Education

Including Source for a Potential Hacking Tool? 20

rajinder asks: "What are the experiences of Slashdot folk when it comes to including the source code of a security tool in their final year dissertation? I have a project in mind that I want to submit that can be used by admins to evaluate the security of their wireless network(s), but it could just as easily be used for their nefarious purposes. Before I submit the idea, I wanted to see if anyone knew of potential hurdles I would have to face. Anybody ever done something similar? The official rules about what is allowed is available in this PDF [or the HTML version], but I don't see anything relevant to my dilemma (the relevant section is 2.4, page 9) UK university-system specific info would be appreciated, but I plan on carrying on my education in the US, so info from either side of the pond would be good. Does anyone know if I would be able to GPL the code afterwards and put it out there? Would it remain property of the University or the student that wrote it?"
Debian

What's Missing from Free Software? 141

dan.hunt asks: "Klaus Knopper was interviewed here and the interviewer, technobeast, asked: 'If you were asking the questions, what would be the 1st one you would ask?' Klaus answered in part 'What are you missing in the available Free Software, and how would you like to change that?'"
The Internet

Does Open Source Need a Red Team? 49

garyebickford writes "IMHO the Open Source community (whatever that is) needs a Red Team project. This would be an open source project, but its output would be a process rather than a piece of software. If such a group exists, I'm not aware of it. This document and this page [from the Google cache] are from a commercial company (picked at random from a Google search) that provides similar services. The OS Red Team would provide 3rd party security testing, code review and evaluation for open source projects prior to release, providing a 'report card' stating what has been reviewed and tested, and recommending fixes. When a package is released, the Team's 'weather report' stating the probabilities that a package would survive different kinds of attack would be a valuable piece of information for prospective users." Do you think the Open Source Community would benefit from such an effort?
The Internet

New Broadband Capping Techniques? 101

doublea16 writes "Upon calling my broadband cable company to see why my modem's upstream was so slow as of late, I was told I had been capped due to excessive uploads. When I dug deeper for more details, I was finally told by a manager that any upload in excess of 35 minutes (size of file or type, etc have no bearing) would result in an automatic capping of the user's upstream. The Terms of Service provided are very vague when it comes to their rights to restrict speed. I was wondering if anyone else out there's broadband company had resorted to tactics like this? Is this fair to the consumers or even legal?"
Linux Business

Network Chat as a Tool for Corporate Communications? 69

rimmon asks: "I'd like to know what experience have you made with [network-enabled chatting programs] as tools to communicate with your boss, with your employees or your customers? Does your company utilize [Instant Messenger or IRC] as a communication tool (to communicate with customers, between employees and Pointy Haired Bosses? If you use or provide [chatting systems]: Is this technology an effective tool to communicate? What are the Pros and Cons? What type of chat technology do you use and what flavor of chat (open, moderated, etc.) works best for you?"
Security

Replacing SMTP? 539

dousette asks: "In reading over one of the RFC's governing the SMTP protocol, and other RFC's as well, it's interesting to note that you see some big names and big companies from time to time. With all the loopholes in the current SMTP specification, is it possible for the Slashdot collective to come up with another one? Would it stand a chance in making it into a standard, or do they just listen to Cisco, AT&T, etc? I realize that a lot of people have a lot of ideas how things should be done (and they haven't been shy about posting them to Slashdot), but has anyone tried to write the RFC for a replacement protocol? As a side note (where I won't be shy about posting how things should be done), if there were a replacement trusted protocol, one could have mail received via that protocol bypass spam filtering, id checking, or whatever checks might be in place (saving processor cycles, etc). The regular checks could still be done on other mail received via the 'older' SMTP protocol. If more and more ISP's make use of this, SMTP could be gradually phased out... or if you are one for a sudden cut-over, just cut to the new one at the same time as the IPv6 upgrade!"
Linux Business

Workgroup Messaging? 60

Displaying my ignorance asks: "We have a small workgroup running on Windows XP Professional; we do not have a domain server. We use Peachtree accounting software which is supposedly multi-user. Unfortunately, multi-user does not translate into allowing two people to be in the same module (i.e., accounts receivable) at the same time. Because the users are in different buildings they often crash Peachtree because they don't know that someone else is already in that module. These crashes result in the loss of data since the last backup. I am therefore trying to locate software, compatible with Windows XP, which would allow a user to create pop-up messages for display on the remote screens. It needs to be a pop-up, not just a flag in the system tray; ideally it would be a flashing neon sign which fills most of the screen [grin]. Because we do not have SIP (Session Initiation Protocol) Messenger appears not to be a solution. Any suggestions?"
Businesses

On Employees Educating Employers? 79

ramannoodle asks: "My employer currently makes many decisions that I feel would save them a lot of money by going about it in a different way. I have presented many of these ideas to them, but being the not-so-great sales person that I am, I feel in some ways that by voicing my opinion on these things, I am jeopardizing my standing with the company. Is it the right thing to do to continue educating my employer on issues they do not want to hear, but will save them money and just risk being one of the many unemployed honest IT professionals out there? Do I hide what I know from them by keeping my mouth shut and just doing what they tell me so I can keep my job and feed my family? It's a tough economy out there, and is it worth being over-enthusiastic about helping the company?" We touched on this issue for contractors, but what about actual employees?
Technology

Required Tools for PC Repair? 202

kennethrona asks: "I seem to be spending a lot of my time installing friends' WiFi access points, replacing power supplies, hard disks, blocking ports, installing software, etc. I can usually find any of the software I need on-line, but am thinking about putting together a "toolkit" for PC repair. What tools, both hardware and software, does the community think are essential for PC repair? Bonus points for free software (I always install a free firewall and spyware checker). Also, keep in mind that most folks are running Windows."

Science and Math For Adults? 489

Peter Trepan writes "Like most Americans, I made it through high-school and college without a thorough understanding of major scientific and mathematical concepts. I'm trying to remedy this situation both for personal betterment and so I can supplement my *own* kids' education. The problem is, most textbooks are not designed to convey an understanding of the subject, but to squeeze in all the 'facts' required by state law. I'm looking for books that don't just tell me an equation or a concept works, but also explain *why*. Would you please list books that have helped you gain a greater understanding of the basic concepts of algebra, chemistry, calculus, physics, and other core areas of science?" This is similar to an earlier question, but with a broader focus.
Music

What Do You Get When You Buy a CD? 182

Wiseleo asks: "What is the full value and meaning of the entire transaction when someone exchanges money or its electronic equivalent for a new sealed CD?Notice that I am being extra careful to say that someone actually acquires anything of value in the deal. I am not claiming that anything is bought in the traditional sense either. I am in fact not claiming that any value whatsoever is procured through the transaction. Can someone actually answer this question? I would really love the RIAA to do so, and in fact, I intend to contact them for this purpose. This question is surprisingly complex. I first attempted to get it answered some 10 years ago by several music stores and they could not answer it. I guess I should have talked to attorneys, but I was a teenager clueless of such an avenue. I tried again late 90s and again I couldn't get the question answered. In other words, any 'commercial' CD that is produced by a RIAA-affiliated CD manufacturer clearly states that it is not to be loaned. If I 'buy' a CD, what am I actually paying for?"
The Courts

Is Licensing SCO Unix Legally Dangerous? 85

cheros asks: "I'm starting to get very puzzled by the SCO licensing scheme - am I mistaken or is licensing SCO actually about the most dangerous thing you can do as business or end user using Linux? [disclaimer: IANAL and AFAIK, so get decent legal council - I might be completely wrong ;-)] If I buy a copy of Linux from a provider, my contract is with that provider, NOT with SCO. In other words, if said provider has supplied me with something dodgy (and that is still very much an open question IMO), the issue lies with SCO and the provider, not with me and SCO, as I have no contractual relation with SCO in any way, shape or form. So, licensing SCO might actually CREATE that relationship and thus enable SCO to play further games with enforceable contractual obligations, something it currently lacks with end users. If that is correct it puts SCO in an even worse light (if that's possible) as that could mean deception as well as FUD. The latter might have become accepted in business and politics, but the former might actually be illegal in some countries. In short, as far as I can see you don't actually have a problem as a Linux end user...until you get a license. Comments?"
Handhelds

Property Rights and the MSDN PDA Give-Away? 95

An anonymous reader asks: "MSDN subscribers recently qualified for a free Viewsonic V37 PDA (supposedly, around 25,000 units were given away). The software development group, at my company, just received our shipments; however, now there is contention between the developers and the company over who owns the PDAs. The company I work for (a worldwide information technology and services company) contends that that they own the PDAs because they were obtained through a subscription purchased by the company and, therefore, the PDAs are company property (and so all company policies governing the use of their property applies). This upset quite a few developers in my group who were excited to have a new gadget to work/play with and now any tinkering must be approved by the company. So, who owns the PDAs -- the developers who found out about the promotion, filled out the forms, paid for the stamps, on their own initiative, etc. or the company who purchased the MSDN subscriptions to make the developers eligible for the 'free' promotion? Also, I am curious to find out if others are having similar debates at their respective companies. Details of the offer can be found here."
Linux Business

Desktop Linux Sliding in Under the Radar? 742

Paul Johnson asks: "This article at ComputerWorld describes a sysadmin's discovery that many people in his company are installing Linux on their desktops without consulting IT. The writer is concerned with the security implications, but there is a wider issue. At present the 'official' penetration of Linux into the desktop market is something around 1%. The writer of this article doesn't give figures, but it sounds like he may have stumbled on several times that percentage of desktop Linux installations. If so then this is an important trend. Linux got its foot in the datacentre door in exactly the same way a few years ago, with unofficial installations doing odd server jobs. If you are a sysadmin, in an organization that runs Windows on the desktop, have you stumbled on many unofficial Linux installations?"
The Internet

IPv6 Tunnel Brokers? 18

thedillybar asks: "I have noticed the appearance of many IPv6 Tunnel Brokers which allow anyone to sign-up and tunnel IPv6 over their current IPv4 connection. Hurricane Electric and BT Exact both offer tunnels here and here, respectively. For those of you using a tunnel like this, what do you think of their reliability and use as a development tool?"

Slashdot Top Deals