Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×

Comment Re:of course they are (Score 1) 127

No. The best Lenovo could do is not collecting money and let new users get infected hardware.
The best Lenovo could do is commit to their customers, and get the PCs cleaned before they are sold.
But this kind of thinking is not really in the direction of typical chinese manufacturers, who simply ship the darn thing, whatever the defects. Japanese manufacturers are more commited to their users, when they admit the fault ( which does not always happen)

Comment Re:Not a big deal (Score 1) 127

>> No point to the story

Yes, there is a point. If Lenovo was concerned with the security of their customers, they would arrange with their distributors to either remove the malware or recall the hardware.
Continuing to sell it with malware shows they don't care about their customers.
And yes it costs money. That's the cost of deliberately distributing malware.

Comment Re:Hiding it and always was a bad idea (Score 1) 564

>> Then things got a lot more complicated. We started building verification code into the first bytes of the data and added icon to tell humans what it was.

This fails. OS still largely use extensions for identification.
Identification and verification are both broken because there is no standard file header for that.
Extensions still give an easy method. Not reliable (coz users/spoofers mess with it), but easy to use and cross platform and cross format.

The big advantage of using extensions is that it is backwards compatible. Header identification would require rewriting every single file format, as well as all software using it. That will not happen.

see some examples of identification/verification abuse :

http://media.ccc.de/browse/con...

Slashdot Top Deals

"Engineering without management is art." -- Jeff Johnson

Working...