Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Comment The problem isn't the amount, it's the motive. (Score 1) 39

but specifically noted the difficulty of determining exactly how much companies, governments and individuals could lose if subject to an attack. “It’s very difficult to put a dollar figure on it,” Mr Fey said.

So... why put a dollar figure on it? If the number is 4 trillion or 90 billion, what would be the difference in strategies that consumers and organizations should pursue in each case? Fey's language is so obviously just more marketdroid conjuration babble -- "Look! look over here at my right hand! Nothing in it at all! ."

The fact is, Mr. Fey, that the danger of security flaws isn't in the direct dollar amount of damage done by any single incursion, nor in the aggregate sum total of attacks to date. The danger of unsecured machines/networks is cost-neutral, because an unsecured machine/network necessarily implies an infinite relative cost to you -- that is, it is the state of being unsecured which is untenable, not the potential monetary loss. If your neighbor one night digs a trench through your yard and buries an extension cord spliced into your house's electrical power, does it really matter to you whether he is only plugging in his mp3 player to charge it once a week, versus running all his refrigerators and washing machines?

You cannot really put any dollar amount on someone else controlling part or all of your machine/network, because Access is not an object, it is a potentiality. A security hole is a hole is a hole. Patch it up regardless. If on September 10, 2001 some insurance actuary named Smith would have calculated the "loss" experienced in an airplane hijacking by determining the depreciated cost of the plane itself, any cargo it carried, the cost of compensatory marketing to restore consumer confidence, the earning potential of the passengers, etc. The next day, a bunch of black hat social engineering crackers capitalized on a long-unpatched security hole - Access to the cockpit - to pull off an exploit which had an eventual cost far exceeding our actuary's previous estimate by several factors of ten. (And that cost will continue to reverberate/multiply for decades to come.)

The focus on dollar value is simply Mr. Fey's way of opening the haggling process over how much his company wants to charge you. He knows that whatever number "industry experts" give will be quoted and repeated by our infotainment media and by other businesses/consultants wanting to stake their own claim in the network security gold rush. Once the notion enters public consciousness, well what's a $25,000/year enterprise license for software and security services to an individual company when faced with the "common sense" understanding that we're talking about great googly moogly-illions of dollars in Crime. So now he's simply been caught overestimating the number, which is expected in ANY good haggle. Now he's here to tell us "Okay, okay, because you're such a good friend, I'm going to roll it down to $300 billion -- special just for you!"

Don't constantly test and patch flaws because of some dollar amount reported by some "expert study" you read about. Constantly test and patch flaws because a good administrator takes care of business. The number is FUD, but your job is the same either way.

Comment LOL. Okay, and.....? (Score 4, Insightful) 161

"...not only is Weev's conviction bad law, if upheld, it will destroy independent security research, and perhaps the rest of consumer safety research as well."

Yeah, I'm pretty sure that's the point. What in the world makes them think the government and the mega corps that they've merged with wouldn't want to "destroy independent security research" and "consumer safety research"? You think those federal-corporate cockroaches want you shining a light on their clandestine behind-the-fridge data gorging?

Comment Re:Why qwerty? (Score 1) 100

Using the input method of a bulky device (whose letters were ordered that way to not let you write too fast to avoid jamming of mechanical parts) with fixed letter positions for very high tech, digital small devices, with no mechanical parts that could jam could not be the best approach.

Maybe entry could be arranged like in compressing algorithms, having the most common letters and words right at your reach (few bits/touches) and you could navigate to more uncommon ones that fits in your input. Or handwritting recognition, but with extended "alphabet" (where you can have different gestures for i.e. common words). Or hardware keyboards with soft keys.

Yes please for the love of god can we kill QWERTY on small-form keyboards? Putting three vowels right next to each other is a major annoyance. bug/big/bog, suck/sick/sock, un/in/on, if/of ..... so many common words that can end up wrong by just a couple millimeters, in such a way that autocorrect will never catch them.

Comment Re:Doesn't have the gun lobby an interest in this? (Score 1) 175

We also go after weapons dealers who don't follow the law and facilitate crime as well. For instance, a gun store owner encouraging people to buy his guns to commit murder would be charged with all sorts of things if someone actually went out and did it.

If the gun store owner does his job properly, doesn't sell to people that he shouldn't, runs background checks and doesn't encourage people to commit crime, and if he sees crime in progress he alerts authorities or otherwise tries not to let it continue, then he's not going to have an issue if he's gun store sells a gun that kills someone.

Oh? We went after Eric Holder and his justice department employees who facilitated the sale of thousands of guns to murderers in Mexican drug cartels?

Good to know.

Comment I hope this NEVER comes to the USA! (Score 1) 105

And here's why -- just imagine if police were forced to provide this in the '80s. Kevin Mitnick could have used a Google search box to activate a script running on WOPR to launch a nuclear missile!

We wouldn't even be here on Slashdot now, just huddled in our underground shelters for decades waiting for the end of nuclear winter. Although now that I think about it, I haven't been out of mom's basement since World of Warcraft was released. So I guess no real difference there.

Comment Re:Coworker story time. (Score 1) 283

Coworker: I switch to root beer in the afternoon so I don't get all jittery on caffeine.
Me: Barq's has caffeine.
Coworker: That explains a lot.

I gave up caffeine for a year. I noticed that I really liked root beer during that year, drank a LOT of Barq's. One day I read the label, and I had the same reaction: "That explains a lot"

Thanks Slashdot. I've always thought all root beer was caffeine free. TMYK

I don't drink colas anyway except the once or twice a year when I'm somewhere with a soda fountain and I enjoy a refreshing mixture of root beer and lemonade.

Comment Re:Another reason we're stuck on this blue planet (Score 1) 505

Could you point out where the GP mentions flat earth theory? I'm not sure what your point is...

I think his point isn't necessarily flat earth, but the real reason people "feared the vast ocean just as much as we do space". They weren't at all afraid of water or being at sea -- during the time in question naval power was the dominant military power and every emergent imperial power did so through their navy. People didn't "fear" the vast ocean, they just didn't know other continents were out there, and so they quite rationally "feared" that if there was nothing but thousands of miles of water between Gibraltar and Canton, it would be extremely difficult to stock a ship sufficient to support all the crew over that long of a journey while still preserving room/mass for the cargo necessary to make the trip financially worthwhile.

So there's a significant difference here, in that we can actually see what's in space between us and our destination. And we don't see a damned thing that looks anything remotely equivalent to the luxuriously resource-rich American continents discovered by early European explorers like Columbus. When European ships pulled up to the New World they were encountering basic natural resources which have high utility for human beings with no special technology -- timber, fresh water, game, plant foods, arable land. And those two land masses are truly massive, stretching nearly from pole to pole across the surface of this planet. Space on the other hand, contains almost entirely, well, empty space. Hence the name, Space. Any matter/energy we do encounter is going to be in a form which will take significant technological infrastructure and on-the-spot engineering for us to have any use for it. We're not going to just accidentally stumble on a Kwik-e-mart with rechargeable batteries and slim jims between here and Proxima Centauri.

Therefore, the "fear" of the vast ocean in the 1400s is not at all equivalent to our "fear" of the hostility of dead empty space -- because we can directly verify that space does indeed consist of millions of light years of cold dead nothingness. There's no "there" there.

Comment Anyone have a Gmail account? (Score 2) 181

...and how is this different from Google reading all your mail discussions and targeting ads to you? You've already accepted that a corporation can listen to your conversations and build a profile of your likely purchasing habits. Does the difference in medium - from text to audio - really make that much difference?

Comment Re:Easiest way to shut them up (Score 1) 1163

Obama: "If your state seceded, you would no longer be a citizen of the United States and therefore the United States federal government would no longer be obligated to pay you Social Security or Medicare benefits when you retire. (And if you think the Confe-DUH-racy is going to be able to afford to do it, think again.)"

This just demonstrates that you live in a liberal filter bubble, because you think that threat is some kind of game-ending trump card. On the contrary, you'd have total bedlam as millions of people rushed to line up asking where to sign their names.

In the last 6-7 years I have witnessed is an increasing number of rank-and-file conservatives (especially under the age of 45) who have started saying, "Look, I know the system is going to implode and evaporate long before I get there. And even if it doesn't, I find the policy/economic side effects of the federal government filling this role to be inherently, inescapably hostile to a free society. Therefore, LET ME OUT NOW. I will gladly forego any benefits I would have received at retirement. You can even keep whatever I've paid in up to this point. Just LET ME OUT NOW to stand or fall on my own financial choices with whatever money I earn from the sweat of my labor."

Pragmatically, a very very large percentage of the younger conservative generation has ALREADY kissed their "benefits" goodbye because they believe the system is irredeemably corrupt and bankrupt. Your threat doesn't scare them any more than it would if you threatened a terminal stage 4 lymphoma patient with execution.

Comment Passenger promos show a guy playing drumsticks? (Score 1) 317

http://www.newairplane.com/welcome/

I'm looking forward to sitting next to the guy in Boeing's "Passenger Experience" video/stills wearing headphones with his drumsticks out. What, is he gonna be drumming on the armrests or something? Even if he's only playing "air drums" and not making noise, how totally obnoxious is that visual gonna be?

This old man
he played 4
he played knick-knack on the emergency exit door.
before the rest of the passengers beat the everloving crap out of him for bringing out drumsticks on a freaking plane ferchrissakes! Jeez!

Comment Re:Probably, but watch out for the Audit. (Score 1) 157

There's also nothing forcing you to show the same ticket to the TSA as to the people at the gate. Could have a fake one for the TSA and a real one for the plane to ensure it checks out with the airline.

I wonder if any top-level tracking system would notice if you booked a ticket on two separate airlines leaving from the same terminal around the same time. I don't know that doing so would be exploitable in any way, but now I'm curious toward just how broad the software-based aggregation/collation/analytics are.

Comment Re:This is what Benjamin Frankin warned us about.. (Score 4, Insightful) 1160

I agree with OP's principle but am still willing to make some special allowance for Germany. If any circumstance can be called justifying to say that some things shall not be discussed, it's probably theirs.

If any circumstances can be called justifying to say that some things shall not be discussed, then all censorship can be justified eventually; it's just a matter of organizing a sufficient majority of voters/protesters/terrorists.

Slashdot Top Deals

"If I do not want others to quote me, I do not speak." -- Phil Wayne

Working...