Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×

Comment Re:Better analogy: imported rats, not farmed (Score 1) 140

Your observation, that a bug hunt will reveal lots of inconsequential bugs, but the few significant ones make it worthwhile -- well, that's entirely the expected result, surely?

Well, I could make some argument about whether it's generally worthwhile even for a few significant bugs... if they are significant, it's likely they would be found and reported in short order regardless of a bounty. And especially if there's a backlog of bugs, I'd say those should take priority over finding new bugs that haven't actually bothered anyone yet.

The security aspect is different though, because those are bugs that have a motivation to go unreported. And there's the 'papercut' type, where small annoyances go unreported. I'd consider it an good question whether bounties are more effective than simply paying an expert (or several) the same amount up-front to comb through things. The old crowd-source vs. out-source argument I guess.

Comment Better analogy: imported rats, not farmed (Score 1) 140

I think the point he's getting at is that a lot of the bugs are not the ones that would trouble users (i.e. they only appear "in the lab"). So although it's still good to fix them, they are low priority.

The farming analogy is bad because it implies people are creating these bugs just to turn them in, which as everyone is pointing out, doesn't make sense and would reflect poorly on the buggy developer, so it would be self-limiting. Instead, I propose he should have said "imported" rats instead of "farmed" rats: instead of killing the rats in the city (the "high priority" ones), people are going out into the country and killing rats that weren't really bothering anyone. Eventually they or their descendants might make it to the city and cause a problem, so we're certainly not sad to see them go (environmental concerns breaking the analogy here :)), but the point is those rats/bugs aren't really the ones we care about.

I could have sworn there was an article/blog post a little while back with statistics from a bug bounty program where most of the bugs were relatively trivial (found by automated methods, style consistency, etc.) or else quite obscure, with only a couple 'interesting' ones. But all I can find is this slashdot article, which I don't think is the one I'm thinking of. But I remember the author's summary was also that he still appreciated the peace-of-mind that others had looked through his code and that was all they had come up with, so still a net positive.

Comment Re:Netgear WNDR-3700 (Score 1) 398

I realize it sounds like a dumb slashdot topic, but given my experience with the number of crap wifi access points out there, I can understand the need to get community assessment. I went through several b/g routers (netgear, dlink) which were constantly dropping connections (the netgear one was actually sensitive to certain bit patterns, e.g. a particular CVS checkout would consistently kill the router at the same place in the transfer each time. WTF.), so now I'm wary of upgrading to the N series until I hear of a suitable successor to the venerable WRT54GL.

Comment Waste of money (Score 1) 225

Building a non-oil-based economy would require social and educational development, which in turn requires leadership, or in other words, insight and hard work by the ruling elites.

However building the tallest phallic symbol just requires throwing money at immigrant workers, and in the long run will accomplish nothing much except an impressive symbol of wasted wealth. But it leaves more playtime for the rulers, and a clear sense of accomplishment ("look at that!")... as opposed to actually empowering their people, which would probably be counter-productive to the rulers anyway, diluting their grip on the region.

Comment CTY and PA Gov's School (Score 1) 116

CTY in particular was life changing (F&M FTW!), I am so glad for that experience and the people I met there. Pennsylvania's Governor's School for the Sciences was also very well done, but I'll point out that PA has since cancelled its program because the state politicians are shortsighted idiots. Not that there's any other kind...

Comment Re:Please provide native support of PDF for OS X. (Score 1) 364

Why would you want to launch a whole 'nother application, especially on a platform where PDF is built-in to the OS and can be displayed much faster than launching bloatware like Adobe Reader. Maybe you like Reader or want to disable PDF altogether for security, but I agree it would be nice to have an inline option, this a major reason I use Safari (browse research papers online, with *drumroll* the browser!)

Comment Re:Not fear - disgust (Score 4, Insightful) 1017

What difference does it make that they 'only' use the back of the hand on the erogenous areas? Why should we give a flying fart if it's the front or the back?

How about if TSA 'only' sticks one finger up your ass to check for items, as opposed to using two if they thought you had an evil eye? The point is they should be using ZERO. It's a straightforward violation of unreasonable search and seizure and as well as freedom of movement.

Comment Re:Get another ISP! (Score 2, Insightful) 379

Good luck finding one in your local monopoly. (missed that part?) Even in my major metro area, the next best choice is an also-ran DSL service from Verizon at a fraction of the speed for almost as much money.

This is why we should just give up this free-market farce and regulate the ISPs as utilities, with standards on purity (e.g. not modifying traffic) and equity (not censoring traffic from conglomerate competitors). AKA net neutrality.

Comment Re:Dramatic effect and scientific precision (Score 1) 1017

FYI, most people find slightly 'salted water' aka mineral water tastes better. Besides taste, our bodies need proper salt balance. Consider that most sports drinks, which are focused on rehydration, advertise their electrolyte content -- the electrolytes they speak of are basically also known as 'salts'. They don't add these to make athletes thirsty! You might be curious to read about water intoxication.

You might also be curious to note that the 'crap' in the city water is generally held to higher quality standards than the 'crap' in bottled water. Check a quick search for a variety of articles.

Comment Re:Any reward at all? (Score 1) 197

For a well-known example, the age-old bar tab should have invalidated Amazon's "One-Click". That was well publicized and still got approved. You can claim to be following some set of guidelines, but that just shifts the blame to whoever is making the idiotic guidelines that adding 'on the internet' or recently 'on a mobile device' is somehow a non-obvious extension of prior art. This is an ongoing problem of having the bar set way too low. I don't care whose fault it is, I just want it fixed.

But to counter your direct claims, what do you say to reports of the patent office clearance quotas ([1] [2]) The idea of hurrying up to clear out the backlog only inflates the problem of companies needing to file defensive patents on every trivial little thing, causing even more backlog...

And then there's the whole aspect of "when in doubt, approve and let the courts figure it out" (e.g. [3]) which certainly isn't helping.

Slashdot Top Deals

A morsel of genuine history is a thing so rare as to be always valuable. -- Thomas Jefferson

Working...