Catch up on stories from the past week (and beyond) at the Slashdot story archive


Forgot your password?

Comment Too much javascript (Score 1) 37

There's not only too much javascript, it looks like you've got some sort of movie trying to load. (I didn't wait for it to time out, but I think it would have.)

I can easily handle most stores, but not that one.

Comment Hydrogen is a scam (Score 1) 293

It is mostly produced from hydrocarbon fractionation, mostly natural gas fractionation. It can also be produced from coal. It there does nothing to reduce dependence on fossil fuels and the process release large amounts of CO2. So, in my opinion, it is a useless road to go down and a scam.

Comment Re:Microsoft Windows only (Score 2) 143

Despite the "only security through obscurity" meme, you need to understand it, not just say it.

There are only two types of security:
1) security through obscurity,
2) security through inaccessibility.
They can, however, be intelligently combined.

Please note that private key encryption is security through obscurity. Cutting the phone line is security through inaccessibility. Saying that "it's secure because they can't get the prime factors of that key" is security through obscurity.

Despite the meme, security through obscurity is widely and properly used. What's wrong if false obscurity, which is common. If you don't properly assess just how obscure your secret is, then you have a security failure.

So having a monoculture is reduced security, because that means that there are a much larger number of entities seeking to discover the secret...and any breach in security cannot be easily contained. If you don't have a monoculture, then a single breach cannot be as widely damaging, and is thus also less valuable to find. This is a sort of network effect.

OTOH, a diverse community means that more effort needs to be devoted to security, because each branch is a separate thing to be maintained. So it's not all benefit or all loss, it's a mixture.

FWIW, I choose not to have flash installed on my system, despite the fact that it would have some utility, because I consider that the weakness that it presents is not worth the benefit. The ability of refuse to have such a service installed allows increased a cost. For some people the cost is higher than they are willing to pay. This reduction of the attack surface is a form of security through obscurity mixed with security through inaccessibility, i.e., I have become inaccessible to some forms of attact, and I have reduced my visibility to many attackers.

Slashdot Top Deals

"Remember, extremism in the nondefense of moderation is not a virtue." -- Peter Neumann, about usenet
