Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×

Comment Re:say wha? (Score 4, Informative) 68

JSONP callback functions normally return a JSON blob wrapped in a user-specified callback function, which the browser will then execute as JavaScript. Nothing out of the ordinary here. However, the new attack has leveraged a method of crafting a Flash file to contain a restricted character set that's usable within JSONP callbacks (i.e. in a URL). By combining the two, the attack demonstrates it's possible to use a JSONP URL with the contents of the crafted Flash file as the callback function. When set as the data of a standard HTML object tag, the SWF file executes on the targeted site, bypassing all Same-Origin policies in place.

ummmm what? english please!

The code sneaks a Flash file disguised as a URL into some JSON data and cons the browser into treating it as JavaScript, but on the local machine it acts like an HTML <OBJECT>, and because the browser is executing the Flash code locally now (due to the masquerade), it can run with greater privileges than if it were from a remote site.

Or in layman's terms: Flash totally sucks the suckage, dude. Always did. Still does.

Comment Re:Good news though (Score 1) 74

This is just flat out wrong. Have you ever actually seen a 1099? If you are paying an individual, the SSN is the tax id, and must be listed on the form. If you are paying a corporation, then you don't use a 1099.

Not so, I contract, I am an individual working for my own S-corp.

I have never given out my SSN when being paid 1099 through my company.

I give out only my TIN, they pay me with checks, and at EOY I get a 1099 from them for my tax purposes.

Comment Re:Good news though (Score 1) 74

Unless the doctor is incorporated, the SSN is the tax id.

Err, if the said Dr. is in business and is not incorporated, he's quite a fool.

They didn't. The gave out their SSN because this is directly related to SS transactions. The doctors receive payments from the insurance company, and those payments must be reported to the IRS on a 1099 form, and that must include the tax id, which is the SSN.

Err, no. there is NO place to fill out SS on a 1099 payment. That is precisely where you have and use your TIN (Tax Identification Number), You only give your SS on your Personal tax forms at EOY in that situation.

No, there is no valid reason a Physician should be giving out his personal SS for a business transaction, especially if it is a 1099 and NOT a W2 type form. Taxes are NOT taken out of 1099â¦.you are responsible for that on your own at EOY.

he sooner we move away from the idiotic notion that the same number should be used for both identification and authentication, and thus must be simultaneously both widely known and secret.

ON this I heartily agree.

Comment Re:The Watchers 'Wet Dream' (Score 1) 150

I know I'm getting old, but more and moreâ¦I"m going retro, and analog.

I'm still mobile enough to get off my ass, and change the manual thermostat, etc.

WTF would I give out my energy info? I make enough $$ to pay them monthly, etc.

They only have a need to know if I"m having a problem paying, nothing more.

I just don't' get it when folks voluntarily give out SO much info on themselves. I don't see it being long till this really starts biting people in the ass.

Comment Re:Good news though (Score 4, Informative) 74

This was my first thought, WTF are they using SS on this type of report at all?!!?

I mean, if they need a record of the physician's business, why not use the Federal Tax ID? Why in the world would anyone give out a SS number in this day in age for anything besides something that is directly related to SS transactions (taxes, payments, etc)?

I don't give my SS to anyone except the bank and for SS tax purposes. My last power company tried to insist I give it to them, when I asked WTF they needed this for simply connecting power they said for a 'credit check'. I talked further and found out they'd take a deposit in lieu of this and that's the road I took. I got the deposit refunded about 6mos later I think.

But seriously, there not a THING these days that should or does require a SS# to be given. However, sometimes, sadly, you DO need to be persistent in your insistence that they don't need it. Speak to a mgr or two if need be, but don't' give it out.

Comment Re:Chattel slavery is so passé (Score 1, Troll) 21

Broad-spectrum legal reform is the kind of issue that seems blatantly obvious to even the most casual observer.
And yet the number of Congresscritters of any strip running on the idea is. . .um. . .wait a sec. . .let's look at Libertarians. . .
Unfortunately, all the power is draining into DC, where the money can be printed at will, thus giving a us positive feedback loop.

Slashdot Top Deals

A meeting is an event at which the minutes are kept and the hours are lost.

Working...