Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Privacy

Submission + - Security hole found in price-comparison sites (pcpro.co.uk)

Barence writes: A PC Pro investigation has revealed a gaping security hole in leading price-comparison websites. Following a reader tip-off, PC Pro visited Comparethemarket.com and clicked on the retrieve a quote button. In order to gain full access to the entire quote history of an account holder all that was required was their email address, surname and date of birth — details that could be easily harvested from social-networking sites such as Facebook. This was enough to unlock a veritable treasure chest of further valuable data including telephone numbers, car registration and make details, occupation, personal details of spouse as well as property details where house insurance quotes were available. Confused.com was little better: all that was needed to change the account password and get instant access to the quote-history data was an email address, date of birth, postcode and surname. The account holder would be none the wiser — no email is sent to even confirm the password had been changed. PC Pro informed both sites of the flaws a week ago — both have failed to react.

Comment Re:Missing option (Score 2, Insightful) 534

On my spaceship, I'd like artificial gravity

To exist

Seriously, "artificial gravity" is a bigger hand-wave than "Heinsenberg compensators".

Artifical gravity is very easy to create using the centripetal force. Just make it a round shape that rotates at the right velocity to make the centripetal force of the ship equal to whatever level of gravity you'd like.

Comment Re:No reason to (Score 1) 277

Hold on... What does this mean:

thinking that the monitor cable from a CRT can go to an LCD

My monitors (LCD and CRT) both have a standard, interchangeable power cable (three-prong, no power brick) and SVGA video cable. I could switch out either one (or both) between monitors no problem. Are yours different?

Not trolling--I'm honestly curious

For most monitors the circuitry for the actual ac to dc conversion is within the monitor itself that's why it appears as though they use the same cable. However some of the smaller monitors do have a separate power brick, so that that the power adapter is separate from the monitor itself.

Privacy

Submission + - Germany seeks expansion of computer spying (latimes.com)

volt4ire writes: Germany used to seem like a very progressive nation in terms of technology policy, like having good privacy standards and lacking draconian anti-hacking laws. This was thanks in part to groups such as the Chaos Computer Club .Sadly, it seems that the government's policies have gone down-hill, with the passing of antihacking laws . Even with the recent Berlin protest against the nations' increasingly Orwelian policies, the government has remained on this unfortunate path.
Programming

Submission + - Establishing user identity on free sites.

RPalkovic writes: "I'm in a bit of a predicament. I am an administrator of a smallish online game with free registration. We're running into a problem where users are violating the terms of service by creating and using multiple accounts, but since we do not collect any personal information, nor would we have a way to verify it if we did, we're running into problems enforcing the "one account per user" section of the terms of service.

We've tried tracking IP addresses and letting people know that if they are caught sharing in game transactions with anyone they've shared an IP address with will result in termination of their account. We've also given them a list of anyone who've they've shared an IP address with.

The problem with this method is that several of our players play in internet cafes, or at school, and we've even run into people who live in different countries who end up sharing an IP address because they use the same proxy server.

We tossed around the idea of changing the terms of service to limit players to one account per computer, but that would impact single computer households and would require the installation of an ActiveX control (or similar) to gather an NIC's mac address or somehow generate a unique hash based on the hardware configuration.

We also tossed around the idea of only allowing registration via Major ISP's or pay for e-mail providers, but that hampers those that ONLY play at an internet cafe or school network, as they may not have a non-free e-mail address.

Our main goal is to keep the site free, with a secondary goal of preventing any single user from having more than one account.

Have any other SlashDotters found a creative way to prevent users from having more than one account to an online service without charging a fee for registration, or being forced to verify user identity?"

Slashdot Top Deals

One way to make your old car run better is to look up the price of a new model.

Working...