Forgot your password?

Comment: Re:The Canadian Exodus.... (Score 1) 1608

by heypete (#46770131) Attached to: Retired SCOTUS Justice Wants To 'Fix' the Second Amendment

Yo should look a little deeper.
A) Guns are seriously regulated, including need to account for every round. Good luck getting the level of regulation about firearm in the US.

Not quite. You need to account for every round purchased at the range because the government subsidizes such ammo, even for practice purposes with non-government-issued firearms.

You can buy unsubsidized sporting ammo from gun shops and gun-related sporting goods shops with essentially no restrictions other than having the fact that you've bought ammo recorded in a logbook at the shop (which is the case for a small number of US states).

The Swiss do require a permit to purchase guns from a commercial shop, but this is automatically issued unless one is disqualified from owning arms (e.g. mentally unfit, convicted criminal, etc.). Purchasing single-shot or bolt-action firearms does not require a permit. Private sales do not require a permit, but buyer and seller need to keep a record of sale for 10 years.

Source: I live in Switzerland.

Comment: Re:Oh, man, what a mess (Score 5, Insightful) 151

by heypete (#46741445) Attached to: Private Keys Stolen Within Hours From Heartbleed OpenSSL Site

So not only do those of us responsible for web servers need to generate new server certs for all of our servers... pretty much every current web server cert in existence also needs to be revoked. Are the CAs even willing/able to do something on that scale in a short amount of time?

Netcraft actually has an interesting article about that very situation.

Obviously, the CAs don't really have a choice in the matter, but I can't imagine they really have capacity issues in regards to the actual revoking/signing as that's all automated. If things get crazy busy, they can always queue things -- for most admins it doesn't really matter if the new cert is issued immediately or after 15 minutes.

Human-verified certs like org-verified and EV certs might have a bit of delays, but domain-validated certs should be quick to reissue.

Of course, revocation checking for browsers is really bad. Ideally, all browsers would handle revocation checking in real-time using OCSP and all servers would have OCSP stapling enabled (this way the number of OCSP checks scales as the number of certs issued, not the number of end-users). Stapling would help reduce load on CA OCSP servers and enable certs to be verified even if one is using a network that blocks OCSP queries (e.g. you connect to a WiFi hotspot with an HTTPS-enabled captive portal that blocks internet traffic until you authenticate; without stapling there'd be no way to check the revocation status of the portal).

Also, browsers should treat an OCSP failure as a show-stopper (though with the option for advanced users to continue anyway, similar to what happens with self-signed certificates).

Sadly, that's basically the opposite of how things work now. Hopefully things will change in response to Heartbleed.

Comment: Re:Won't work (Score 1) 342

by heypete (#46683479) Attached to: Australia May 'Pause' Trades To Tackle High-Frequency Trading

Personally, I think that it should be law that if you buy shares in any company (or fund or whatever), you have to hold on to them for a minimum of a week or a month. Shares represent actual physical companies which own factories and employ real people. Those things don't change in 500 ms. They change over a much larger amount of time. And I believe that the stock market would be healthier if this was reflected in its trading. Obviously, when new information comes out (press release: "The factory of company X has just gone up in flames"), everybody's counter should be set to zero, but shares sold in such a case cannot be bought back a fraction of a second later (because whoever just bought them has to hold on to them for a week/month).

A week or a month might be a bit too long, but something along the order of 1-5 minutes might be reasonable.

Alternatively, one might also have the exchange do batch orders: traders submit their orders to the exchange, the exchange groups them all together, and then processes them all periodically (say, every 30 seconds or something), then displays the results. Since the results are not released until after the batch is fully processed there's no advantage to submitting an order at 29.999 seconds compared to any other time within that window. This way trades can be executed reasonably quickly on a human scale and HFT doesn't have any particular advantage.

Comment: Re:Sand in the brain - cloudflare in the way? (Score 1) 105

by heypete (#46682535) Attached to: Sand in the Brain: A Fundamental Theory To Model the Mind

What's with the "cloudflare" website middleman stuff? Kind of feels like someone's breaking net neutrality. I can't read the link unless I go through a middleman SSL & whatnot?

Cloudflare's basically a CDN.

The site owner intentionally uses Cloudflare as a middleman to cache their content in locations around the globe and to improve security (Cloudflare can block attacks before they hit the actual server). Cloudflare also offers SSL proxying to site owners so visitors can connect securely to the local Cloudflare cache, which in turn connects securely to the source server.

It's quite similar to, say, Akamai, and doesn't "break net neturality" (the site owner specifically elects to use Cloudflare, just as they'd elect to use Akamai).

Comment: Re:maybe the internet should be put in space (Score 3, Insightful) 223

by heypete (#46682173) Attached to: Why There Are So Few ISP Start-Ups In the U.S.

with dozens of satellites in orbit and then no ISP subscription needed, FREE internets for everybody with an internet capable device, smartphone, tablet, laptop, desktop, etc...

that would make ALL ISPs obsolete

Who pays for the launches, the satellites and the constant adjustments needed to keep them in proper orbits, the ground stations, and the staff needed to run everything? Those are hardly free.

Comment: Re: Snowden's leaks has gone off the rails (Score 2) 90

by heypete (#46672415) Attached to: More On the "Cuban Twitter" Scam

Do I think he's lost legitimacy? No.

At the very start he turned over all his data to a few journalists (Glenn Greenwald, Laura Poitras, etc.) and they are the ones who choose to publish articles based on the data he gave to them. Snowden has said he doesn't retain any of the documents or data himself, and has no control over what is published or not. That's entirely up to the journalists.

Comment: Re:Two years? (Score 1) 142

by heypete (#46659419) Attached to: Skydiver's Helmet Cam Captures a Falling Meteor

How come it made into the news now but not at that time?

Two years is a long time. It seems it is the time it takes to a non-professional to tamper with a video, after the guy got the idea that the video would be more fun having a meteorite falling along with him. Seriously, a falling meteorite? Even if the camera would have caught a real meteorite, we'd have seen a blurry line, at best. The images breakdown clearly shows a number of photographs that have been added to the video.

If the meteorite and the skydiver were moving at (or near) their respective terminal velocities, why do you think that you'd see only a blurry line? The meteorite is not traveling at orbital velocities that deep into the atmosphere (or else it'd be glowing).

Comment: Re:RTA: geologists wanted to find the rock (Score 5, Informative) 142

by heypete (#46659413) Attached to: Skydiver's Helmet Cam Captures a Falling Meteor

Article notes that they kept it quiet so the geologists could have a look for the rock - I assume these things are pretty rare and perhaps there's even a concern a treasure hunter might get there first and take it? (perhaps a geologist can give a more informed opinion here....) . Certainly I have a geologist friend who was flown from Europe to the deserts of Australia on more than one occasion to look for meteorites because they are so rare... apparently much easier (comparatively speaking) to spot in a bare desert than lush green European landscapes.

The article suggests they looked for it, couldn't find it, and are now asking the public to help find it. Plus perhaps it took a while before the sky diver realised something had happened after a few views of the footage, he might not have realised at the time.

I'm not a geologist, but I do research on meteorites and have participated in a meteorite search expedition sponsored by the Swiss and Omani governments. You're right: there is a concern that private collectors might find meteorites first. In the case of the expedition I was on, that was a major concern: we were plotting the distribution of thousands of fragments of one meteorite strewn over a large (several hundred square kilometers) area. Each of the fragments we found were photographed where they lay from several angles, the location recorded using GPS, given a catalog number, collected using clean tools etc. Private collectors often don't bother doing this, so it makes it difficult to identify where meteorites in private collections came from. This makes it difficult for researchers who are interested in the precise distribution of the fragments (some of my colleagues are able to use the distribution of light and heavy fragments from this meteorite to determine the speed of the wind at different altitudes when the meteorite passed through the atmosphere, and this requires precise knowledge of where the fragments were found). My particular research is less concerned with location, but it's still nice to know the provenance of meteorites.

Of course, we don't begrudge individuals finding meteorites and wanting to keep or sell them, but we'd really appreciate it if people called their local university (or other relevant authority) so researchers could log the find and perhaps keep a sample for scientific purposes.

Comment: Re:OwnCloud (Score 4, Interesting) 243

by heypete (#46620239) Attached to: Dropbox's New Policy of Scanning Files For DMCA Issues

This is what OwnCloud is made for.

I know not everyone is able to set up their OwnCloud server. There are places that will host it and set it up for you.

OwnCloud is great, with one exception: the slightest change to a file necessitates an upload of the entire file. Dropbox does delta syncs using a modified version of rsync, so it only uploads change portions of a file.

For typical files and fast connections, the lack of delta sync is tolerable, but when you're dealing with large files or slower transfer speeds it's an issue: if you, for example, you keep a large TrueCrypt container file in OwnCloud and make a change to a small file stored in the container, OwnCloud needs to reupload the entire container. Dropbox would just update the blocks that changed.

Until OwnCloud implements some sort of delta sync functionality it is considerably less practical than Dropbox.

Comment: Re:Sometimes I wonder why we even have this topic. (Score 2) 144

by heypete (#46606417) Attached to: Microsoft Promises Not To Snoop Through Email

I believe it was Thawte did/do free certs for email for non-commercial use. I would prefer php/gpg though.

Edit: did. Ah well.

(Just kidding, Slashdot has no edit function) and StartSSL offer free client certs.

While CAcert's root is not included in browsers and mail clients (thus people you communicate with will need to install and trust the CAcert root or they'll get scary warnings), the StartSSL root is widely included. StartSSL is totally free for "Class 1" certs (domain-validated server certs or email-validated client certs) for non-commercial purposes. Class 2 certs (identity-validated server and client certs, as well as organization-validated certs for organizations) only charge money for the validation, but you can issue as many certs as you want for yourself (or your organization, if you get the org certs) at no extra cost.

Comment: Re:UPMC Presbyterian Hospital in Pittsburgh (Score 5, Informative) 357

by heypete (#46600915) Attached to: Gunshot Victims To Be Part of "Suspended Animation" Trials

My question is this voluntary? How is exactly does one opt out if they prefer traditional care? Doesn't seem to be like a recent victim of gross trauma, can exactly make an informed decision.

According to the article at New Scientist:

Getting this technique into hospitals hasn't been easy. Because the trial will happen during a medical emergency, neither the patient nor their family can give consent. The trial can only go ahead because the US Food and Drug Administration considers it to be exempt from informed consent. That's because it will involve people whose injuries are likely to be fatal and there is no alternative treatment. The team had to have discussions with groups in the community and place adverts in newspapers describing the trial. People can opt out online. So far, nobody has.

Comment: Re:Opportunistic TLS for SMTP? (Score 1) 141

by heypete (#46538137) Attached to: Gmail Goes HTTPS Only For All Connections

The article briefly mentions this, but does anyone have any additional detail? Are they using opportunistic TLS on SMTP connections?


Depending on what ciphers are supported by the remote system, different ciphersuites will be supported. will only connect with RC4-SHA, but my server connects with ECDHE-RSA-AES128-GCM-SHA256. Your mileage may vary.

Luck, that's when preparation and opportunity meet. -- P.E. Trudeau