Forgot your password?

Comment: Re:Findings... (Score 1) 72

by vux984 (#47716001) Attached to: Tor Browser Security Under Scrutiny

They say ASLR is disabled

I *think* what they are saying is that:
ASLR is disabled in their build of the software. (It must be enabled via compiler option).

However, ASLR is enabled in windows itself.

from Microsoft:

Address Space Layout Randomization (ASLR): In older versions of Windows, core processes tended to be loaded into predictable memory locations upon system startup. Some exploits work by targeting memory locations known to be associated with particular processes. ASLR randomizes the memory locations used by system files and other programs, making it much harder for an attacker to correctly guess the location of a given process. The combination of ASLR and DEP creates a fairly formidable barrier for attackers to overcome in order to achieve reliable code execution when exploiting vulnerabilities.

ASLR was introduced in Windows Vista and has been included in all subsequent releases of Windows. As with DEP, ASLR is only enabled by default for core operating system binaries and applications that are explicitly configured to use it via a new linker switch.

As for EMET and ASLR:

Basically EMET can force recent versions of Windows to use ASLR even on applications that don't explicitly build with support for it:

EMET can force a non-Microsoft application to perform ASLR on every component it loads, whether the program wants it or not. Please note that before you install EMET, youâ(TM)ll need to have Microsoftâ(TM)s .NET Framwork 4 platform installed. And while EMET does work on Windows XP (Service Pack 3 only), XP users cannot take advantage of mandatory ASLR and a few other notable protections included in this tool.

Comment: Re:I definitely share password with family (Score 1) 115

by vux984 (#47715919) Attached to: 51% of Computer Users Share Passwords

Not really sure which post is "GP" at this point.

I agree that there are better alternatives to sharing passwords in many cases.

I just think that the scenarios where "sharing" is so far-and-away the easier (perhaps even "better") solution that they shouldn't be classified as a 'rare exception'. Its pretty common.

For example, my wife and I both need the passwords to all of our utility accounts. The teenaged kids have the login to netflix. We all share the login to the HTPC in the living room rather than having separate accounts. These are all cases where I "have" to share passwords.

If I had a trusted guest house-sitting while I was away? Would I change the netflix and wifi and htpc and alarm code just for their visit? No. I could, but I wouldn't bother. Not in a million years. This is a case, where I *could* change the password and change it back... but I wouldn't.

If I had to give my some tech at my cell carrier my password so they could log into my account to look at it with me (something I HAVE had to do in the past) then yes, I do change it, give them a temp, and then change it back.

People need to think about it on a case by case basis. A "sharing passwords is always wrong" mentality is absurd... a "give your password to anyone who needs into your account" mentality is just as absurd.

Each case needs to be evaluated on its own merit... value of what is being protected, level of trust to the individual, level of hassle, etc. Neither scenario is exceptional or rare.

Comment: Re:well (Score 1) 194

by vux984 (#47715665) Attached to: Phoenix Introduces Draft Ordinance To Criminalize Certain Drone Uses

Unfortunately, the exemption you quoted doesn't cover what I am doing,

I read it as the law targeting drones that show a guided intent to record someone, you read it as the law including anything that happens to catch an image of anybody.

  It proposes "filming people unawares from a drone" as being a problem. I see that as being distinct from simply having an image of somebody in the shot as you fly by.

Just as I can tell the difference between being incidentally in the background of someone's photograph, and someone photographing me. Or the difference between someone behing behind me, and someone following me.

I see the law as only targeting deliberate use of the drone to take video of people unawares, not your backyard scenario.

I fly my drone I'm guilty -- for flying my own drone in my own backyard with the clear intent of videoing only my backyard. Oops, caught a bit of the neighbors again. Here come the cops....

So move where you have a less idiotic neighbor. Because even if they don't pass this law, the neighbor can STILL call the cops if he sees you flying a drone around his yard with a camera, and you'll potentially STILL get charged under the existing anti-peeping laws, or at the very least harassed and questioned, and have the contents of your camera examined to establish you weren't peeping.

Hell, you don't even need a drone. The minute you pull a camera out on your deck, those neighbors can call the cops and accuse you of trying take pictures through their windows... using a camera or telescope (or zoom) to look through your neighbors window is ALREADY illegal.

My point HERE is that if you have THOSE neighbors, you are already screwed.

Comment: Re:Torvalds is true to form.... (Score 1) 552

by vux984 (#47715371) Attached to: Linus Torvalds: 'I Still Want the Desktop'

Either a vendor thinks the market is large enough to bother with or not. The "level of bother" factor is largely irrelevant.


What is the Return on the Investment? The "level of bother" is the "I". The smaller the "level of bother", the better the ROI, the more likely the vendor will do something.

That said, I DO agree that if the R in ROI is sufficiently small, then even if the I goes to zero it still won't be worth the vendors while. Lots of large companies require both a high absolute R, plus a reasonable ROI, which is why you get companies shutting down small but otherwise perfectly profitable business units. (which is VERY frustrating...)

Comment: Re:I definitely share password with family (Score 1) 115

by vux984 (#47714735) Attached to: 51% of Computer Users Share Passwords

Are you seriously attempting to imply that the rare exception should justify the rule for normal behavior? I really hope not, but that's how I read what you wrote.

Not at all. When you can change to a temporary and back you should. But the exceptions where that isn't simple aren't all that rare. (And in the case of systems that won't let you change back, you often don't find out until after you've gone down the rabbit hole; so its especially annoying.)

Wifi pre-shared keys for example are a prime common-as-dirt scenario, where its a giant PITA to change them for a temporary guest, just to avoid sharing your password.

Comment: Re:performance never measured in MHz (Score 1) 151

by vux984 (#47714667) Attached to: Can Our Computers Continue To Get Smaller and More Powerful?

You only believe an urban legend, a myth, a falsehood was true.

Give me a break. Everybody who lived at the time buying computers used MHz as a proxy for performance.

Those of us who did measure performance of machine over the past four decades used benchmarks.

I'm sure you did. I remember the benchmarking tools too. I know anyone professionally measuring performance used them.

But the majority of the buying public, and a great deal of corporate/business/enterprise/educational buyers too made all their decisions based on MHz.

The reason there were so many articles about the "MHz myth" -- it was precisely because a LOT of people were using MHz as a performance metric.

Its simply ridiculous to claim that nobody was using MHz as a performance metric.

Comment: Re:I definitely share password with family (Score 1) 115

by vux984 (#47714245) Attached to: 51% of Computer Users Share Passwords

Even if you trust someone to fix a problem, why would you trust them with your password? Set a temporary password so they can fix something, then change it back when they are done fixing.

These days, common as not, you aren't allowed to set it back to what it was before. I think gmail, for example, now enforces password history for example. Pretty infuriating, because I DO generally change passwords before giving someone temporary access.

If you want a "proper" car analogy...

You would talk about those cars with the little number pad above the door handle?

I have no idea why you would give someone the temptation, especially when there are simple safe alternatives.

a) You can't change the password from where you are. Happens all the time. Maybe you are giving the person the password precisely so they can help resolve the problem preventing you from logging in where you are.

Your buddy borrowed your truck, you lent him the keys, and he locked them in the cab... he's 500 miles from anywhere. Do you tell him the keypad code?

Best practices says if you do this, change the code when you get the truck back. No problem.

Maybe you have a whole fleet of trucks, and for simplicity you had the same code on all of them. Now your fucked and have to re-key the whole fleet...

b) Cases where changing the password creates rolling chaos. Think scenarios where the same password is on several devices. For example you want to let a guest onto your home wifi but don't want to give him the password -- changing it while he visits knocks everything else you have off the network. Other scenarios -- backups, where multiple computers backup to a service and all use the same key, or various file sync things, where changing the password will throw errors up all over the place.

Comment: Re:well (Score 1) 194

by vux984 (#47708881) Attached to: Phoenix Introduces Draft Ordinance To Criminalize Certain Drone Uses

Yeah, because using my own drone to video in my own backyard is SUCH a douchebaggy thing to do, because it might possibly see over the fence I PAID TO INSTALL and catch a bit of you in your yard while I'm using it.

Its not. And its highly unlikely to fall afoul of the law. That was my point.

Well, if I'm taking video of me in my own backyard them I'm identifiable, and I'm going to hazard a guess that those people in my neighbor's yard that is in view will be identifiable, and I'm not doing artistic or journalistic operations ...

Nor are going out of your way to record them in any way; and presumably you'll blur or edit them out before you post any video/stills online... so...?

Comment: Re:This actually makes perfect sense. (Score 3, Informative) 112

by hey! (#47708377) Attached to: Scientists Find Traces of Sea Plankton On ISS Surface

Except water vapor is the gaseous form of water; the plankton would have to be transported on individual molecules of water to reach the ionosphere.

If plankton were transportable in microscopic *droplets* in the troposphere as you suggest, a more plausible explanation is that the equipment was contaminated -- both the station itself and the gear used to test it.

Comment: Re:well (Score 1) 194

by vux984 (#47708203) Attached to: Phoenix Introduces Draft Ordinance To Criminalize Certain Drone Uses

I think it should not be illegal for me to fly my drone in my backyard just because the focal length of the lens on the camera it carries means it will take images of my backyard and a bit of someone else's.

It doesn't appear the law would make that illegal. It proposes to make filming people unawares from a drone illegal. Catching a "bit of someone elses back yard" while flying in your own hardly sounds like you are filming other people.

Certainly the law should not allow someone to damage my drone while I am flying it in my backyard just because they are paranoid that it might have a camera and that the camera might be catching them in its view.

I must have really missed something. Where did it say they may damage the drone in your own backyard based simply on a suspicion that it MIGHT have a camera?

If the goal is to make "doing X" illegal, then make that illegal and don't waste time adding "from a drone".

Your realize we don't actually have the draft proposal in front of us. Perhaps it merely calls out low altitude aerial photography and doesn't call out "from a drone". Perhaps "from a drone" was simply added to the news release because drone is a good keyword that gets hits, and "drone photography" is the root cause prompting this law. But perhaps, just perhaps, the proposed law doesn't specify it has to be "from a drone".

As for the rest, according to the news article:

"However, the proposal has many exceptions, which include permissible taping and photographing for mapping or artistic or journalistic purposes as long as the recording shows several residences and no individual is identifiable. The ordinance also would allow violators a defense if the person destroyed the photos or tapes upon learning of the law as long as he or she did not record or photograph children, sex or nudity or distribute the images or recordings."

So it seems pretty clear that unless you are being a douchebag, you won't run afoul of this law, and your fears about being harassed for flying a drone in your backyard where you might catch a bit of the neighbors yard are just hysterics.

Comment: Re:Trust, but verify (Score 1) 168

I disagree. It means trust but don't rely entirely on trust when you have other means at your disposal.

Consider a business deal. You take the contract to your lawyer and he puts all kinds of CYA stuff that supposedly protects you against bad faith. But let me tell you: if the other guy is dealing in bad faith you're going to regret getting mixed up with him, even if you've got the best lawyer in the world working on the contract. So you should only do critical deals with parties you trust.

But if the deal is critical, you should still bring the lawyer in. Why? Because situtations change. Ownership and management change. Stuff can look different when stuff doesn't go the way everyone hoped. People can act differently under pressure. Other people working at the other company might not be as trustworthy as the folks sitting across the table from you. All kinds of reasons.

So you trust, but verify that the other party can't stab you in the back, because neither method is 100% effective. It's common sense in business, and people usually don't take it personally. When they *do*, then that's kind of fishy in my opinion.

Comment: Re:well (Score 1) 194

by vux984 (#47707843) Attached to: Phoenix Introduces Draft Ordinance To Criminalize Certain Drone Uses

Why should the platform matter, when the alleged goal is "privacy" and the taking of pictures?

The law reacts to a perceived problem, written by people who are primarily adept at things like fundraising and image management.

"residency" and "citizenship" are prerequisites for the job. "Writing good Legislation 101" isn't.

Should there be a law that makes it illegal to use a tripod with a camera to take pictures of people that violate their privacy? How about using a stedi-cam to do the same thing?

These don't generally allow different vantage points than just holding it. So the rules and norms for already in place for photography are reasonably adequate. A drone enables a heretofore generally inaccessible vantage point. It is the new "problem" in question.

Can I throw my camera up in the air to get over-the-fence shots?

If that actually becomes a widespread problem, then we can expect a new law to be passed.

Just as a law was recently passed in response to someone taking upskirts after it was found the existing laws didn't close off the loophole the photographer was using.

You are right, in the sense that the law outlawing the 'platform to take photos' is silly, that it should be a law defining what a "privacy invading photo" is and then outlawing that.

But that's ultimately a circular argument, since the definition is going to be one that includes "taking low altitude shots of people otherwise unaware, from vantage points a photographer could not normally stand, such as from a drone" anyway; and some smart ass is immediately going to ask... "what I drop my camera on the trampoline and it bounces up goes off and just happens to snap the neighbors back yard, am I a criminal now?"

The issue is not "should be", it is a matter of legality.

The law is an very imperfect expression of what society wants the rules to be, usually written re-actively to problems as they arise.

If your complaint is that its a pretty shitty system, then we agree. :)

If your complaint is that you should be able to take photos of your neighbors yard from a drone, then we don't.

Comment: Re:Why do we need Auto? (Score 2) 189

by vux984 (#47707465) Attached to: C++14 Is Set In Stone

C++ isn't strongly typed

Yeah it is.

Specifically reinterpret_cast. It's almost as unsafe, if not as unsafe, as good old C style casting.

Its exactly as unsafe. The difference is that it cannot happen by accident. You are telling the compiler, in very explicit terms that you WANT the reinterpret_cast behavior.

And strongly typed means you can't change the type.

Casting doesn't change the type of the thing being cast. It just lets you treat the thing being cast as if it were a different type. typeof(x) never changes.

If you have to ask how much it is, you can't afford it.