Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Security

Drupal Warns Users of Mass, Automated Attacks On Critical Flaw 76

Trailrunner7 writes The maintainers of the Drupal content management system are warning users that any site owners who haven't patched a critical vulnerability in Drupal Core disclosed earlier this month should consider their sites to be compromised. The vulnerability, which became public on Oct. 15, is a SQL injection flaw in a Drupal module that's designed specifically to help prevent SQL injection attacks. Shortly after the disclosure of the vulnerability, attackers began exploiting it using automated attacks. One of the factors that makes this vulnerability so problematic is that it allows an attacker to compromise a target site without needing an account and there may be no trace of the attack afterward.

Comment Re:We can be certain of one thing (Score 1) 152

That was an analogy and was not intended to be identical in every way. The similarity is in the relationship between employee and employer, and the significance of what someone might consider the "main work" when in fact it is not.

Why do I have to explain this?

Because in the case of creator's rights that your analogy is aluding to, it's the relationship of the creator and employer that are the most relevant to the discussion.
It's the creator, or their estates, who often claim control of the rights and demand compensation retroactively for a share of the total profits. That hardly if ever happens with the dozens of people who created new material using the characters after the creator has moved on.

So the players in a relevant analogy are:

The creator who had the original idea for a character = The inventor of the recipe for the burger, nuggets, joyful meal etc.
The people who do the "main work" for decades after the creator stops working on the character (and usually generate more total revenue than the creator ever did alone). Writers, artists, colorists, inkers, letterers, editors = burger flippers, fry cooks, managers, etc.
The employer = The employer.

That last one was spot on, I'll say.

Comment Re:Only usefull for wine? (Score 1) 55

You make no sense, since having only the proprietary driver available sounds to me like "require you to have a specific driver installed". The Gallium3D driver, which supports Radeon cards since the R300 series (Oct 2002), offers an alternative to the required proprietary driver. And since AMD regularly drops support for older hardware in the proprietary driver, the Gallium3D drivers supports a wider variety of hardware, and will continue to do so. Seems like writing for the proprietary driver is the more risky approach with a smaller potential audience.

Programming

Code.org: Blame Tech Diversity On Education Pipeline, Not Hiring Discrimination 227

theodp writes: "The biggest reason for a lack of diversity in tech," says Code.org's Hadi Partovi in a featured Re/code story, "isn't discrimination in hiring or retention. It's the education pipeline." (Code.org just disclosed "we have no African Americans or Hispanics on our team of 30.") Supporting his argument, Partovi added: "In 2013, not one female student took the AP computer science exam in Mississippi." (Left unsaid is that only one male student took the exam in Mississippi). Microsoft earlier vilified the CS education pipeline in its U.S. Talent Strategy as it sought "targeted, short-term, high-skilled immigration reforms" from lawmakers. And Facebook COO and "Lean In" author Sheryl Sandberg recently suggested the pipeline is to blame for Facebook's lack of diversity. "Girls are at 18% of computer science college majors," Sandberg told USA Today in August. "We can't go much above 18% in our coders [Facebook has 7,185 total employees] if there's only 18% coming into the workplace."

Comment Re:So essentially... (Score 1) 76

Don't trivialize this by ignoring the true nature of the breach.

This is more like obtaining an exclusive unlisted client list detailing who exactly is doing business with a given organization. The phone book doesn't provide that connection - knowing names, addresses and phone numbers doesn't tell you which crucial and vulnerable businesses are associated with a household. Obtaining the same information from a business of interest is a different story entirely. Metadata is crucially important.

Comment Re:Security through obscurity - useful but inadequ (Score 0) 76

Well, that's hardly comforting. So even spending an ENORMOUS amount of money on IT and security can't prevent your system from being breached in a big and spectacular way? Then either that enormous amount of money was spent poorly, or that information should not have been exposed to the internet in the first place until it was properly secured. They were breached, in a big way. So their systems were exactly as weak as I think, enormous expenditure aside. I fail to see your point. "They tried REALLY hard" doesn't count for beans if they don't succeed.

Comment Security through obscurity - useful but inadequate (Score 4, Insightful) 76

The hackers appeared to have obtained a list of the applications and programs that run on JPMorgan's computers — a road map of sorts — which they could crosscheck with known vulnerabilities in each program and web application

I find this interesting because it shows both the usefullness but ultimate inadequacy of security through obscurity. Had the hackers been unable to obtain this information, the implication is that the breach would not have happened, or at least not happened as soon. Without the ability to create a road map, they would have had to take the less efficient approach of randomly guessing and probing with the hope that something worked. So keeping that list of applications and programs a secret has some value.

On the other hand, it underscores the importance of the point that people have been making about security through obscurity for decades: it's very weak security, and once that layer of the security onion is breached, there had better be stronger security layers underneath. Like patched and updated programs and web applications that close known vulnerabilities. I'm guessing that didn't happen, because the JP Morgan Chase management has probably acted like many other management teams I've had the "pleasure" of working with - they placed higher value on the secrecy than actually fixing stuff, because the former costs less, and it kind of works until it doesn't (and then that policy fails in a big way).

I sincerely hope that these breaches light a fire under the asses of lax management at these large companies and they realize that spending the time and resources to *really* secure their systems is worth it in the long run.

And then I laugh sadly, because that's wishful thinking.

Comment Re:How long is a piece of string? (Score 1) 209

The data bits go by pretty fast when using one's phone as a hotspot to RDP to a work computer...

Yep. I've done that too. And that's kind of the point. The benefit of the unlimited plan isn't about the constant baseline level of usage - it's more about when you need more data than normal. If you don't approach the capped limit, Verizon comes out ahead because you used "less" than your alotted limit (if you were capped). but when you exceed the capped limit under the new plans, you pay dearly, because you likely don't just go over a little bit, you go over a lot for the time when you are solely relying on that 4G data stream. And you probably really need it, so there isn't the option of just not using your 4G connection.

I personally find the concept of data caps problematic because unless you consistently exceed them, you can't really be considered to be "abusing" the network when your usage spikes on occasion.

So why the big focus on data caps? Probably because they know that data usage is only going to go up, so what used to be excessive data usage becomes the new normal. And then your risk of exceeding the data cap becomes even greater, and the framework is in place to catch you doing so in order to extract the requisite fees.

One thing I've never heard is the data caps being raised as a function of the average use across the entire customer base so that overages continue to represent spikes of excessive use rather than just evolving with the increase in streaming everything. As more people stream, the idea of what constitutes excessive use should increase.

Comment How long is a piece of string? (Score 3, Insightful) 209

Stupid analogy, that.

Useful answers to this should take into account the problem with the question of "How long is a piece of string?" Give some context about how much you pay, and how much you use -- and how much that would change if the price were different.

The second half of the commentary in the summary is a bit easier to digest. Yes, it all boils down to math. The key is, Verizon has probably calculated how the math will benefit them in the long run, and customers effectively can't, so the game is rigged from the start.

Let's give an example. Verizon bases their "limited" usage caps based on the average usage of their aggregate customer base (plus a little wiggle room, I guess). So on average, the data usage of a given customer won't go over the limit. However, the usage of a particular customer might exceed the cap at particular times. Travel/vacation time is a good time for this. You use more data while running the GPS-based turn-by-turn navigation while driving to your destination. Once there, you want some entertainment during the evenings, but you're not at home where you can use your home-based internet via wi-fi, so you stream some Netflix via 4G. Since your phone can output 1080p via HDMI, you use that cable you bought to plug into the HDMI port of the television at the place you are staying. Depending on the length of your stay, that's a significant spike in your data usage.

Under the unlimited plan, you either get throttled at some point (but now you don't) or you just don't notice the fact that you wandered above the average usage for the week or two you were traveling, because unlimited. Under capped, metered data plans, you are subject to overage fees based on a cap that has been fine tuned to be just above the threshold of "normal" usage, so your bill is higher. It may be only for those few weeks, so easy to absorb, but add that up across the entire customer base and Verizon has made more money than they would have with the unlimited data plans in place.

*That* is what it's all about. So unless you absolutely have to, you might as well stick to your grandfathered unlimited plan, because once you give it up, you will be fleeced, even if just a little bit.

Comment Re:Speak for yourself, Mr. Emanuel (Score 1) 478

I have a wife who is a board member for the local hospice, so I get to accompany her to a lot of functions. Many of the board members are approaching or have passed the age of 70 and still seem to be going strong. Note I said "board members" - those who are managing the entire affair (quite effectively from what I can gather), not those in need of care. Your friend may have experienced some selection bias because of his work. That doesn't mean his observations apply to everyone. In fact I'm sure they don't.

Slashdot Top Deals

Be careful when a loop exits to the same place from side and bottom.

Working...