Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Privacy

Submission + - Ontario Court, No search warrant for IP to name (nationalpost.com)

AHuxley writes: An Ontario Superior Court, Canada could allow police to use Internet protocol addresses
to find names of users without a search warrant.
Justice Lynne Leitch found that there is "no reasonable expectation of privacy"
in subscriber details logged by an Internet service provider.
"One's name and address or the name and address of your spouse are not biographical
information one expects would be kept private from the state," Judge Leitch said.

Comment Re:its only the CA's that use MD5 so the question (Score 4, Informative) 300

If I understand the CCC's paper correctly, as long as *even one* of the CA certs trusted by the browser uses MD5, it is possible (with considerable effort) to create an intermediate CA cert that can be used to sign a cert for any FQDN, say paypal.com. Then with a little DNS poisoning, the user is directed to an https site, with a correct domain name and (if the user looks, not bloody likely) a perfectly good certificate that looks like it was signed by a cert that was signed by a cert trusted by the browser.

You don't have to create many rogue certs, all you have to to is create one rogue intermediate CA cert that can sign as many certs as you like, all of which will be accepted with the default browser config. This is what the CCC has done.
Power

Ubiquitous Hydrogen Power Not Getting Any Closer 267

NewScientist has a story about the "hydrogen economy" that has been resting on the horizon for a decade or more. Despite a great deal of enthusiasm for and research into hydrogen-based power systems, the technology seems just as far away from everyday use as it's always been. A British startup, ITM Power, has recently claimed a breakthrough in lowering production costs by using a nickel catalyst (rather than platinum) with a membrane small enough for home use. But, even if their method is proven and adopted, it still wouldn't address huge energy efficiency problems in the process. "The point was made forcefully by Gary Kendall of the conservation group WWF in a recent report called Plugged In (PDF, pgs. 135-149). Kendall, a chemist who previously spent almost a decade working for ExxonMobil, highlights how the energy losses in the fuel chain - from electrolysis to compression of the hydrogen for use to inefficiencies in the fuel cell itself — mean that only 24 per cent of the energy used to make the fuel does any useful work on the road."
Security

Net Shoppers Bullied Into "Verified By Visa" Program 302

bluefoxlucid writes "According to The Register, several banks are forcing users to opt-in to the Verified by Visa optional service by locking their cards if and when they encounter a Verified by Visa participating site and fail to opt-in. Register reader Steve says, 'This seems like a strange way to implement a voluntary system. On most of the retailers' websites there is no clue that you are about to be challenged by Verified by Visa until you attempt to complete the transaction. This means that you trigger the "fraud protection" unintentionally. And when you have located a retailer who doesn't require Verified by Visa to complete a purchase, you can't because your account is on hold.' Further, '[I]n some cases resetting the password is all too easy. Fraudsters know this and go after these credentials which, once obtained, make it harder for consumers to deny responsibility for a fraudulent transaction. Phishing scams posing as Verified by Visa sites have sprung up targeting these login credentials.'"
The Courts

Non-Compete Clauses Thrown Out In California 375

drfuchs writes "If you signed an employment agreement in California, any non-compete clause in it is null & (void*), says the state Supreme Court of California (ruling PDF). Better still, the San Francisco Chronicle opines that the US Federal courts are likely to fall in line with the decision in the way they interpret California law. (Most other states still have non-compete laws on the books and it's not clear this ruling will affect them.) Turns out it wasn't a high-tech case at all, but a CPA who had worked for the accounting firm Arthur Anderson (now disgraced due to their complicity in the Enron case)."
Education

"Last Lecture" CMU Professor Randy Pausch Dies 208

Many readers are sending in word that Randy Pausch has died at 47. The charismatic young college professor celebrated life despite a death sentence from pancreatic cancer in a remarkable speech widely known as the "Last Lecture." The video went viral and has been downloaded by over 10 million people.
Caldera

10K Filing Suggests Grim Outlook for SCO 149

dacarr writes "SCO has filed their 10K with the SEC — and according to this, their own assessment of the company's outlook is pretty grim. As usual, PJ of Groklaw has a good synopsis of the filing highlights. In short, it boils down to one thing: unless there's a miracle, even SCO doesn't think they're going to come out of this. 'As a result of the Chapter 11 filings, realization of assets and liquidation of liabilities are subject to uncertainty. While operating as debtors-in-possession under the protection of Chapter 11 of the Bankruptcy Code, the Debtors may sell or otherwise dispose of assets and liquidate or settle liabilities for amounts other than those reflected in the consolidated financial statements, in the ordinary course of business, or, if outside the ordinary course of business, subject to Bankruptcy Court approval. In addition, under the priority scheme established by the Bankruptcy Code, unless creditors agree otherwise, post-petition liabilities and prepetition liabilities must be satisfied in full before stockholders are entitled to receive any distribution or retain any property under a plan of reorganization.'"
Announcements

2008 Turing Award Winners Announced 66

The Association for Computing Machinery has announced the 2008 Turing Award Winners. Edmund M. Clarke, Allen Emerson, and Joseph Sifakis received the award for their work on an automated method for finding design errors in computer hardware and software. "Model Checking is a type of "formal verification" that analyzes the logic underlying a design, much as a mathematician uses a proof to determine that a theorem is correct. Far from hit or miss, Model Checking considers every possible state of a hardware or software design and determines if it is consistent with the designer's specifications. Clarke and Emerson originated the idea of Model Checking at Harvard in 1981. They developed a theoretical technique for determining whether an abstract model of a hardware or software design satisfies a formal specification, given as a formula in Temporal Logic, a notation for describing possible sequences of events. Moreover, when the system fails the specification, it could identify a counterexample to show the source of the problem. Numerous model checking systems have been implemented, such as Spin at Bell Labs."
The Courts

Submission + - RIAA ordered to divulge expenses-per-download

NewYorkCountryLawyer writes: The Court has ordered UMG Recordings, Warner Bros. Records, Interscope Records, Motown, and SONY BMG to disclose their expenses-per-download to the defendant's lawyers, in UMG v. Lindor, a case pending in Brooklyn. The Court held that the expense figures are relevant to the issue of whether the RIAA's attempt to recover damages of $750 or more per 99-cent song file, is an unconstitutional violation of due process.
Science

Nano Safety Worries Scientists More Than Public 167

Nanotech Coward writes "The unknown human health and environmental impacts of nanotechnology are a bigger worry for scientists than for the public, according to a new report in the journal Nature Nanotechnology. The new report was based on a national telephone survey of American households and a sampling of 363 leading U.S. nanotechnology scientists and engineers. It reveals that those with the most insight into a technology with enormous potential — and that is already emerging in hundreds of products — are unsure what health and environmental problems might be posed by the technology."

Slashdot Top Deals

U X e dUdX, e dX, cosine, secant, tangent, sine, 3.14159...

Working...