Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×

Comment Very rarely, alas. (Score 5, Informative) 601

I use GPG/OpenPGP for some mail and "secure" web mail for other applications. I do not use third party web mail (such as gmail) because I can't control the dissemination or privacy (or longevity) of my mail and while my life is generally boring enough to fit within Eric Schmidt's idea of privacy ("If you have something that you don't want anyone [someone] to know, maybe you shouldn't be doing it in the first place [at least not though a google property]."), I occasionally write a personal opinion of someone I wouldn't want them to be able to Google later or share a business detail that could be economically damaging or embarrassing (or is subject to NDA) and gMail and all other web mail services are effectively public.

I've used PGP (and eventually GPG) since about '94 and my keyring has about 20 people on it: more than 1 new key a year! Alas, 25% of those keys expired in the late 90s. My address book has about 1500 entries. Why so few keys? As the OP pointed out, it isn't all that difficult.

The answer for me is that the model for encouraging encryption has to be more like S-WAN than GPG-like. I'd love to turn on "encrypt everything" and forget it, but I'd get an error message for 99% of my correspondents, so obviously that isn't going to happen. So I set my prefs to reply to encrypted messages with encryption, which is fine, but it means I rarely (almost never) initiate an encrypted thread.

What I'd like is an opportunistic encryption mode where any message to an address in my keyring is encrypted by default. Any message to anyone I don't have a key for gets a nice little .sig file with a brief notice that their mail is insecure and effectively public and a link to further instructions for getting GPG set up.

One annoying problem is that encrypted mail is not searchable. To solve that, I want my client to extract a keyword list on decryption then upload that keyword list to (my own) server as an unencrypted header to enable searching (implemented, of course, with a stop list for words you wouldn't want to appear in the clear even out of context or perhaps particularly out of context).

For the truly paranoid, this list could be a hash list, though you could still fairly effectively dictionary hash fish, but it would provide some security and reduce the easy availability of information. In fact, all headers could be hashed and still generally be searchable (except maybe date ranges).

I also want my server to store my public key and encrypt all incoming mail with it. Of course it is already transported in the clear, but it makes my server less vulnerable. Once the mail has had an index extracted and the body encrypted, someone cracking into my IMAP server would, at least, not find a historical trove of clear-text data. And my friends without keys would get annoying sig files evangelizing encryption.

Comment It is common sense, not the patriot act. (Score 5, Informative) 203

If you put your data in the cloud, you put it in the hands of not just the US government, but every government the cloud company does business with. And also in the hands of every underpaid employee in the company; and while some companies may claim otherwise, their claims are unverifiable and unenforceable. "Cloud" services have their place - it is for data that is intrinsically public and ephemeral. Nobody should ever trust any cloud service with data that is proprietary or private or irreplaceable.

Most obviously, the "free" services are predicated on exploiting the value of their users as product to customers that are not the users. The model makes sense in some cases, for example a forum, where the shared public content is willing coproduced by users of the forum, exchanging their content creation efforts for use of the forum itself, the forum exploiting that content to attract eyeballs to advertisers that pay the bills.

While there are strong logical reasons why cloud services are intrinsically untrustable (ultimately, he who owns the hardware, owns the data), a simple thought experiment proves the folly: how hard is it to bribe an employee of a cloud service to give you inappropriate access to someone's data? Do you think you couldn't find one employee in one company somewhere? While one may be able to find companies that are currently resistant to easy attacks, cloud companies come and go like the .coms that they are are, and with inevitable waning economic optimism, so too wanes employee loyalty. In the eventual asset transactions that follow, acquiring companies of even trusted entities are unknowns and customers have no recourse and no authority.

At best, the loss of yet another fleeting cloud service means only the loss of the associated data and whatever codependent business line the cloud service customer bet on the serial risk of the success of the cloud company itself.

The premise of handing your proprietary data to another person for remote, invisible processing and care is fundamentally flawed. Your interests are not aligned and their interests will evolve and ultimately diverge or fail.

Foreign companies (and US as well) are well advised to be wary of cloud services.

Comment Tom Bihn Brainbag (Score 1) 282

I carry a Tom Bihn Brainbag with their sleeves in it for laptops since 2007. I carried two laptops with it (T60+Dell M40) for a long time, now a W500+Sony NX5+acc and a crap load of other goodies. It has been on about 500 (?) maybe 600 flights with me, well over 1,000,000 air miles, was strapped to a pallet in a CJ in Afghanistan (and offloaded at the wrong fob where it spent the night and finally got back to me awfully dusty), bounced around Iraq, and accompanied me to to other difficult, sometimes less than gracious environments without any failures. The zippers are tight and with an occasional NikWax have kept the contents dust-free and dry.

My only complaint is that the Freudian Slip doesn't organize enough stuff - I wanted to make a rigid MOLLE style insert for the front pocket to strap sacks of cables and crap to and keep organized, and still keep an eye out for semi-rigid containers for delicate things, but so far nothing has been smashed inside, the straps and zippers work like new, no real fraying. The waist strap on mine has been a vestigial annoyance, but newer models have removable ones.

The only system failures are that the sternum straps disappeared one by one, but my GF has a later edition of the same bag and gave me hers since they interfere with her anatomy and the updated ones work better, no problems since. She's had hers for almost as long and almost as many miles and pretty much the same difficult travel schedule with no problems at all.

If it ever fails, I'll get another. It would be really cool if they had a ballistic spectra option and it would be very cool if there was an easy option to lock the zippers.

Comment Re:Not fear - disgust (Score 1) 1017

Nobody would ever, ever put an explosive device or weapon on a child if we decided that children were too precious to scan.

http://www.asianewsnet.net/home/news.php?id=19669

http://articles.cnn.com/2010-06-15/opinion/obaid.suicide.children_1_suicide-bombers-pakistan-northwest-frontier-province?_s=PM:OPINION

http://www.washingtontimes.com/news/2009/jul/2/taliban-buying-children-to-serve-as-suicide-bomber/

http://www.youtube.com/watch?v=_lwaypeucTk

So there could not possibly be a problem with systematically allowing a certain class of people through security unscanned.

Image

Florida Man Sues WikiLeaks For Scaring Him Screenshot-sm 340

Stoobalou writes "WikiLeaks founder Julian Assange has been accused of 'treason' by a Florida man seeking damages for distress caused by the site's revelations about the US government. From the article: 'David Pitchford, a Florida trailer park resident, names Assange and WikiLeaks as defendants in a personal injury suit filed with the Florida Southern District Court in Miami. In the complaint filed on 6th January, Pitchford alleges that Assange's negligence has caused "hypertension," "depression" and "living in fear of being stricken by another heart attack and/or stroke" as a result of living "in fear of being on the brink of another nuclear [sic] WAR."' Just for good measure, it also alleges that Assange and WikiLeaks are guilty of 'terorism [sic], espionage and treason.'"
Government

White House Holding Piracy Summit 268

DesScorp writes in to let us know about a White House piracy summit, which is going on this afternoon. Judging by the press accounts, the sort of intellectual property criminals they are interested in are large-scale DVD bootleggers, not individual downloaders. "Hollywood once again demonstrates its close ties to Washington DC, regardless of who is in power, with a White House summit on piracy to be attended by the top executives in Hollywood, as well as the music industry. Vice President Joe Biden will be leading the summit to discuss organized cooperation between the federal government and the entertainment industry on all matters of piracy. Also at the summit will be the Obama Administration's new Copyright Czar, Victoria Espinal. The summit comes after Congress has earmarked $30 million dollars of taxpayer funds for anti-piracy efforts." According to one attendee's tweet, the press was kicked out of the meeting around 20:45 GMT.
Science

Aussie Scientists Find Coconut-Carrying Octopus 205

An anonymous reader writes with this excerpt from an AP report: "Australian scientists have discovered an octopus in Indonesia that collects coconut shells for shelter — unusually sophisticated behavior that the researchers believe is the first evidence of tool use in an invertebrate animal. The scientists filmed the veined octopus, Amphioctopus marginatus, selecting halved coconut shells from the sea floor, emptying them out, carrying them under their bodies up to 65 feet (20 meters), and assembling two shells together to make a spherical hiding spot. ... 'I was gobsmacked,' said Finn, a research biologist at the museum who specializes in cephalopods. 'I mean, I've seen a lot of octopuses hiding in shells, but I've never seen one that grabs it up and jogs across the sea floor. I was trying hard not to laugh.'"
Biotech

Novel Algae Fuel-Farming Method Gets Big Backing 176

Al writes "Dow Chemical has given its backing to a Florida startup called Algenol Biofuels that hopes to produce commercial quantities of ethanol directly from algae without the need for fresh water or agricultural lands. Dozens of companies are trying to produce biofuels from algae, mostly by growing and harvesting the microorganisms to extract their oil. Algenol has chosen instead to genetically enhance certain strains of blue-green algae, also known as cyanobacteria, to convert as much carbon dioxide as possible into ethanol using a process that doesn't require harvesting to collect the fuel. Algenol's bioreactors are troughs covered by a dome of semitransparent film and filled with salt water that has been pumped in straight from the ocean. The photosynthetic algae growing inside are exposed to sunlight and fed a stream of carbon dioxide from Dow's chemical production units. The goal is to produce 100,000 gallons of ethanol annually."
Space

No Space Porn (For Now) 260

With the entry to sub-orbital flight, and even orbital flight, becoming ever so slightly easier, the obvious thought of space porn kicks in. Who wouldn't want to see two or more people going at it like rabbits in a weightless environment (or at least trying to go at it like rabbits in a weightless environment)? Sadly, Virgin Galactic has turned down a $1 million offer to do just that. The offer was made by an unidentified party who was willing to put the money up front to do a space porn movie. Considering that a flight aboard VG costs $200,000 for a two-hour flight, $1 million doesn't seem too bad. Though how much you could actually do and perform in two hours is debatable. And what if one or more of the actors gets sick?
Software

Stallman Says Cloud Computing Is a Trap 621

stevedcc writes in to tell us about an interview with RMS in The Guardian, in which he gives his views on cloud computing, with a particular focus on user access to data and the sacrifices made for convenience. "'It's stupidity. It's worse than stupidity: it's a marketing hype campaign,' he told The Guardian. 'Somebody is saying this is inevitable — and whenever you hear somebody saying that, it's very likely to be a set of businesses campaigning to make it true.'" Computerworld has a summary of some of the blogosphere's reaction to RMS's position.

Comment Retarding progress of science and art again (Score 4, Interesting) 316

This is just yet another example of how the current copyright regime is prima facia unconstitutional.

To promote the progress of science and useful arts, by securing for limited times to authors and inventors the exclusive right to their respective writings and discoveries

Copyright is not a property right; copyright is an agreement between the public and authors & inventors creating a privilege of limited exclusive right as incentive for dissemination of ideas because otherwise authors & inventors have only the choice of keeping their inventions secret or sharing them that the recipient does what he or she will with the information without limitation, which is the natural right of the recipient.

Any mechanism of securing exclusive right to the author or inventor must meet two tests to be constitutional:

  • the term of the exclusive right must be limited (that is it is not a property right),
  • the mechanism must demonstrably promote the progress of science and the useful arts.

An attempt was made to test the absurdly long exclusive term against the "limited" requirement and that failed because any finite term is by definition limited.

The test that must now be made is against the requirement that copyright laws "promote the progress of science and the useful arts." The burden of proof should be on demonstrating that the laws do promote the progress of science and the useful arts because copyright is a limitation on the rights of the public and therefore intrinsically a burden on society. In granting copyright society temporarily yields their natural right to a privilege offered authors & inventors, a privilege that may be revoked at any time.

Current copyright laws do not pass the test of promoting the progress of science and the useful arts; they are a burden on innovation and have systematically retarded the progress of science and technology, strangling many significant innovations, once again with internet radio. Current copyright laws are therefore unconstitutional.

Slashdot Top Deals

Ya'll hear about the geometer who went to the beach to catch some rays and became a tangent ?

Working...