Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×

Comment Re:His viewpoint is staggeringly ignorant (Score 1) 618

I think adblockers are great - for the end user to own and maintain. I've been running filtering proxies of one type or another since the last millennium. (And nothing will teach you the nuances of regex like the challenge of stripping out unwanted HTML tags.) It's for me to decide what I want my browser to display.

But just as it's wrong for my ISP to inject their own ads, it's also not the place of my ISP to censor them out of my data stream. That's my decision, not theirs.

Comment Re:How can this be? (Score 1) 190

Good point. I would not assume that flight information is from the nav and control systems. But it could be, in which case they could use one-way data isolation devices to eliminate the possibility of anything on the entertainment system negatively impacting navigation controls. That would technically be a "tie", but not one that could be exploited.

Yes, they *could* have used some kind of special 'data diode' isolation device, but then the researcher probably wouldn't have been able to jump networks in the lab, or, as stated in TFA, "He told WIRED that he did access in-flight networks about 15 times during various flights but had not done anything beyond explore the networks and observe data traffic crossing them".

Car networks (CAN bus) have a similar weakness in that the infotainment systems have previously been breached, allowing attackers access to cross over to security systems and unlocking the doors.

Comment Re:How can this be? (Score 2) 190

There's no way that entertainment/wifi/anything-accessible-to-a-passenger could in anyway be connected to those critical systems...is there?

There should be no tie between the control and entertainment networks. I would be surprised if there aren't regulations that forbid it. My guess is this simulated system was not like the real ones. It certainly isn't clear what really was done.

If there is no tie between the entertainment and nav systems, then it becomes difficult to explain the seatback display of the current flight information. At some point the data has to move from one system to the other. That takes a lot more than "no tie".

Comment A large load of sheets from BB&B (Score 1) 150

NASA's current plan it to cover a sufficient amount of the object with a different colored cloth (white or black as the case may be) and let the solar sail effect do the work. So a 30% off coupon to Bed Bath & Beyond would do the trick; even with the discount the manager and staff should get a nice bonus for selling 250,000 white sheets in one day.

sPh

Comment Re: 23 down, 77 to go (Score 3, Informative) 866

I'm fairly certain humanity would find plenty of reasons to wage war if religions were not around to blame it on.

Religions were created as the first rudimentary forms of government or control over other people, and are still remarkably effective at that task. They only require an ongoing group of leaders to ensure obligations are continually felt by the members, as it's difficult to create a new religion quickly with a large enough number of committed adherents to wage an effective war.

The entire process is well understood and practiced worldwide.

Submission + - Smart Grid Meter Homegrown Security Protocol Crushed By Researchers

plover writes: According to this article in ThreatPost,

Two researchers, Phillip Jovanovic of the University of Passau in Germany and Samuel Neves of the University of Coimbra in Portugal, published a paper exposing encryption weaknesses in the protocol.

The paper, “Dumb Crypto in Smart Grids: Practical Cryptanalysis of the Open Smart Grid Protocol” explains how the authenticated encryption scheme used in the OSGP is open to numerous attacks—the paper posits a handful—that can be pulled off with minimal computational effort. Specifically under fire is a homegrown message authentication code called OMA Digest.

Comment Re:Awesome (Score 1) 39

That's really great news for Liberia. Thanks are due to all of the brave Liberians who worked tirelessly to control and treat this outbreak.

Yeah...but I"m curious...

Why did Roger Daltrey and Pete Townshend break this news......?

Because Keith Moon is dead.

Comment Re:The best thing Keurig can do is die (Score 1) 369

Arthur Anderson was primarily an accounting and auditing firm. The entire reason that firm existed was to be trustworthy. If people can't trust the auditors, they blame it on instructions coming down from the top that said "anything for a buck comes before an accurate audit." So there was no way to trust the rest of the firm wasn't uninfected with the same corruption that led to Enron.

At Green Mountain, the decision to put DRM into coffee came from the top. While it doesn't translate the same way to the line workers, the trust in the company was similarly lost by their clients.

And yes, people might lose their retirement savings. Employees often have a lot invested in company stock. And if Green Mountain has a pension plan, those employees are at risk as well.

What would be ironic is if Green Mountain collapsed, but other players in the marketplace continued to thrive while using the K-cup (1.0, of course) as a de facto standard.

Submission + - How Silicon Valley got that way -- and why it will continue to rule. (medium.com)

An anonymous reader writes: Lots of places want to be "the next Silicon Valley." But the Valley's top historian looks back (even talks to Steve Jobs about his respect for the past!) to explain why SV is unique. While there are threats to continued dominance, she thinks its just too hard for another region to challenge SV's supremacy.

Comment Re:Very unlikely to be triggered in the field (Score 1) 250

The entire world isn't the US/Japan/EU. While most airlines outside that region who operate 787s run tight operations (Ethiopian for example is often mentioned as very well-run with a strong safety culture), there are a few who do not.

That said, in the few instances where less organized airlines have managed to acquired 787s they are probably being shut down 2-3 times/week much less every 9 months.

sPh

Comment Re:Least common denominator (Score 1) 161

Connectivity is huge, but it's only one of the ingredients in making this decision.

If you want the app to work for them outside of the corporate WiFi, you have to host it on the public internet, where all attackers are equally welcome without regard to skillz or skripts. Are you sure that server is secure? What about tomorrow? Are you patching it? Are your users securing their devices properly? Uh oh, it's the new version of Heartbleed, go back three spaces.

You also have to consider performance. Is this something that your users will use constantly for their jobs, or occasionally for some rare piece of info? If it's going to add one second to every screen, and you're asking people to tap their way through 600 screens a day, the inefficiency is going to cost you 10 minutes worth of payroll per user per day. Maybe you make that up in hardware costs if you force your users to bring their own smartphone to work. Maybe the sluggishness just makes your users miserable throughout the day. Or maybe it simply costs you a lot of money.

On the other side, if it's used perhaps once or twice a day by 2000 people, poor performance and connectivity issues won't be nearly as important as savings on developer costs and time to market, Or if you have only a half dozen heavy users, perhaps you're willing to eat the payroll cost of an hour per day instead of spending them on development.

It's a question best answered by the money.

Slashdot Top Deals

"Engineering without management is art." -- Jeff Johnson

Working...