Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×

Comment Re:If it's accessing your X server, it's elevated (Score 1) 375

What exactly would you propose to add? This isn't a matter of implementing new functionality, but rather removing fundamental misfeatures. Any change to address this issue is going to end up breaking existing applications which depend on the original input behavior.

Oh how about a new protocol extension that allows one designated program to receive all keyboard inputs regardless of any other grabs. The X11 server can keep on pretending that the other grabbers still have such a grab.

Look: X11 works on Windows even though windows can apparently REALLY gab the keyboard. X11 will we are told work on Wayland too despite the fact that wayland can apparently REALLY grab they keyboard. Do you really think it couldn't be extended to do that itself?

Comment Re:First they came for... (Score 0) 228

what have you "won" exactly?

You "win" Turkish citizens annoyed with their government -- a win in the only venue likely to be able to create change there.

i stopped reading there

how did that work with cuba? iran? north korea? china?

what you're asking for is massacred citizens

iran for example

http://en.wikipedia.org/wiki/2...

no matter how many intelligent, forward thinking students you have agitating in the cities, the government just calls up busloads of basiji thugs from the countryside and cracks skulls until change seekers shut up in fear. or worse:

http://en.wikipedia.org/wiki/D...

slow stead engagement is what really works

reactionary inflexibility simply means no change at all

welcome to reality

this is you:

http://www.politico.com/story/...

pragmatism, flexibility, realism, compromise always wins

inflexible ideological dogmatism is how you lose and are ignored

Comment Re:Eisenhower said it (Score 2) 214

well yeah, by definition a rock star is very rare

so if you want a rockstar working for you, you better be ready to shell out big money or provide truly extraordinary perks

you can't just expect or demand rock star status from average or even above average programmers. you can't mold people's personalities like their technical proficiency. i suppose there does exist stress mitigating strategies someone can consciously adapt. but from the rock star i met, it is a sort of chilly immunity to even the concept of stress that is quite awesome to behold

that's why i quoted eisenhower

because when i met such a person, i immediately thought of someone functioning under the stresses of extreme combat. i thought of this person on the eastern front in wwii. what it would take to survive *real* stress, because stress in programming, while real, taken in perspective to something like fields of combat, is a joke

i always wondered if this person had indeed been in such an extreme stressful environment, like war. a sort of "once i've seen that, none of this shit impresses me." because indeed, nothing seemed to impress him. you could scream in his face and he would react the same as if you were casually discussing gardening. nothing phased the dude

Comment Re:Eisenhower said it (Score 1) 214

I haven't met or heard of anybody who is a "rock star" by your criterion. The closest I met was a person of very resilient personality, capable of working hard and steady through great stress, and who had an average level of talent. Not a bad person to have as part of a team, but in no way a rock star.

i have met a person with that stress proof personality, and above average talent. they exist. those are the rockstars

Comment Re:First they came for... (Score 0) 228

ok, let's say you prevail. zuckerberg gives turkey the middle finger and doesn't censor images

ok, now facebook is kicked out turkey

what have you "won" exactly?

how has turkey changed in any way? you've given the authoritarians a win: they've successfully excised the evil western cancer of facebook from glorious turkey

and how will turkey change in the future?

so you're for not opening diplomatic relations with cuba? we should just never ever ever reconcile or talk with cuba? how has that strategy paid off to change cuba?

we don't talk to iran? what is iran's attitude going to be then?

you are a dogmatic rigid ideologue

you are exactly the same as what you don't like in turkey

and the fruits of your ignorant stubbornness is you HELP the people you don't like

pragmatism always wins

Comment Re:physical access (Score 1) 375

Which could be a good argument for replacing X. It is rather old technology, perhaps it is time to update it to something newer, rather than clinging to it and claiming it is all one needs.

Or how about adding a protocol extension to deal with this security problem as has been done a number of times in the past for authentication. I don't understand why X11 seems to get special treatment here.

Program has security flaw. Response "has it been patched yet"

X11 has security flaw: we can't possibly patch it we must discard everything and start again.

There's certainly some things wrong with X11, but this is one which could be solved easily. It could, for example, be done by having a "kill all grabs" command which is available to the window manager.

Comment Uh. (Score 1) 375

Uh.

Why can't I have my screen locker have a passive grab on Ctrl+Alt+Delete or shift+altgr+control+` or whatever, using XGrabKey. That way if someone else installs a screenlock faker then I'll know because it won't respond to the magic key presses.

The thing is on Windows it never worked as well as it ought to. The reason is that if the screen said something like:

"pls entar u r passwordz to login"
[ password box ]
[OK]

"pls wate wile redirecting to http://scamsite.ru/yourbank"

"Pls entar u r bank passwrd thx"

an appalingly large number of people would have dilligently followed those steps. the ctrl+alt+delete thing was fine but required more knowledge than 99.9% of users had.

Oh and the active grab thing: if you ever hear a wayland dev tout that as a problem, please kick them in the nuts because it XFree86 USED to have a feature for killing grabs from a keystroke, until the fuckers who went on to develop Wayland decided we didn't really need it because "it would only be needed if a program is buggy". Well, no fucking shit hotshot.

Comment Re:Screen locker == physical access == ... (Score 1) 375

Why is this considered acceptable? Get physical access to my iPhone (for example - Android is probably the same?), good luck getting in.

Huh? This exploit only works if someone has already had access to your unlocked computer long enough to load and run malicious code. It's not like oyu can plonk down someone at a computer wit ha locked screen and have them hack in by being clever.

And if I had access to your unlocked iPhone, could I not root it or whatever the iPhone cracking is called and install a fake screenlocker too? Or hell, install a custom keyboard app which looks like the normal one but saves all passwords and sends them to the cloud. I might not even need to root it to do that.

Comment Re:not the point (Score 1) 375

Well, yes.

However, that only works if the attacker already has arbitrary local code execution. If they can do that then they can trojan every single program, by diddling with the PATH environment variable and/or pissing with LD_PRELOAD.

Basically yes, it's a hole but one that only kicks in if you're fucked 6 ways to Sunday already.

Or if you've done xhost+ and disabled your firewall. But that hasn't been the default in years.

Comment how did things go before communication over wires? (Score 1) 431

people met on the street and in taverns and in private rooms, completely beyond the ability of anyone to eavesdrop

but enforcement against illegal activity proceeded by infiltrating groups and other methods

it seems the feds are complaining they might have to actually engage in hard work

do your damn job

Comment Re:First they came for... (Score 2) 228

if the positive influence outweighs the negative

the absence of facebook won't make those problems go away. how do you make those problems go away? with influence. like facebook. a bastardized influence, in order to exist, is still an influence, and better than no influence at all

this is called realism

it trumps ineffectual dogmatic idealism, which is just as authoritarian and extreme as what you are complaining about

compromise always wins

if you want to lose, hold fast to extreme adherence to difficult demands and never budge. there's no better way to make yourself marginalized, ineffectual, and ignored

Slashdot Top Deals

You knew the job was dangerous when you took it, Fred. -- Superchicken

Working...