Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Comment Re: Wireless security (Score 1) 84

If you're using client certificates for authentication, and an attacker obtains the server cert, then the attacker can successfully fool you into thinking that you have connected to the real server, but the attacker cannot successfully fool the real server into thinking that you have connected to it. This kind of "half-MITM" attack is not usually thought of as a full MITM. The authentication protocol uses a challenge/response protocol which incorporates ephemeral keys and hence is not portable even between two entities both holding the same server cert. That is, if A and B both have the server cert, and A challenges C, and B obtains C's response to A's challenge, B cannot then impersonate C to A, since B does not know either C or A's ephemeral DH keys. Even if the attacker just blindly proxies between the real server and the real client, it won't work; in this case the communication would just be a real connection that the attacker can't decrypt or alter in any way thanks to forward secrecy.

Comment Not faked GPUs... (Score 4, Informative) 76

I've read the Heise articles in the original German, and the GPUs were not faked; the cards were an older generation graphics card (~10% of the graphics throughput of the claimed item) with the video BIOS hacked to zero out the card manufacturer ID and the GPU type twiddled to fool the driver into thinking it was the newer card. According to the articles, NVidia is tracing the GPUs through the supply chain by their internal serial numbers.

I would speculate that someone bought up a truckload of obsolete cards, reflashed the BIOS images, and relabeled them with plausible product ID labels. Could have been the Chinese manufacturer, could have been someone elsewhere in the pipeline.

Comment Re:"Paleolithic diets" now vs then (Score 1) 281

The latest research points to primarily sugar being the main problem in our diets. Excessive carbs in general seem to be likely driving a fair amount of weight and health problems and my very rudimentary understanding of the paleo approach addresses this and it's why many people on it find success -- if you're eating paleo, you aren't eating much bread, sugar, etc.

It seems to me that this transition to carb heavy diets that satiate hunger probably helped accelerate civilization -- it helped to satisfy hunger more easily and freed people to pursue activities that didn't involve hunting for food from dusk till dawn. But this came at a price -- negative health effects.

Maybe I just don't understand what paleo is all about, but trying to achieve a balance of macronutrients closer to those original diets seems like the point (or it should IMO) and not actually trying to eat foods that are 100% like what our ancestors ate.

Comment Re:That's why slashdot is against tech immigration (Score 1) 441

It's a very typical practice to have insane requirements that just aren't practical for jobs you have no intention of locally sourcing. Spend 10 minutes on a major job board and you'll find them. It will be like 6+ years experience in a product that's only been out for 6 or 7 years. They'll want someone that's an expert on three or four unrelated things that it's just not likely someone WILL be an expert on all of them -- expert in Java, SAN and Networking with 8+ years project management experience. They will post someone with CCIE level experience and be asking for someone at a CCNA level salary.

I've noticed you'll find this behavior often in older public companies that have exhausted their market growth through saturation and have made every reasonable efficiency improvement they can make without hitting salaries and cutting workforce. This is the last step of the constant drive for greater profits to appease shareholders.

Being in one of these companies at this transition period is not particularly pleasant and there's a better than good chance you'll get axed either on the front-end as they find a way to outsource your job or on the back-end as they prep the company to look more attractive to a potential buyer or after an acquisition and your job is marked as duplicate because someone from the other company is working for less and will get saddled with your work load.

Comment Re:The problem of Microsoft (Score 1) 337

You often can't customize your own install without breaking the law. The GP post specifically mentioned OEM Windows licenses as a way of getting cheap Windows licenses. This is no accident: OEM licenses are the only way to get cheap Windows licenses. Any sort of enterprise license will be far more expensive. But an OEM license is the least customizable of all the options. You can't even legally install an OEM licensed copy on any other machine other than the individual machine that the software came with, since an OEM license is tied to an individual machine. To get a custom install starting from an OEM copy, you can't just make one custom version and install it on all your machines; that kind of activity is specifically forbidden by the terms of the OEM license. You'd have to spend 30 minutes individually on each and every machine in your organization if you go the OEM license route and you don't want to break the law. Those 30 minutes of staff time are way more expensive than the bare-bones OEM license cost. Alternatively, you could purchase an enterprise license, but now we're no longer talking about cheap Windows licenses, we're talking about very expensive Windows licenses.

So, yes, you can customize Windows installs, but it's much more expensive to do so in any legal way, since you need an enterprise license, which really does cost ridiculous amounts of money. There is no cheap way to get customizable Windows. Even then, it's a bit of a hassle compared to Linux.

Comment Re:Pete and Repeat (Score 1) 278

Most employers only care what you've done in the last 7 years. Outside of that window, it's generally assumed that either A. The skills/tech are no longer relevant or B. If you haven't used it in the last 7 years, you probably don't remember it well enough to be relevant anyway.

Tweak your resume to highlight your skills and experience that are relevant to the job posting. Don't include anything that isn't directly related or completely awesome. I mean REALLY awesome. Like you won a prestigious award kind of awesome.

Most resumes I've seen that are excessively long would be less than 2 pages following this design regardless of the formatting unless you used gigantic fonts.

Comment Re: The problem of Microsoft (Score 1) 337

It's not the price (free or pay). It's what you can do with the software. Apple software is still subject to BSA audits. You can't distribute customized versions. Things are slightly better in that hardware support is uniform and there are no client access licenses, but you also encounter new problems like Apple dropping software support for your hardware. Free software is just better. The cost of purchasing the software is insignificant. The time and hassle saved by free software is the real jewel.

Microsoft and Apple are poor choices unless your (sysadmin, IT, and staff) time isn't worth anything.

Comment Re:The problem of Microsoft (Score 5, Insightful) 337

The Microsoft tax is not just about the monetary price of Windows. That's actually the least burdensome part of the tax. The real problem is the cost of license compliance. Most obvious are the direct costs: license management, purchase records, and receipt tracking. How much staff time are you going to spend on keeping track of Client Access Licenses? Is this expense worth it, when there are free platforms with no CAL requirements? I bet you didn't know the MS EULA gives the BSA the right to audit your premises at will. That's another huge overhead which simply does not exist with free software: A single small screw-up (almost inevitable, given the minuteness with which the audit is conducted) results in heavy fines plus having to pay the considerable costs of the audit. Compared to this insanity, anyone using exclusively free software can simply slam the door on the BSA and tell them never to come back unless they have a warrant.

Those are just the direct costs of compliance. The indirect costs of Microsoft's licensing model are something that even fewer users realize. You can't customize a distro and legally release the result to anyone outside of the organizational unit holding the license. You can't slipstream updates and legally distribute to outside parties. You can't create USB bootable media and legally release it to anyone else. Rescue discs and installation discs customized for particular hardware are left to the mercy of your OEM. All of these restrictions cause considerable friction which slows down the agility of your business. If nothing else, it makes it very hard to outsource IT functions; at most, you can hire contractors who have to keep your OS software bits separate from everyone else's OS software bits. How can this situation possibly compare favorably to free software where anyone can create and share anything? It really can't.

Comment Re:Athletes? (Score 1) 146

Pretty much all of the games require at least two of the following:

1. The kind of hand to eye coordination you'd need for ping pong
2. The mental concentration golfers must exert for virtually every shot (often for the entire length of a game)
3. The muscle memory necessary of any sport

That the players don't generally utilize their cardiovascular system doesn't mean it's less of a sport. I mean after all -- you don't exert much cardiovascular wise in golf or bowling.

Comment Re:keep calm everyone.... (Score 1) 183

Funny enough I think "panic" is _exactly_ what frightens the crap out of governments of heavily populated and prosperous countries. Citizens acting irrationally and taking evasive actions that craters economies -- that's the stuff apocalyptic books are made of. The entire world could change in a matter of months if this hit a few major cities in America, Europe, Russia and other major nations.

People don't panic _as much_ about flu pandemics because of lower death rates and healthy folks typically only having a few days of not so great experiences but otherwise being OK. But a 50%+ death rate? That's the kind of thing that makes lots of people do very dumb things.

Slashdot Top Deals

All seems condemned in the long run to approximate a state akin to Gaussian noise. -- James Martin

Working...