Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×

Comment Enter at your own risk (Score 1) 204

The way that I read Jeff's comment was not so much as a ban of the Feds but he seemed to be politically cautioning the attendance of Feds on potential hostilities from attendees who aren't particularly thrilled with the recent disclosures. We can all argue the maturity level of the conference but in the immortal words of Friedrich Nietzsche: "Madness is rare in individuals, but in groups, parties, nations and ages, it is the rule" Surely there would be severe consequences on both sides were there to be pranks or aggressions on Feds in attendance. Of my many years of attendance, I have never considered Defcon to be a completely open environment free from danger, but rather a Hackers Mos Eisley where you can interact with all walks of life, but that you had better be aware of those who do not like you.

Submission + - The state of information security today (purdue.edu)

tanawts writes: Capturing a recent topic posed during a panel at CERIAS Symposium, Gene Spafford breaks down the problems of the industries current response to computer security today.

The article touches on recent government involvement, pwn2own style competitions, and the vicious cycle of IT professionals being pulled into incident after incident without being allotted the time and priority to correct the systemic problems that cause these security fiascos.

"There's another barn on fire! Quick, get a bucket brigade going — we need to put the fire out before everything burns. Again. It is getting so tiring watching all our stuff burn while we're trying to run a farm here. Too bad we can only afford the barns constructed of fatwood. But no time to think of that — a barn's burning again! 3rd time this week!"

Submission + - Crisis averted in BIOS source code leak (scmagazine.com.au)

mask.of.sanity writes: The world's largest BIOS vendor has attempted to calm rising panic over the leak of the cryptographic signing keys and source code for its UEFI BIOS
A Taiwanese vendor had left a file transfer protocol server open for anyone to browse and download internal emails and the source code for the vendor's UEFI BIOS and cryptographic signing keys.
The company, American MegaTrends, said the security keys on the ftp server were not used for production systems.

Comment Re: Improve infrastructure, don't inact laws to pr (Score 1) 80

I'm not sure that we have a choice. "Because its hard" is probably not going to be a sufficient excuse with respect to the critical mass we are heading toward. If everything that the world has invested in standing on top of the Internet is so important, than all that important stuff is going to need to experience the growing pain of adapting to new redesigned transit protocols. The alternative seems to be a sheer cliff.

Comment Improve infrastructure, don't inact laws to prolif (Score 2) 80

Given that a lot of these problems stem from inherent design flaws with our current Internet protocols, perhaps we ought to start improving upon the 20 and 30 year old protocols we've been relying on. Fundamental scale and design flaws will continue to empower bad people to do bad things so long as it continues to be nearly effortless. BGP, DNS, IPv4... You can only build on a foundation for so long before its age and brittleness beings to cause serious problems.

Comment Sounds like tech support? (Score 1) 630

I guess I am desensitized... I realize this is a pharmaceutical company, but this is all very standard behavior in the tech support / call center world. I've seen this sort of thing since 1998, so it really isn't that new to me. In both cases it sounds like management is being asked to predict productivity and deliverables based on time. Is your job function serial in nature at all? Does someone have to do something to a product before its passed to you and do you pass it to someone after that?

Comment Two types of Professionals (Score 1) 515

You are going to find two types of techs throughout your career.

* The Career-Person:

Is there to punch a time card and collect a paycheck
Learns only what is necessary to do the job
Probably received a classroom education on tech
Goes home and complains about not having enough free time to socialize

* The Enthusiast:

Loves technology and loves getting paid for working with it
Is constantly researching new technology even if it doesn't have to do with work
Could either have a degree our self taught education
Goes home and hacks on/fiddles with some sort of tech

Slashdot Top Deals

"A car is just a big purse on wheels." -- Johanna Reynolds

Working...