Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Submission + - Serious Network Function Vulnerability Found In Glibc 1

An anonymous reader writes: A very serious security problem has been found and patched in the GNU C Library (Glibc). A heap-based buffer overflow was found in __nss_hostname_digits_dots() function, which is used by the gethostbyname() and gethostbyname2() function calls. A remote attacker able to make an application call to either of these functions could use this flaw to execute arbitrary code with the permissions of the user running the program. The vulnerability is easy to trigger as gethostbyname() can be called remotely for applications that do any kind of DNS resolving within the code. Qualys, who discovered the vulnerability (nicknamed "Ghost") during a code audit, wrote a mailing list entry with more details, including in-depth analysis and exploit vectors.

Comment Re:jessh (Score 4, Informative) 397

This.

I grew up in the DC metro area. Snowstorms in New England are notoriously hard to predict, especially nor'easters like this one (which are typically a combination of 2-3 storm systems).

Sure, you can see it coming down from the Midwest, but it's always hard to tell exactly what's going to happen to a blizzard after it stumbles over the Appalachian Mountains, which will divert some of it and squeeze some or all of the moisture out of it. Then it collides with some storm full of rain coming in from the North Atlantic. Then the wildcard is some sort of warmer air coming up from the south... It all collides over New England. The computer models can tell you what's going into the mix, but who knows exactly where it's going to transition from rain to snow? WHICH STORM WILL WIN?! A butterfly in Miami decides.

Comment Re:So what will this accomplish? (Score 3, Informative) 154

In Econ 101 you also learn about horizontal and vertical pricing.

Basically, if the surge price is reasonably high, most drivers will be available. From 1.0 to 1.5 you may raise the number of drivers considerably, but from 3.0 to 3.5 you will probably not motivate many more drivers to go out and drive - most available drivers will already be on the road, and the few who decide against it will not change their mind here because if 3.0 doesn't motivate them, then 3.5 most likely won't because they have important reasons to stay home.

A cap on such elastic pricing is almost always a good idea.

Comment Re:Escaping only helps you until a war. (Score 1) 339

This exactly.

Why do rich people not live in Africa and Asia where the climate is good? Safety and convenience. If you don't want to spend your life in a castle defending your riches, you go somewhere where culture, society and government will do that job for you.

Strangely, many don't see this as a service worth paying for, which is largely a semantic problem. Maybe we should tackle it there, and instead of taxes, we should collect a "wealth-protection service fee".

Comment Re:"They" is us (Score 1) 339

From the very article you link to:

But Credit Suisse's report doesn't tell the whole story.

It doesn't take into account how much it costs to buy goods in each country, for example. Half a million pounds might buy a one-bedroom flat in central London, but in other countries it could buy a mansion.

It also doesn't take into account income. As a result, many well-paid young people in Western countries may fall into the bottom 50% of wealth - either because they still have student debt to pay off, or because they know how to live well, and spend all their income.

Comment never believe PR (Score 1) 339

I am extremely sceptical about all these doomsday scenario media reports.

If you do not know something for sure, "follow the money" is always good advise. For example, why would someone who makes his money on the stock market give free advise to the rest of the world by warning them about an imminent market collapse? It makes no sense. If I knew (or were sure about) such an event, I would put my money into short options and become mega-rich.

But, of course, if you expect the opposite, such a press statement can lead a critical mass of people to disinvest, temporarily lowering prices, convincing others that you are right and the crash has begun, so they do the same, and then you buy at the low point.

The same with all the "super-rich are investing in getaways" bullshit. It's a really great tool to convince the wannabe-super-rich (aka the simply rich) to follow (or believe they are following), because that's what they do. In all layers of society, people tend to emulate the next-higher-up from their own status, because that is where they want to be.

Maybe I'm overly cynical or just blind, but thinking about not only what is being said, but also who is saying it and why seems to me to be a good idea.

Comment Re:Lack Of Faith (Score 1) 90

Could be, as I rent and don't buy, I don't drive cars older than a few years.

I know the Toyotas and Hondas are famous for their reliability. My first car was a used Honda and it had almost no signs of being used before.

That said, old Mercedes cars are also legendarily reliable. My GF wants to buy a used SLK for exactly that reason - they are cute and almost as good as new, for a fraction the price.

Comment Re:A call for Write Protect (Score 1) 95

For those old enough to remember them, changing a BIOS required an EPROM burner and UV eraser. Changing CMOS settings required setting the write protect jumper.

Well, I had an IBM PC-1, and yes and no respectively.

Clearing CMOS settings is still done with a jumper. I do wish that all flash BIOS devices had a write protect jumper, though, and it would cost little to add them.

Comment Re:Saddest line ever (Score 3, Funny) 141

You are *so* cool! I bet you have a neckbeard too!

I sure do, but any time I go visit a new contract or even just go on vacation, I shave it. It's not an attachment or an affectation, I just don't measure my value by the cleanliness of my neck. It's not my fault I was born hairier than the average bear.

But hey, thanks for recognizing how great I am. I could use the publicity.

Comment Re:There should be a law (Score 1) 181

The emblems would be sooooo small because there are so many you wouldn't be able to read them :-)

Only the top ten or so even get space.

Here's another way to handle it. Whenever they appear on television, block out x% of their face and words based on their campaign contributions. Whoever gets least comes through at 100%, whoever gets most is just a wall of ads, and everyone else falls somewhere in-between

Comment Re:everybody getting lost in technical details (Score 1) 468

And not seeing the obvious. This is a move to close down the 2nd hand market.

No, no it isn't. Just having non-transferable activation codes was that. This is a stupid and ham-handed attempt both to fight actual crimes and to dissuade people from seeking bargains.

It is so obvious, a 5 year old could get it.

Next time, consult a five year old.

Comment Re:First Sale (Score 1) 468

You buy a license to use a game. They revoke the license, which is their right, but by doing so, you are no longer bound by the license terms either, which includes the payment you made.

Well, no. The license is something you enter into after you make the payment, hence the assertion that shrinkwrap licenses should not have any weight: you're not getting anything for them, you already got it. This online activation bullshit is a way around that: You're getting online activation.

Slashdot Top Deals

The flush toilet is the basis of Western civilization. -- Alan Coult

Working...