Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Comment Re:OpenSSL and the Internet (Score 0) 97

It's an affront to common sense to put security as an afterthought on top of another protocol instead of making it an intrinsic part of the protocol. But that's what you get when you use ancient technology (and yes, TCP is ancient by computer standards) and simply refuse to accept that it is necessary to invest into it.

But security does not sell. Only now people finally start to slowly catch on and realize that there might be a reason for security. They still don't know jack about it. They only know they "kinda wanna be protected". And that's what HTTPS and OpenSSL offers. It looks secure, Joe Randomsurfer doesn't understand jack and the whole security community will certainly not stand up and admit that it's all ... well, we can't really say it's insecure but ... well, I wouldn't bet my job on it either.

The problem with the whole shit is that it is very, very hard to prove without a doubt that something is insecure when it's not blatantly so. And OpenSSL is not blatantly insecure. It doesn't have the gaping "dude, that's fucked up" holes. When you look through the past year, from heartbleet to POODLE, you'll notice that ... ok, heartbleet was a blunder and a half, but POODLE is by no means something you will instantly understand without quite a bit of understanding of the whole security process behind it and even then it may take a while to wrap your head around it.

We're heading into the area of chances and probabilities. And I do predict that we'll see a lot more of this, attacks where it's not clean cut and "easy" to end up with a way to break security, but we will find that systems we thought to need 10^DAMN_LOT tries to brute force only need 10^VERY_LITTLE, because of flaws in the implementation or even the algorithm itself, where it becomes known that most of the "possible" keys were in fact impossible.

That's what I'd expect from the next few years. And I kinda fear that we will find out more than we'd want to know.

Comment Re:What's the difference between China and EU? (Score 2) 222

so you're ok with child porn and death threats?

can i take photos of you having sex with your significant other and put it on a billboard in your hometown? it's just free speech dude

everything has limits. including free speech. not because i say so, but because of simple logic and reason: it ends where it impinges on the freedoms of others. classic example: yelling fire in a crowded theatre

the fact that i recognize that freedoms are not boundless, but logically constrained by other people's freedoms, does not make me an authoritarian, it just makes me smarter than you

Comment Re:The "what?!" is reaction time (Score 1) 304

It also means that, instead of just being charged with "distracted driving," the perp can be charged with "texting while driving" and "driving erratically" and "distracted driving," which adds up to triple penalty (including jail time!) unless he gives up his right to trial and allows himself to be railroaded into a "plea deal."

Comment Re:Nope (Score 1, Funny) 332

I can't see the hairs on real people 10 feet away (for normal arm hair), if I can see the hairs on someone's arm on TV, why are they zoomed in on someone's arm?

I suspect that the format might fit a certain popular film niche, in which seeing the actor's body hairs is in fact considered a desirable feature.

Slashdot Top Deals

Ya'll hear about the geometer who went to the beach to catch some rays and became a tangent ?

Working...