Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror

Submission Summary: 0 pending, 43 declined, 5 accepted (48 total, 10.42% accepted)

×
Hardware

Submission + - The Memristor - It may transform computer hardware (americanscientist.org)

al0ha writes: The first new passive circuit element since the 1830s might transform computer hardware.

In a thriving transistor monoculture where more transistors are created than grains of rice grown world wide; can a new circuit element find a place to take root and grow? That’s the question posed by the memristor, a device first discussed theoretically 40 years ago and finally implemented in hardware in 2008. The name is a contraction of “memory resistor,” which offers a good clue to how it works.

Submission + - Why Is Slashdot Session Management Insecure (slashdot.org)

al0ha writes: Why is it that Slashdot session management is insecure? If you force HTTPS during login, then session cookies are set for encrypted sessions only, so for the rest of the site you are not logged in. If you login over insecure HTTP, then the session cookies are set for any connection.

This is totally lame and makes session hijacking via FireSheep simple, as well as credential sniffing on the wire and wireless.

How Geeky can Geeknet be if they can't even handle session management appropriately?

The password change page and login pages should be protected by HTTPS. Then session cookies appropriate for general content, or privileged content (like changing account information) should be set where privileged content always runs over HTTPS.

Android

Submission + - Android Trojan captures credit card details (thinq.co.uk)

al0ha writes: A team of security researchers has created a proof-of-concept Trojan for Android handsets that is capable of listening out for credit card numbers — typed or spoken — and relaying them back to the application's creator.
Privacy

Submission + - Worry About Little Brother (cnn.com)

al0ha writes: To paraphrase the article: "These days, the main enemy of privacy is not Big Brother, but a whole bunch of Little Brothers. I grant you that long experience teaches us that the government itself must be watched. However, if you think that it is the main threat to your privacy these days, I humbly suggest that you think again."

Submission + - Dissecting the neural circuitry of fear (caltech.edu)

al0ha writes: In this week's issue of the journal Nature, a research team led by scientists at the California Institute of Technology (Caltech) has taken an important step toward understanding just how this kickoff occurs by beginning to dissect the neural circuitry of fear. In their paper, these scientists—led by David J. Anderson, the Benzer Professor of Biology at Caltech and a Howard Hughes Medical Institute investigator—describe a microcircuit in the amygdala that controls, or "gates," the outflow of fear from that region of the brain.

Read the Paper if you have No Fear; of real science. :-)

Science

Submission + - School; where most Americans learn science. NOT! (americanscientist.org)

al0ha writes: From American Scientist: "Although data show that taking college-level science courses dramatically improves public science literacy, only about 30 percent of U.S. adults have ever taken even one college-level science course."

This is an interesting statistic; I guess...

Security

Submission + - Zeus Trojan 2p0wn 2 Factor Auth (net-security.org)

al0ha writes: The attack begins as it usually does — the Trojan steals the username and password as it is inserted by the user. Then, a rogue form pops up and demands of him to share his mobile phone vendor, model and phone number:

A while back Schneier pointed out the failure of 2 factor auth: http://www.schneier.com/blog/archives/2005/03/the_failure_of.html

Security

Submission + - Haystack Security Goes Up in Flames (slate.com)

al0ha writes: Among many others I also found myself very skeptical that this self-proclaimed, "Whiz Kid" could code a truly useful and secure application in a few days.. Seems it turns out to be just another example of over-hype by the media regarding a product they themselves never saw. How pathetic.
Science

Submission + - Possible Dark Matter Discovery (smh.com.au)

al0ha writes: TWO small signals detected in an experiment deep underground in an abandoned US iron ore mine could be the first glimpses of the mysterious dark matter that is thought to make up about 24 per cent of the universe.
Security

Submission + - Browser Security Courtesy of the American Taxpayer (darkreading.com)

al0ha writes: Invincea, a security firm originally funded by the Defense Advanced Research Projects Agency (DARPA) to build a prototype virtualized browser, today rolled out a Windows application that places Internet Explorer (IE) into a virtual environment in order to protect the underlying system from Web-based attacks.

While the product is an interesting idea and may be useful, I totally object to the pricing as an American taxpayer. I have already helped pay for the development of this product; the CEO must be related to Bush/Cheney somehow. What a scam.

Security

Submission + - Active Govt. SSL MITM Spying (crypto.com)

al0ha writes: From the article, "A paper published today by Chris Soghoian and Sid Stamm [pdf] suggests that the threat may be far more practical than previously thought. They found turnkey surveillance products, marketed and sold to law enforcement and intelligence agencies in the US and foreign countries, designed to collect encrypted SSL traffic based on forged 'look-alike' certificates obtained from cooperative certificate authorities."

There is protection via an FF add-on...

Linux

Submission + - Darl, please go away now like a good boy (novell.com)

al0ha writes: Today, the jury in the District Court of Utah trial between SCO Group and Novell issued a verdict.

Novell is very pleased with the jury’s decision confirming Novell’s ownership of the Unix copyrights, which SCO had asserted to own in its attack on Linux. Novell remains committed to promoting Linux, including by defending Linux on the intellectual property front.

This decision is good news for Novell, for Linux, and for the open source community.

Well as long as Larry never buys Novell that is!

Unix

Submission + - SCO and McBbride refuse to die (theregister.co.uk)

al0ha writes: Desperate to fund its seemingly-endless legal battle for Unix copyrights against Novell and others, SCO Group has found someone willing to buy the bankrupt company's mobile assets — and it's none other than Darl McBride, the former SCO chief executive sacked as a result of his ruinous crusade to claim Unix.

Slashdot Top Deals

It is easier to write an incorrect program than understand a correct one.

Working...