political machines in the big cities to manufacture as many votes as the Party might require.

> and redistricting

So you are pissed we finally took enough State Legislatures to show you just how unfairly you guys have been playing that little game the last fifty some odd years? Payback too much of a bitch for ya? Well screw you hippie, suck it. In a generation I'll perhaps join you in a call for a more fair system.... but for now enjoy the payback.

Comment Re:Preference cascade (Score 1, Funny) 238

> "legalize weed" - not gonna happen. Too bad too.

What other major component of his base has yet to get a major bone thown to them, usually in a totally lawless fashion? Think about it. He announces he is ordering Federal law enforcement resources to be 'redirected' away from enforcing the laws against weed. Lots of blah blah about it being his discretionary authority to direct scarce resources in this time of budget crisis, etc. The message to the college/youth vote will be unmistakable: Romney would instantly reverse this executive order but if I get reelected you can light up forever because after four years weed will be such a open and accepted part of society none would dare revert the change. So you stoners better get off yer ass and put the bong away long enough to drag my sorry ass across the finish line.

Slashdot Top Deals

The system was down for backups from 5am to 10am last Saturday.

Working...