Forgot your password?

typodupeerror

Comment: Re:"Damage" (Score 1) 311

by Rich0 (#39089805) Attached to: UK Student Jailed For Facebook Hack Despite 'Ethical Hacking' Defense

Maybe they didn't have an IDS. Or, maybe they weren't certain it was accurate. If an intruder is roaming around on your LAN (where they shouldn't be anyway), how do you know your logs truly show everything they did?

Bottom line is that a guy who breaks into your house isn't in a good position to argue about how much money you spent checking the contents to make sure nothing was taken. The intruder broke the law, and a judge is not going to give him the benefit of the doubt.

Comment: Re:How about Android apps ? (Score 1) 177

by Rich0 (#39089779) Attached to: Unauthorized iOS Apps Leak Private Data Less Than Approved Ones

So, how is giving a user an app that steals private data and the ability to block that stealing worse than simply giving them an app that steals private data with no ability to block it at all?

Sure, most users won't make effective use of any tools you give them, but they're not any worse off for it...

Comment: Re:The $200,000 figure... (Score 1) 311

by Rich0 (#39088807) Attached to: UK Student Jailed For Facebook Hack Despite 'Ethical Hacking' Defense

For the record, I agree with most people here that the $200k "damage" figure is bs. Unless he infected their system or took down security in some way, that $200k cost was only the cost of patching their preexisting vulnerability.

What about the cost of investigation? How do you know if he infected your system or took down security in some way, unless you investigate? That costs money - if you have a multidisciplinary team of 10 on it (server guys, database guys, application guys, security guys, and a lawyer), it costs you the better part of $1k per hour.

Comment: Re:"Damage" (Score 1) 311

by Rich0 (#39088783) Attached to: UK Student Jailed For Facebook Hack Despite 'Ethical Hacking' Defense

Did he cause damage or reveal it?

I dunno - I'd have to do a security review to figure that out...

If I walked into work and found in some server log signs of suspicious activity and a possible intrusion I'd report that to senior management. Then this guy would call them up and say "hey, I broke in - I just took some notes and for a fee I'll help you clean up, and don't worry - I didn't do anything other than copy data off your servers while I was in there." Then the managers would ask me "did this guy do anything besides copy data off our servers?" I would have to reply, "I dunno - we'd have to REALLY carefully check all our logs to know for sure, and we should assume that he's got the password files to every box in the server room to be safe." Then the managers would ask "can you change the passwords?" Then I'd answer, "sure, but that means changing the access credentials on all our internal applications, which means testing cycles to ensure we don't break anything else." Then the managers would say "get right on it, and keep a record of all the time anybody spends cleaning up this mess."

If a guy breaks into one of my servers, I'm not going to assume he's nice just because he claims to be. $200k isn't a lot to burn through when employees with overhead cost $90/hr.

Comment: Re:Bad reason to get vaccinated (Score 1) 1258

by Rich0 (#39084865) Attached to: Doctors "Fire" Vaccine Refusers

Just on a whim, where do you come down on the abortion debate?

That's a bit of a mess. On the one hand killing your kids because they're inconvenient is despicable. On the other hand we let people do far worse to them and then everybody else has to deal with the mess.

The affordable socialism solution to this is fairly straightforward - implanted contraception for everybody and it is only removed if you're issued a reproduction license. Social programs get generally funded out of license fees. So, anybody who doesn't want to have kids doesn't have to pay for running schools, and so on. If you want to have kids you get a share in the risk that they'll have problems, and you won't bear much more or less than that share no matter how it turns out (at least not financially). To encourage diversity beyond children of sociopaths who are good at accumulating money there could be "scholarships" based on any number of criteria, and perhaps even a lottery as well. Those who elect to just buy their way in end up paying a bit more so that their kids can live in a functional next generation.

We'll never see any of that happen, or a clean solution to the abortion problem. Most people would rather just deal with the unmanaged mess until society collapses under the weight of its entitlement programs than try to engineer a society that is sustainable.

Comment: Re:First thing.. (Score 1) 177

by Rich0 (#39084831) Attached to: Unauthorized iOS Apps Leak Private Data Less Than Approved Ones

What's wrong with email? You can attach anything you want,

That's great for sending out info, but it isn't very useful for receiving info if everybody else is posting it on Facebook.

If you can convince 40 bazillion people to stop using facebook more power to you - I stopped posting on it ages ago.

Comment: Re:Lot's of possibilities (Score 1) 489

by Rich0 (#39084765) Attached to: James Randi's Latest Debunking Operation

Such things are beyond the scope of archaeology. What is the point of debating them? Everybody already knows that people can't walk on water or rise from the dead. Either it happened anyway, or it didn't, but at this point the best you can do is philosophical argument.

Arguing over whether a particular person was governor is something that at least is potentially verifiable.

Do not clog intellect's sluices with bits of knowledge of questionable uses.

Working...