Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×

Comment $1b corps (Score 2) 268

They all need to be contributing to OpenSSL or a fork.

In a typical year the OpenSSL project receives about US$2000 in donations.

This week we have received roughly 200 donations totaling nearly
US$3000. Amounts have ranged between $0.02 and $300, and I notice that
some individuals have made multiple contributions.

https://groups.google.com/foru...

Security theater is sometimes more like security exhaustion.

Comment Re:Whatever you may think ... (Score 1) 447

Clearly $billion corporations like RedHat are going to spend more time auditing code commits, with or without lawsuits. Google found this bug and I wonder what kind of fork / NSS migration / whatever solution will emerge. NSS is from Mozilla, and Google revenue funds Mozilla.

Maybe it will go as far as "OpenSSL considered harmful" and anything linked to it will be flagged. That would be too sensible.

Comment Re:What I want to know is... (Score 1) 239

Here's a sad post from one year ago:

Is it possible to ensure by a configuration parameter, that curl uses OpenSSL, and not NSS to retrieve https content? I need to ensure this, in order to enforce compliance with FIPS140-2, which RHEL6.2 has certified?

http://stackoverflow.com/quest...

By the way I know NSS does a lot of FIPS compliance, but part of the Heartbleed problem for the "normal" user is that it is hard to tell what openssl is linked into. We had it in our web server daemon even though shell "openssl version" showed a good version.

Comment Re:BASIC is where M$ got its start (Score 1) 146

And if you haven't seen ASCII-art porn images come clacking out of a teletype with a phone-cradle modem to a time-sharing computer, then you weren't there (thankfully perhaps). http://en.wikipedia.org/wiki/T...

Briefly I had to deal with compiled programs on decks of IBM cards. BASIC was much nicer for a student doing small programs because it was interpreted and you could fix it as you went along (in memory). Those card decks looked cool on Hawaii Five-0, but one syntax mistake in a cobol or fortran program and you had to wait another two hours to get your homework done.

Comment Amazon mysteries (Score 3, Interesting) 88

Amazon's primary interest in this device *seems* to be to drive sales on Amazon Instant, not to serve as a general purpose streamer like Roku (though it does that too). There's some confusion in the business press about what Amazon is up to, but this is a likely guess. It doesn't want to be reliant on Roku, ChromeCast, Sony, etc., and would like to have a sticky ecosystem like Apple.

The other theory is that Amazon believes users will prefer it as a premium branded product, again like Apple. The product does not need to compete with Roku on price, in that case, but does need to compete on features.

Slashdot Top Deals

Understanding is always the understanding of a smaller problem in relation to a bigger problem. -- P.D. Ouspensky

Working...