Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×

Submission + - Why hackers may be stealing your credit card numbers for years (computerworld.com.au)

angry tapir writes: The PCI Security Standards Council, which develops PCI-DSS, has recommended that merchants switch to using point-to-point encryption to prevent the largescale siphoning of credit card details from point of sale terminals (think Target, Neiman Marcus, Michaels, UPS Store and others). However, retailers often have long technology refresh cycles, so it could be five to seven years before most move to it — not to mention that the fact that PCI-DSS version 3.0 doesn't even mandate the use of point-to-point encryption.

Comment Re:Why? Nobody uses NFC payments (Score 2) 187

NFC payment cards in Australia/Europe cryptographically sign a challenge from the terminal, using basically standard crypto. It's EMV all the way. In-person magstripe payments are carefully controlled and risk analysed to ensure they only occur if, for example, the card is broken - or outright banned.

NFC payments in the USA involve the phone sending regular magstripe data to the terminal, with only the CVC code being some kind of cryptographic derivative - a three digit number (less than 1000). The reason for this crazy setup is so merchants don't have to update their backend/PoS systems that still expect magstripe data. There is no plan to perform a complete upgrade thus old style transactions cannot be phased out. It's a dramatically less secure system.

Comment Re: As much as I hate Apple (Score 4, Interesting) 187

More importantly, the underlying technology is totally different. VISA Europe is not at all the same as VISA USA. VISA in Europe is a coalition of banks, VISA USA is a private company. America has never rolled out EMV, making its banking industry a ridiculous joke compared to, well, everywhere else. You don't get reports of major European supermarket chains getting their PoS systems hacked and magstripes skimmed like you do in the US, because EMV is a much more secure system.

The NFC payment cards that are rolling out around the world (outside USA) now are basically a variant of EMV/Chip and PIN. The underlying crypto is the same. The card signs a challenge from the terminal. They're upgrading to elliptic curve crypto at the moment actually, not sure if all NFC cards do that or not but it would not surprise me. NFC as tried by Google in America is actually a very minor variant on just sending your magstripe data via radio. I believe the CVC code rotates (three digits of entropy lol) and the tech is based on a Secure Element hard-wired to the NFC radio. But the phone has minimal control over the actual payment transaction, thus doesn't add much value beyond being a big battery, and that's why the tech largely stalled. Also they screwed up the compatibility testing and the terminals were full of bugs that meant transactions just sort of randomly failed.

So don't be fooled. The "NFC payments" that we know outside of North America is totally different to what they call "NFC payments", which is an unfortunate piece of linguistic confusion.

Comment Re:Not quite old but... (Score 1) 635

--You should try switching to the palemoon browser. Nice replacement for firefox, based on the same code base, and WITHOUT all the stupid new UX crappiness (i.e. Australis.) Mostly trivial to copy your settings over but you have to know where the cache dir/files live, they don't have an Import coded yet(?) for FF.

The Internet

Grand Ayatollah Says High Speed Internet Is "Against Moral Standards" 542

An anonymous reader writes A Grand Ayatollah in Iran has determined that access to high-speed and 3G Internet is "against Sharia" and "against moral standards." However, Iran's President, Hassan Rouhani, plans to renew licenses and expand the country’s 3G cellular phone network. A radical MP associated with the conservative Resistance Front, warned: “If the minister continues to go ahead with increasing bandwidth and Internet speed, then we will push for his impeachment and removal from the cabinet.” “We will vigorously prevent all attempts by the [communication] minister to expand 3G technology, and if our warnings are not heeded, then the necessary course of action will be taken,” he added.

Comment Re:How I know that Russian troops are not in Ukrai (Score 2) 254

Here's a tip, my Russian friend: if you want to pretend to be a neutral observer on the Ukrainian conflict in an internet forum, then you'd do better to proofread your post again and again until you manage to remove the little telltale signs that your native language is Russian. No informed reader of your post above is going to be convinced you don't have a significant dog in this fight.

You know, maybe some of us should complain to Slashdot about the Obama/Poroshenko-bots that reliably and consistently troll every single story about this conflict? You know, the ones who imply that anyone who even slightly skeptical about the propaganda we're all being fed, must be Russian or a paid Kremlin propagandist?

Suck on this. I'm a native English speaker from the UK, I have never been to Russia, I have been reading Slashdot for about 14-15 years, posting for most of that time too. And the Anonymous Coward tells it like it is. Poroshenko has claimed Ukraine was invaded like ten times already. He claimed he was being "invaded" by a fucking aid convoy, including after Putin's honesty about it's contents had been verified by international journalists and the Red Cross. In fact he asserted he'd shell said convoy, so the Red Cross chickened out, but the crazy Russians just drove right in there and delivered that aid anyway.

So as a native speaker, please heed my call - let's all stop abusing the English language shall we? We know what an invasion looks like. It looks like what the USA did to Iraq. It looks like Russian flags flying above Kiev and Russian tanks rolling down the streets to the parliament building. It does not look like journalists scrabbling around presenting the testimony of a milkmaid in a farcical attempt to find an army, as the Guardian did only a few days ago. Now condemn Putin for militarily supporting the rebels if you like (though the proof of this is wafer thin as well), just be aware that this is something many countries do, including the ones that are currently being most shrill about Ukraine. So such an argument doesn't have much impact, unfortunately, though I wish we lived in a world where it did.

Submission + - The Passenger Pigeon: A Century of Extinction 1

An anonymous reader writes: On September 1, 1914, Martha, the last passenger pigeon was found dead in her aviary at the Cincinnati Zoo. When the first European settlers arrived in North America at least one of every four birds on the continent was a passenger pigeon, making them the most numerous birds in North America, and perhaps in the world. From the article: "But extinction apparently doesn’t ring with the finality it used to. Researchers are working to 'de-extinct' the bird. They got their hands on some of the 1,500 or so known passenger pigeon specimens and are hoping to resurrect the species through some Jurassic Park-like genetic engineering. Instead of using frog DNA to fill out the missing parts of a dinosaur’s genetic code as in Michael Crichton’s story, the real-life 'bring-back-the-passenger pigeon' researchers are using the bird’s closest relative, the band-tailed pigeon.
Media

RAYA: Real-time Audio Engine Simulation In Quake 89

New submitter bziolko writes: RAYA is a realtime game audio engine that utilizes beamtracing to provide user with realistic audio auralization. All audio effects are computed based on the actual geometry of a given game level (video) as well as its acoustic properties (acoustic materials, air attenuation). The sound changes dynamically along with movement of the game character and sound sources, so the listener can feel as if they were right there — in the game.

Comment Re:OK Another one (Score 1) 89

Okay, but for example:
I am pretty overweight, but I'm in pretty good physical condition. I currently weigh 180 lbs. On this planet, I would weigh 315 lbs. That's like carrying 135 lbs of extra weight. If I'm backpacking, I carry anywhere from 25-35 lbs total, and I can "go" all day like that. I get pretty wiped out, but it's something I can adjust to, over time. I've hiked at 70 lbs, carrying equipment for other "less capable" people. That's really about my limit. This seriously cuts my hike range from about 15 miles in a day (max, really humping hard) to about 5-7. After a day like that, I'm fucking beat. And that is where I can take this pack off, and set up camp, cook, eat, sleep. I could pack 135 lbs, but I wouldn't get far, and I'd probably hurt myself trying.

When I train, I train with a pack that starts at about 10 lbs, and I ramp up over a few weeks to 40 lbs. And that is gradual enough, to avoid injuries, while building-up strength. And this increases my capacity and performance, but this takes weeks. (and as I get older, it gets much harder).

I see absolutely no way in hell I'm going to deal with an extra 135 lbs of weight, 24-hours a day. I'm not going to "build-skeletal tissue" or strengthen my body's structure. What will happen, physiologically, is I'll "survive" (minimally) maybe a day. My joints will get beat all to hell. I will be too sore to move for another few days of immobility. If I stayed on the surface, it's pretty likely I'd not recover.

I think that a "1.25 g" planet might be survivable for short periods. And this level MIGHT be enough for "physical toughness" to develop (over time), given a proper training/rest regimen, proper nutrition, and medical assistance with things like testosterone, HGH, and whatever other "black-magic" stuff that the pro athletes are taking.

I'd also tip my hat to probably the top-10% of the genetic bell-curve; those individuals who have rare, natural gifts of athletic ability, and while they are in their prime years of life, to MAYBE be able to adjust long-term to 1.5 g.

Comment Re:Slashdot got a sensational story wrong? (Score 1) 122

Slate's columnists not only demand that we accept the most apocalyptic interpretation of the data as gospel (scientists are not used to using terms like 'believe' and 'denier', but okay, the Maoists take taken over the issue)

Again, you're painting with a broad brush, and you seem to have no idea what the people you're talking about actually believe in. I'm a scientist, I don't vote, I'm a libertarian on most issues, and I'm pessimistic about our ability to actually do anything about global warming, but I still think the so-called skeptics are lying sacks of shit. Most scientists I know feel the same way, not because we're committed to some utopian vision of. . . cap-and-trade legislation? - but because we hate seeing paid shills distort the evidence and accuse our entire community of bad faith. It's the same reason that creationism drives us batty.

but that we automatically reject every proposed solution. We're all going to die, because that's the just fate Gaia intends for us as punishment for being fat and eating meat. We can't go nuclear to eliminate carbon! We can't bioengineer better crops!

Okay, time to back that up: when has Slate published screeds against a) meat-eating, b) nuclear power, c) bioengineering? I know for certain that they've run multiple articles in support of bioengineering, and I can remember at least one or two making fun of vegetarians. And it's not like you need to look very far to find a "left" outlet supporting your favored policies; the New Yorker just ran a very critical article about an anti-GMO activist that basically ended with the statement that only bioengineering would save the world.

What I would really like to see is a leftist site that reclaims the spirit of Roosevelt. If we have problems like climate change, energy shortage, war and poverty, let's attack them by building the giant public infrastructure projects that Steinbeck waxed so lyrical about. An energy independence Apollo would address all of these problems at once.

Liberals have been talking about this idea for years, usually by analogy to the Manhattan Project rather than Apollo. You don't see it getting wider reporting because everyone with a brain realizes that it has a snowball's chance in hell of getting through Congress.

Comment Re:Slashdot got a sensational story wrong? (Score 1) 122

yes, Slate's columnists seem to have sensed that the anti-vaxers have crossed a line in their Luddism

You're still grappling with a straw man. Slate writers have repeatedly denounced anti-vaxxers in fairly strong terms, and I have yet to see a single article taking the opposing view. More generally, they've been strongly anti-pseudoscience. You're assuming bad faith by making it sound like Slate has only grudgingly decide that there's a limit to their left-wing lunacy, rather than being firmly opposed to such nonsense on principle. If their "readership" really consisted of hardcore Luddites why would the editors consistently go out of their way to piss them off? Besides, you find find people saying stupid shit on virtually any Web forum - every Slashdot post about creationism inevitably attracts a slew of pissed-off religious fundamentalists, but I don't go around complaining that Slashdot's readership consists of superstitious morons.

Comment Re:Blah (Score 1) 171

No - this is exactly what happened with Television.

We had 3 broadcast channels which were ad-supported.

then we had the option to purchase around 20 channels.

Then, all of those channels which we PAID for with cable, became ad-infes.... ad-supported. And you had to pay EXTRA for more ad-free channels.
Then many of those extra channels also became ad-infested.

Then we got the internet, and the option to pay for ad-free TV. Then motherfucking HULU comes along, and rams ads down your throat for content you paid for.

They don't "get" it: people want a way to escape the fucking ads.

Slashdot Top Deals

"Gravitation cannot be held responsible for people falling in love." -- Albert Einstein

Working...