Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Security

Kaminsky On DNS Bugs a Year Later and DNSSEC 127

L3sPau1 writes "Network security researcher Dan Kaminsky has had a year to reflect on the impact of the cache poisoning vulnerability he discovered in the Domain Name System. In the time since, Kaminsky has become an advocate for improving security in DNS, and ultimately, trust on the Internet. One way to do this is with the widespread use of DNSSEC (DNS Security Extensions), which essentially brings PKI to website requests. In this interview, Kaminsky talks about how the implementation of DNSSEC would enable greater security and trust on the Net and provide a platform for the development of new security products and services."

Comment Re:It's Comcastic (Score 1) 281

inet6 addr: fe80::***:****:****:****/64 Scope:Link

No need to redact that. It's a link-local, non-routable address []

The lower 64 bits almost certainly contain the interface's MAC address; while it's not as bad as a globally reachable network address, some people still might not want to post it openly on /.

Biotech

Fertility Clinic Bows To Pressure, Nixes Eye- and Hair-Color Screening 847

destinyland writes "A fertility service in L.A. and New York screens embryos for breast cancer, cystic fibrosis, and 70 other diseases — and lets couples pick the sex of their babies. But when their pre-implantation diagnostic services began including the baby's eye and hair color, even the Pope objected — and the Great Designer Baby Controversy began. '[W]e cannot escape the fact that science is moving forward,' the fertility service explained — before capitulating to pressure to eliminate the eye and hair color screenings."
Security

Microsoft's Free AV App May Be a Non-Starter 251

CWmike writes "Microsoft is preparing to launch a public beta of Morro, the free anti-malware it announced last November, according to reports. Morro will use the same scanning engine as Windows Live OneCare, the software that the free software will replace and Microsoft's first consumer-grade antivirus package. OneCare is to get the boot as of June 30 (along with finance app Microsoft Money). John Pescatore, an analyst at Gartner, has questioned whether users would step up to Morro even if it was free. 'Consumers are hesitant to pay for a Microsoft security product that will remove problems in other Microsoft products,' he said. 'Think of it this way. What if you smelled a rotten egg odor in your water and the water company said, "Sure, we can remove that, but it will cost you $50." Would you buy it?' Not surprisingly, competitors have dismissed Morro's threat to their business. 'We like our chances,' Todd Gebhart, vice president in charge of McAfee's consumer line, said when it was announced OneCare was a goner. 'Consumers have already rejected OneCare,' added Rowan Trollope, senior vice president of consumer software at Symantec. 'Making that same substandard security technology free won't change that equation.'"
Networking

Comcast Intercepts and Redirects Port 53 Traffic 527

An anonymous reader writes "An interesting (and profane) writeup of one frustrated user's discovery that Comcast is actually intercepting DNS requests bound for non-Comcast DNS servers and redirecting them to their own servers. I had obviously heard of the DNS hijacking for nonexistent domains, but I had no idea they'd actually prevent people from directly contacting their own DNS servers." If true, this is a pretty serious escalation in the Net Neutrality wars. Someone using Comcast, please replicate the simple experiment spelled out in the article and confirm or deny the truth of it. Also, it would be useful if someone using Comcast ran the ICSI Netalyzr and posted the resulting permalink in the comments.
Portables

Qualcomm Demos Eee PC Running Android OS 125

angry tapir writes "Qualcomm has showed off a version of Asustek Computer's Eee PC based on its Snapdragon processor at the Computex exhibition, including one running Google's Android operating system. The new laptop — which Qualcomm calls a smartbook — is thinner and lighter than current members of Asustek's Eee PC netbook lineup because the 1GHz Snapdragon processor that it uses does not require a heat sink or a cooling fan."
Operating Systems

When VMware Performance Fails, Try BSD Jails 361

Siker writes in to tell us about the experience of email transfer service YippieMove, which ditched VMware and switched to FreeBSD jails. "We doubled the amount of memory per server, we quadrupled SQLite's internal buffers, we turned off SQLite auto-vacuuming, we turned off synchronization, we added more database indexes. We were confused. Certainly we had expected a performance difference between running our software in a VM compared to running on the metal, but that it could be as much as 10X was a wake-up call."
Television

Hulu Testing Client App; Boxee Dispute Explained 166

N!NJA sends in word of Hulu's new beta section, Hulu Labs, which is now showcasing Hulu Desktop, a client that runs on both Windows and Mac. The author believes that Hulu Desktop explains why Hulu has been so touchy about Boxee. "This clearly explains why Hulu has been so persistent in blocking Boxee — an open-source media-center application for Macs, Apple TVs, and other devices — from including its content. Since Hulu provides free, ad-based mainstream content from the largest studios and networks in the business, they are under tight constraints imposed by these major players. We have already seen good examples of where Hulu is heading with integrated advertising inside the browser. A desktop client produced in-house will be much more conducive to monetizing Hulu using these kinds of campaigns."
Censorship

Church of Scientology On Trial In France 890

An anonymous reader sends word that a trial has opened in Paris that could shut down Scientology in France. The organization stands accused of targeting vulnerable people for commercial gain. Scientology does not have the status of a religion there, as it does in the US, and anti-cult groups have pursued it vigorously over more than 30 years. The current case is based on complaints filed by two women in December 1998 and July 1999. Three other former members who had initially joined the complaint have withdrawn after "reaching a financial arrangement with church officials." If convicted, the seven top Scientologists in France face up to 10 years in prison and a fine of €1M. The Church of Scientology-Celebrity Centre and its Scientology Freedom Space bookshop not only face a much larger fine but also run the risk of being shut down completely.
XBox (Games)

Microsoft Trying To Patent a 'Magic Wand' 157

theodp writes "Newly-disclosed USPTO documents show that Microsoft is seeking patent protection for a 'Magic Wand,' a device with various gizmos and sensors that can manipulate and interact with its environment, including video and holographic images, while using biometrics to connect with the user. 'Even the most pragmatic individual,' explains Microsoft, 'would have trouble arguing against the merits or utility of, say, a magic wand that actually worked to control or communicate with objects or components in an associated nearby environment.' No doubt. The inventors include CXO/CTO J Allard, and Sr. Researcher Andy Wilson."
The Courts

Usenet Group Sues Dutch RIAA 90

eldavojohn writes "With the Pirate Bay trial, it's been easy to overlook similar struggles in other nations. A Dutch Usenet community named FTD is going on the offensive and suing BREIN (Bescherming Rechten Entertainment Industrie Nederland). You may remember BREIN (along with the IFPI & BPI) as the people who raided and cut out the heart of eDonkey. This is turning into a pretty familiar scenario; the FTD group makes software that allows its 450k members to easily find copyrighted content for free on Usenet. The shocking part is that FTD isn't waiting for BREIN to sue them. FTD is refusing to take down their file location reports, and is actually suing BREIN. Why the preemptive attack? FTD wants the courts to show that the act of downloading is not illegal in the Netherlands. (Both articles have the five points in English that FTD wants the courts to settle.) OSNews has a few more details on the story."
Google

Confirmed Gmail / Google App Outage 189

mbone writes "Earlier today there was a confirmed Google outage which got a lot of attention from network operators. From a post to NANOG after everything calmed down: 'Google ack'd a maintenance on their core network did not go as planned-Forced traffic to one peer link that was unable to handle all the traffic. Maintenance has been rolled back. Issue has been restored.' This is exactly what makes me nervous about cloud computing and data storage. It's bad enough when I screw up a config and it takes down my mail, but what about when it happens to the entire globe at once?" Several readers also point to CNET's coverage of the outage. Update: 05/14 19:25 GMT by T : CWmike adds this: "Steven J. Vaughan-Nichols writes that what may be happening is a massive DDoS attack. Based on the size of the attack that would be needed to interfere with Google, I believe that it's quite likely to be the result of an attack from the controllers of the Windows worm, Conficker. Another theory that has been put about — that the problem was due to AT&T NOC routing problems — does not appear to hold water, writes Steven." Update: 05/14 21:01 GMT by T : Google's put up a low-detail explanation on their blog that says "An error in one of our systems caused us to direct some of our web traffic through Asia, which created a traffic jam. As a result, about 14% of our users experienced slow services or even interruptions."
The Media

Craigslist Kills Erotic Services Ads, Will Launch Adult Section 390

CWmike writes "Submitting to mounting legal pressure, Craigslist has announced that it will remove the Erotic Services category from its classified advertising Web site within seven days. The move comes just two and a half weeks after Jim Buckmaster, CEO of Craigslist, told Computerworld that the company had no intention of removing the category. While it's taking down the category, it will be launching a new category called Adult Services, for which each posting will be manually reviewed before it appears. 'Unsurprisingly, but completely contrary to some of the sensationalistic journalism we've seen these past few weeks, the record is clear that use of Craigslist classifieds is associated with far lower rates of violent crime than print classifieds, let alone rates of violent crime pertaining to American society as a whole,' said Buckmaster in a blog post today. 'We are optimistic that the new balance struck today will be an acceptable compromise from the perspective of the constituencies, and for the diverse US communities that value and rely upon Craigslist.'"
Privacy

Cone of Silence 2.0 91

Village Idiot sends word of a patent granted to MIT researchers for a cone of silence a la Maxwell Smart. This one doesn't use plastic, but rather active and networked sensors and speakers embedded in a (probably indoor) space such as an open-plan office. "In 'Get Smart,' secret agents wanting a private conversation would deploy the 'cone of silence,' a clear plastic contraption lowered over the agents' heads. It never worked — they couldn't hear each other, while eavesdroppers could pick up every word. Now a modern cone of silence that we are assured will work is being patented by engineers Joe Paradiso and Yasuhiro Ono of the Massachusetts Institute of Technology. ... Instead of plastic domes, they use a sensor network to work out where potential eavesdroppers are, and speakers to generate a subtle masking sound at just the right level. ... The array of speakers... aims a mix of white noise and randomized office hubbub at the eavesdroppers. The subtle, confusing sound makes the conversation unintelligible." One comment thread on the article wonders about the propriety of tracking people around an office in order to preserve privacy.
Cellphones

Time For Voice-Mail To Throw In the Towel 393

theodp writes "Slate's Farhad Manjoo feels the end of voice-mail is nigh, and it won't be missed. Since March, he's been using Google Voice to transcribe his voice-mail messages into text that he gets as skimmable e-mail. No more listening to at least a bit of each voice-mail message, hearing the same instructional prompts between each, and worrying about whether it's 9-to-archive and 7-to-skip (or vice versa). Goodbye and good riddance, says Manjoo, to an 'absurdly backward mode of human-computer interaction' that he half-jokes must violate the Geneva Conventions."

Slashdot Top Deals

The question of whether computers can think is just like the question of whether submarines can swim. -- Edsger W. Dijkstra

Working...