Slashback: Shelter, Panic, Intrusion 110
Remember, Free Software Sinks Ships curtS was one of the many to point out that "MSNBC has an article about a security hole you could throw a cat through." This might be more exciting if it was the first time, but jamie posted about a very similar-sounding flaw a few months ago.
Calling off the dogs of war. An anonymous reader writes: "Slashdot reported that Indymedia had received a court order to hand over the logs and other records pertaining to the IMC's coverage of anti-globalization protests in Quebec City. Now FBI has dropped the case. Here is the press release."
phunhippy points to coverage at Wired as well.
This Old House - gr8dane writes "I was just checking out the Sunday posting on /. about .commers in homeless shelters and Salon is running an update to the same story. The previous post prompted quite a bit of feedback on /. and this update article seems to support those who felt the Sunday article wasn't indicative of the industry as a whole. 'John Sacrosante says he went from six figures to a shelter. His friends say there's something fishy in San Jose.' Quite interesting ... "
DoctorZ writes: "In response to reading the recent article about Zero-Knowledge's withdrawal from Linux development for Freedom. I emailed them discussing my concerns along with everyone else's. Here was their response:
'Hello,We know....
We understand your disappointment. It is not a easy decision. We are not giving up on Linux. Our entire Freedom Network is Linux based!This decision was taken in response to the number of people purchasing the Linux version as compared to the number purchasing the Windows version. While many of us at Zero-Knowledge are Linux enthusiasts, the number of interested Linux users downloading Freedom simply didn't warrant continued development efforts, and we have chosen instead to apply our development resources in a way that will maximize value to our customers.
Once again, thank you for expressing your concerns.
Regards,
Alan"
Re:Dot Com Urban Myths (Score:1)
Re:Dot Com Urban Myths (Score:1)
Figments of an overactive imagination.
Masquerading crack addicts.
Federal Reserve agents attempting to slow the economy by giving the illusion of mass layoffs.
Re:Oh... (Score:1)
http://www.gcn.com/vol19_no27/dod/2868-1.html [gcn.com]
Re:Dot Com Urban Myths (Score:1)
Salon might have to give the bribe back to the San Jose Chamber of Commerce, and you know how badly they need the money.
Re:Homeless Proofing Yourself (Score:1)
Unfortunately, all those things are related. Once you lose one, you are much more likely to start losing the others.
You lose your income, your savings start to dwindle while you look for another job. Furthermore, you're less employable; when you apply for a job, the interviewer asks you why you aren't working now (I assume this is approximately what you mean by your "Social Capital"). As for your friends ... well, the term "fair-weather" was invented for a reason ...
Re:Homeless Proofing Yourself (Score:1)
Period.
Which explains a lot about the new breed of essentially Randite dotcommers... and what happened to them when Darwin turned out to be real, and not everybody could win.
Which is not to say all those merrily heartless libertarian extremists turned out to be hypocrites- I am sure there are a lot of them sleeping in their cars because by God they're not taking charity! Better to die alone than to bow to others!
It's just that... well, they can be sincere about that as much as they want, but I still can't help but think that SOCIAL NETWORKS ARE GOOD. They are how civilization has got along for centuries, for thousands of years. Scorning that seems like a singularly stupid and unhealthy attitude.
So, if the dotcommer Randites are determined to die in the back seat of their cars from starvation rather than concede the inadequacy of selfishness as a social mechanism- maybe that's a good thing. You could almost call it Darwinian...
Re:Homeless Proofing Yourself (Score:1)
Part of me believes this is a crass and depressing way to look at it but another part appreciates how sensible and pragmatic it makes having friends sound. Maybe I should get me some.
Coming to a Slash Dot near you (Score:1)
~^~~^~^^~~^
Good news for Indymedia? Not nescessarily (Score:2)
To be honest, my impression of IndyMedia is that they are just as biased, if not more so, than the mainstream media they want to subvert.
--
Re:Good news for Indymedia? Not nescessarily (Score:2)
But frankly, indymedia's bias is why I read it (though not as regularly as I used to). You're unlikely to find truly neutral journalism anywhere, so why not at least find a couple of sources whose viewpoints are clear (and preferably at odds)?
Impossible (Score:2)
Ships are all "she"s.
__
Re:Homeless Proofing Yourself (Score:2)
FYI it isn't against libertarian beliefs to give or receive (or ask for) charity. It is against libertarian beliefs to force someone to give "charity" (quoted here because it isn't really charity if it is taken by force). So giving $5 to a homeless guy on the street is fine. Running a soup kitchen is fine. Going to one is fine. Taking 26% of someone's wages and using it to fund all manner of things including aid to the homeless is not so fine. Not because of the things funded by that money, but because it is taken, not offered up freely.
Likewise asking someone for $5 so you can eat is OK. Telling someone to give you $5 so you can eat, or you will stab them in the eye is not OK.
Re:Homeless Proofing Yourself (Score:2)
One is a hypocrite for wanting to change from a involuntary system to a voluntary one? As far as I know most libertarians (they prefer little l) don't claim to currently be living the live they want too (i.e. are not a person who puts on a false appearance of virtue or religion). They would like to privately fund schools, highways, and most want to fund national defense with excise taxes (I think). They aren't going and claiming that they are doing it, or otherwise falsely asserting that they are currently are not benefiting from the taxes of others.
It would be rather hard to not do so since there is no alternate method set up to account for everyone's use of government services and pay for them.
I don't think the often quoted libertarian idea of almost no government is attainable. But I do want one radically smaller then the existing one. At least on the federal level. At the state level my feeling are much more mixed. I know that would increase the local state taxes quite a bit because a lot of the funding for state works comes from the feds, but it would also increase the likelihood of being able to find a state that offers roughly the services you want for roughly the taxes you are willing to pay. Currently it is all but impossible because so many services are actually payed out of your federal taxes...
Re:Free alternative to ZKS Freedom? (Score:2)
--
Re:That Sinking Feeling (Score:2)
IOW, egos did 'er in.
--
Re:Hype, hype, hype, hype, hype (Score:1)
Try telling several million semi-clueless IIS admins on pissant corporate web sites all over the world who will be cracked over the next year or so that outrage over IIS's inexcusably woeful code is Hype Hype Hype.
Precarious Timing for Microsoft (Score:5)
Let's face it, every major operating system has security flaws, either in the past or just waiting to be discovered. The benefit of Open Source is not only that it makes it easier for everyone to see its flaws, but it makes it easier for anyone to fix them.
Right now we have Craig Mundie preparing to argue the merits of commercial licenses over Open Source, and having a hole of this magnitude (read the article for details) showing up in closed-source software so close to this debate only serves to make our case look better.
There are times when a closed-source license scheme will work out better for a particular company, and there are times when an open-source one will be better (and I'm only talking in regards to the company, not the rest of society). This security hole will hopefully reduce the FUD level against Open Source software, particularly from a security point of view.
I can't wait to hear the Mundie debate [oreilly.com] next week.
--Cycon
Re:Buffer vulnerabilities (Score:2)
Re:Nuclear Reactor (Score:1)
Ontario Power Generation wanted senior developers, and I thought that it'd be cool to write S/W for nuke plants. I was shocked to hear that they wanted M$ VB programmers
Re:Maybe it's time for Java? (Score:2)
We don't need better programming languages, we need better programmers. Those who try to code too quickly and fail to think about what they are doing are the ones that bring us buffer overflows. And now you want to encourage these same people to code with a language they are told will speed up their programming? They better not be coding anything for medical instruments, airplane controls and navigation, nor any military systems ... even if they are using Java.
Since when was a language able to make up for neglect?
Re:Coming to a Slash Dot near you (Score:2)
--
Oxymoron? (Score:2)
Isn't that a contradiction in terms? I guess in "unlimited futures" savings accounts and wads of cash stuffed into mattresses are "off limits."
--
Makes me chuckle (Score:2)
At my $ORK_PLACE, it's usually the other way around.
--
Re:Remember, Free Software Sinks Ships (Score:2)
--
Re:That Sinking Feeling (Score:2)
--
Re:And Microsoft can't date announcment correctly. (Score:2)
So you see, Microsoft is right in what they claim the date is, and it's a user error that occured during the installation of MS Office Professional that makes it appear incorrect.
--
Chief Hacking Officer (Score:3)
If I were a Chief Hacking Officer, I could make broad assumptions like declaring that each domain that uses IIS only has one computer serving pages for it. I could be in article posted to Slashdot! What more could any sane geek want?
--
Hype, hype, hype, hype, hype (Score:1)
--
Oh, the Irony (Score:1)
Re:That Sinking Feeling (Score:1)
Re:Someone patch that bleeding heart!! (Score:2)
It does. Most people call the thought pattern "blind luck". Most technical people call investing a SWAG (scientific wild ass guess). Face it, investing is no more scientific than betting on sports contest. There are some pretty good indicators that some companies are going to win, but everyone is looking at the same indicators which drives the price of that companies stock higher. Betting (investing) on a 'long shot' will provide better payoffs if that company/team wins, but there's a reason that it's called a long shot.
The best thing I've found to do with my money is to spend it. My kids won't have a big inheritance, and both of us will have to work our asses off to get them through college (why do kids today think they shouldn't have to work while in college is beyond me). But when I'm gone they'll have a lot of fond memories of all the fun we had spending money in the good times, and I won't have to worry about anyone trying to come get their stuff during the bad times ('cause it won't be there). Reckless? Yes, but I've dug ditches before and I can do it again.
Re:Homeless Proofing Yourself (Score:2)
Of course you never went to a public school, don't use any interstate highways, or depend on the U.S. military to keep you safe.
If you do you are a major hypocrite [m-w.com], like most of the Libertarians I know...
--
You think being a MIB is all voodoo mind control? You should see the paperwork!
Dot Com Urban Myths (Score:2)
I'm sure there's plenty of human interest stories in other boom-to-bust industries, but they lack the "magical" elements (massive wealth at a young age, mysterious computer skills) that lend the Dot Com stories their fairytale qualities.
I personally can't wait until these stories join the Chupacabra and Monkeyman in the footnote department.
Re:You need to reword that. (Score:2)
For a second I thought ./ had been compromised again.
I guess that nobody explained to you that Slashdot.org used to be a Microsoft website. Microsoft has simply been too embarassed about having their web sit so throroughly owned that they've never taken it back.
(There is no truth to the rumor that, once Linux was remotely installed on their IIS box, they were not able to bring the system down.)
--
Re:Buffer vulnerabilities (Score:2)
Letting your paying customers find the bugs (and, in some cases, then denying the existence of bugs reported by multiple users), is not what I'd call 'testing'.. I'm not interested in paying big money to be part of an unofficial 'public beta' that never seems to end.
--
A scene from the near future.... (Score:2)
Captain: Frigin Script kiddies....
Weapons Control Specialist: I think they used a Microsoft back door to..
B O O M ! !
--
Re:zdnn sources credibility? (Score:2)
Oh - MS was informed severeal weeks ago???
--
Re:Good news for Indymedia? Not nescessarily (Score:2)
Then again, spending the better part of a day removing posts about the (non)'raid' was a surprisingly effective way of igniting interest about the story while keeping with the spirit of the order.
In any event. The FBI probably dropped the case because they were almost sure to lose it on appeal. The sweeping nature of the court order was bound to be seriously questioned by any upper court, and given that the original order was for a non-existant IP address, they would need to ask for a material change to the order to be able to wrest any data from I.M..
On the other hand, if the intent of the order was to provoke disorder and chaos at I.M. in the middle of the summit, it has achieved it's purpose and outlived it's usefulness. Keeping it alive would cost the FBI lots (both money and PR), while gaining them little beyond the damage already done.
It really seems to me like the last was the real intent of the order. Consider that it was dumped on them in the middle of the Quebec conference, referenced an unused IP address, a foreign crime and non-existant posts, while demanding that a site dedicated to getting news out to the public to not tell anybody that everything that they had done for the last 48 hours might be handed over to an organization famous for previous anti-activist activity.
When I think about it, it's actually possible that the FBI was really probing the organization, and hoping that they would breach the gag order. If they had, then the FBI would have had an excuse to shut down the whole operation even though they had done nothing else illegal. This is not too far from a tactic often used in Canada (esp. BC).
--
Re:Holes in MS Software (Score:5)
Microsoft has been releasing software with good, refined code ever since they used BSD code in Windows.
Devil Ducky
Re:Remember, Free Software Sinks Ships (Score:1)
Re:Someone patch that bleeding heart!! (Score:4)
Buffer vulnerabilities (Score:1)
Re:And Microsoft can't date announcment correctly. (Score:1)
Re:Buffer vulnerabilities (Score:1)
please spare me (Score:2)
And I suppose news from agencies which filter out the important parts are better than Indymedia. Take a look at Jim Bell, the judge scared the media, and the media shoved their tails up their asses and stood silently as Bell was shafted.
Take a look at the McVeigh trial, where did the media go when John Doe news was brought about from the beginning? What about CNN's actions during the Gulf War... Sure allow the military into the company to monitor what gets reported.
Sorry sir I would rather have all forms of news to look at instead of believing what I'm fed, especially from normal news agencies which break under pressure by Big Brother's bully tactics.
I don't see why the FBI backed off. Secret documents were stolen, and it's important to find out where they came from, lest the next stolen documents result in murders and chaos.
It's likely they backed off because they didn't have a case to begin with jackass.
Indymedia supports violent actions. Witness how they moan and cry about police trying to maintain order in Gothenburg, Sweden last weekend, ignoring the 50 injured officers and 5 dead horses that
resulted from anarchist riots in the downtown core. The "collective" doesn't seem to give a shit about the one officer that got nailed in the head by a rock, knocking him unconscious, but you'll hear no end to the bitching about the attacker who got shot by fellow officers in self-defence.
Hypocrites and suburbanite bleeding-hearts, the lot of them. They don't deserve sympathy, and they
don't deserve pity.
Your post means absolutely little. I read IndyMedia, and feel no need to go out and hurt anyone asshole.
New World Disorder? [antioffline.com]
Re:Maybe it's time for Java? (Score:1)
Incidently, you could also code a variable length string type in C, and provide functions to access it, like vstrcat, vstrlen...
Re:Free alternative to ZKS Freedom? (Score:1)
I'm not just asking to be annoying, I'm actually curious if there's a way to do this.
Or the simple fact: (Score:2)
Not to say buffer overflows aren't major, but it's not like one is typically any bigger than another. Whether you can throw a cat through or a mouse, is all up to the media and (l)user hype.
Sorry. Just another one of those rants I guess about making mountains out of molehills.
Jason
Privatized Vocational Rehab (Score:2)
I wonder when the privatized prisons will get around to selling the labor of programmers who have been incarcerated for violation of /PL\d+-\d+/ and then having Salon "journalists" writing about how this is simply "rehab" for young men who needed guidance anyway? It would certainly appear to be a great boost to the economy to be able to compensate young programmers with rooms in the portions of the "facility" not populated by gang-rapists. That way you don't have to give them actual Federal Reserve Notes -- greedy neurotic little bastards that they are.
Re:Precarious Timing for Microsoft (Score:1)
Or proof that I'm a paranoid conspiracy theorist.
Homeless Proofing Yourself (Score:5)
My response: "What do you mean WE?"
You need to have to burn a lot of bridges to actually end up in the street. You have to lose your income, your savings, your friends (or the goodwill of your friends) and what might be called Social Capital.
The trick is to have a lot of bridges to begin with, and to keep them from catching on fire.
Most of this will sound utterly obvious to nearly all of you, but you've got to reserve money (for upcoming bills and insurance payments), save money (for no particular purpose . . . a rainy day fund), be absolutely fanatical about paying off your debts, and stay in good with friends and family.
Short of a natural disaster or major crash, someone who does this won't end up on the street or "car camping."
And if there is a major crash, think of the great blues songs you can write! "Once I built a network, made it run, . . ."
Stefan
Re:Someone patch that bleeding heart!! (Score:2)
Thomas Jefferson died broke and deeply in debt. I guess he made some really poor choices, didn't he?
Er... (Score:1)
Analysts are also jumping into the fray, warning consumers and businesses that Microsoft's latest round of products has problems.
"latest round"?
-Legion
Re:Coming to a Slash Dot near you (Score:2)
-Legion
Re:Remember, Free Software Sinks Ships (Score:2)
-Legion
Re:Free alternative to ZKS Freedom? (Score:2)
In fact, netblocks housing such servers would very likely end up on the RBL, never to be removed (until our ISP's TOS us).
Re:Homeless Proofing Yourself (Score:2)
Sacrosante aside, since he turns out to be non-representative, there seems to be a misperception about the dot-com boom/bust. The dot-coms were not generally full of techies. The most extravagantly doomed dot-coms gorged themselves on marketing and sales folk. They were not likely to be Randites - more likely fuzzy liberals in typical San Francisco style.
Not that I'm claiming a belief in Ayn Rand saved anyone from the axe - on the contrary, when a company sank everyone was laid off. If I really thought any talented techie was homeless out of sheer pride and refusal to accept aid, I'd have great respect for his choice and confidence in his future success. However, it all sounds very much like an urban legend.
3am. What time is Java? (Score:1)
Think of Moore's Law - 18 month doubling times.
If Java puts a 100% overhead on execution times (an excessive estimate), then it's the performance equivalent of shipping your product 18 months later. If your schedule speeds up (because Java codes faster than C++) and the debug time decreases (because Java source is less buggy, and debugs much faster than C++) then you may find that the overall saving approaches a useful fraction of the 18 months, or at least enough of it to have your users live with the slowdown.
C++ can rot in hell (or Redmond, which is plug-compatible), as far as I'm concerned. If I can code it in a loosely typed scripting language like J[ava]script or Python I'll do that, and if I can't then I'll do it in Java.
I also work heavily with XML and RDF. You just don't want to think about doing that in C++ !
Re:Maybe it's time for Java? (Score:1)
We don't need better programming languages, we need better programmers.
I consider myself a "good programmer". I still code buffer-overflow bugs, but I just mark them with comments as "Fix this later". I'm good because I know what I'm doing wrong, when I do it. I'm bad, because I still don't have the project timescale to code it all "properly" on any project I've worked on over the last 10 years.
If you want reliable bounds checking, then you have to have it supplied automatically (i.e. Java). There's no time in project schedules for coding it by hand.
Re:Hype, hype, hype, hype, hype (Score:1)
Languages which make it easier to use variable-sized buffers are a lot less subject to this problem, and Java (for example) is quite literally immune to buffer overflow exploits. C# will also be immune to such problems short of using the unsafe keyword.
(Naturally, when I say "immune" I'm referring to the facts that A) no real programmers use fixed-size buffers in these languages, and B) even if they did they would be unable to write past the end of the array)
Re:Indymedia Supports Criminals (Score:1)
Not true. 20 police officers were injured, no dead horses, three civilians (protestors) shot and citically injured. And they were not riots per se, they were protests which got out of hand. Now do you see how important it is with multiple news sources?
Nuclear Reactor (Score:1)
Re:Maybe it's time for Java? (Score:1)
Running everything in a sandbox could accomplish the same thing, and you wouldn't have to re-write all your code. There's nothing about the Java language itself that prevents overruns. How many times has your VM thrown a pointer exception? The important thing is that the exception is caught and handled. Of course, if they did start writing system code in Java they would want to compile it to the native machine, and then the security is still only as good as the quality of the code generated by the compiler. There is no magic bullet.
Re:Hype, hype, hype, hype, hype (Score:1)
Re: Funny... (Score:1)
Oh, give me a break. Do you remember, off the top of your head, the content of every e-mail message you sent over a year ago? (going by the date of the linked article, 2 Nov 1998, versus the date of the mentioned message, 8 Aug 1997). I'm talking about people leaving out details of an article they just saw and could refer back to when they made the submission. I highly doubt Bill had access to his sent-items archive during the deposition.
Funny... (Score:3)
I wonder how many of those other submitters also conveniently "forgot" to point out that the article [msnbc.com] specifically mentions that a patch [microsoft.com] was released yesterday.
Re:You need to reword that. (Score:2)
Holes in MS Software (Score:2)
I posted this [yahoo.com] Yahoo! article describing the flaw, but it was first posted at news.com [news.com]. Really does it suprise anyone? Now what about the poor network admin who isn't keeping updated with latest bug news, and still has the old version a month from now?
You need to reword that. (Score:5)
For a second I thought ./ had been compromised again.
Re:Oh... (Score:1)
Using Windows NT [...] on a warship is similar to hoping that luck will be in our favor.
Listen to the man, he's obviously an expert :)
Re:fast post (Score:1)
indymedia support for free software (Score:1)
And Microsoft can't date announcment correctly... (Score:2)
At the time I write this (11:12 am Australian Eastern Standard), Microsoft's announcement [microsoft.com] of this vulnerability at was dated May 18, not June 18.
Sheesh.
No no thats OBVIOUSLY not what he meant (Score:1)
Re:Holes in MS Software (Score:1)
That Sinking Feeling (Score:2)
The first factor was a design flaw. She was designed to float with any two compartments totally flooded. They could have done better by extending the bulkhead walls higher, but nobody could conceive of a collision that would flood more than two compartments. But if you head straight at an iceberg and then try to turn at the the very last minute...
The second factor was overconfidence. "Oh, the people who built this ship have thought everything through! There's no reason we can't go at flank speed through an iceberg field!"
Fallible engineers and blind faith in technology. Not a problem any more, right?
__
Re:Hype, hype, hype, hype, hype (Score:1)
I't the only other serious "system language" I can think of...
Of course, nobody codes in Lisp except academics, but thats another enterily different matter.
Mmm-hmm. (Score:1)
Translation: "Don't blame us for bad security out-of-the-box, we can't do anything about it," or, "it's the fault of sysadmins who use IIS".
(Also, note that "Microsoft worked for the past two weeks with eEye Digital to develop a patch," whereas Apache, the world's most popular web server, for good reason, is community-supported and -developed.)
Fear and Loathing in San Jose (Score:4)
In part (it is a long and thoughtful read):
In the story, a couple of consultants/network guys wound up in a shelter because they lost their jobs and couldn't pay their bills. One had a 100K a year job, the other a steady 60K consulting gig. These men caught the fear and it has swept them into the gutter. Is the idea of being young and homeless scary? Sure. But here are some factors people have to consider before embracing the fear. Why? Because the fear is a powerful thing. Once it has a hold of you, it owns you. You can't think, can't do anything but absorb the fear and let it control you. Why is the fear spreading so fast, based on ONE article? Because it could be anyone. It was as if everyone now had permission to be scared about their future and all of a sudden, all that liberterian thought they had sucked down was not working. The possibility of poverty, or a quick trip back to 1992 was not what they expected after the boom. And the fact that it's here scares people to the core. There's no work, there doesn't look like there's going to be any work, and people don't see a market for their skills. No more trips to Europe, no more unlimited futures, no more foosball in the office. No more office. But let's look at the circumstances of that article more closely: "
And it goes on.
a pretty good look at the psychology behind why the story struck a raw nerve in folks
Check out the Vinny the Vampire [eplugz.com] comic strip
Re:That Sinking Feeling (Score:1)
Re:duh (Score:1)
Blockquoth the AC:
And who's to say that the same level of anonymity couldn't be implemented without ZKS? It's not like they're the only ones with skills in the field of cryptography.
b&
Free alternative to ZKS Freedom? (Score:3)
The basic idea behind Zero Knowledge's Freedom project is that your traffic gets pooled (in a cryptographically secure manner) with that of the rest of their customers in such a way that all anybody (but ZKS) can discover is that one of their customers is doing something.
It would seem to me that a cooperative group of people could accomplish much the same without too much trouble: set up an IPSEC WAN and a bunch of proxy servers that only speak to clients on the private side of the network. Use DNS load balancing, and all you know is that a request is coming from a participant of the WAN.
ZKS also offers psuedononymous email, web server profiles, newsgroups posting, etc--all very good. But there's no reason the cooperative couldn't provide similar functions.
ZKS runs the servers that do all the heavy lifting. In the cooperative, all the members would provide a piece of the heavy lifting.
Yes, I'm painting with a broad brush here, and even I could start to pick holes in the way I phrased some of all this. But, I think the basic idea is sound: rather than rely on a company like ZKS to do everything, have everybody chip in, even if it's just to share some bandwidth and CPU cycles. Surely if we can all cooperate sufficiently to create a number of operating systems--even if the form of cooperation is nothing more than using them--we can also cooperate to protect our privacy?
b&
interesting slashback pairing.... (Score:2)
How much longer will it be till free market conditions start to force MS to shift its balance from flexibily/interoperability towards security?
notice who they blame (Score:1)
Re:Free alternative to ZKS Freedom? (Score:1)
If you just reroute some of the tsaks you get to some random hosts, your adding a layer of anonymity, but the network traffic is incrased by this.
You have to assume every single node as hostile but it's pretty safe to assume that they are not all from the same party.
Remember, Free Software Sinks Ships (Score:3)
actually, now that I think about it, i'm pretty sure there wasn't much in the way of software back then either....
And you guys talk about Slashdot stories not getting researched enough!
zdnn sources credibility? (Score:2)
ZDNN: On that basis, Microsoft scores highly for its response, said International Security Systems' Rouland.
"If you compare the speed at which Microsoft responds to these vulnerabilities, it's incredible," he said. "They get through with the information and the fix much quicker than you'd see with open-source software."
(emphasis mine...)
Fair to say that M. Rouland just scored a huge A+ in my "troll of the year" quest...
But does someone knows what the hell is International Security Systems, except a lame sounding name?
The closest I could find is a Christopher J. Rouland working for X-Force @ Internet Security Systems (xforce.iss.net [iss.net])...
You answered your own question (Score:1)
When customers stop paying for bad code. You said it yourself: companies are just trying to come out with the most features the quickest in order to try and make more money. And they'll keep doing that until people stop paying for it. Why should MS stop if its customers are happy, or at least happy enough to keep buying their software. Definitely by this point companies should be asking, "Why are we putting up with all this security crap from MS? We like the OS, but IIS has had too many security holes." And they should look elsewhere for internet server software.
But MS customers are not. Their sales go up while their number of flaws go up. And until people stop paying them for bad code, MS won't beef up the quality of their software.
---
Re:notice who they blame (Score:1)
Re:Funny... (Score:2)
Then I said "Can you tell me the address? I'd like to test a remote adminstration program called jill.c that could bring up a C:\WINNT\SYSTEM32\ prompt on my xterm."
He told me this was impossible to hack his server as he has already applied the lastest services patch. Nevertheless, he excused himself and ran back to his office after seeing me grined evilly.
The lastest services patch is not good enough, but I wonder there aren't too many admins there keeping up with the latest hotfix.
 _
Oh... (Score:4)
Helping the homeless (Score:1)
Dancin Santa
Re:Helping the homeless (Score:1)
Dancin Santa
MS-Bug... (Score:1)
I think it's saying Windows 2000, Windows NT or beta versions of Windows XP are default components of IIS and have bad bugs.
Suprised? not really.
The security flaw is the second in as many months for Microsoft.
I'm noticing a trend with what MS produces.
Analysts are also jumping into the fray, warning consumers and businesses that Microsoft's latest round of products has problems.
Which round of products didn't have problems?
--
Re:Good news for Indymedia? Not nescessarily (Score:1)
But now that the FBI has withdrawn their probe, they revert legally back to the status they held previously. They aren't being treated as journalists, whatever they'd like to think. The only way they would have gained that is by winning the court battle for which they were gearing up. Someone at the FBI must have read 'The Art of War"... the feds just deprived IndyMedia of perhaps their most valuable weapon by avoiding conflict with them.
Another thing... from reading the press reports sent out by them (I'll freely admit I don't frequent their site[s]), it seems an extreme stretch to call everyone who posts a story a 'journalist'. You could make the same case for /. posters. I think the bar ought to be a bit higher than they set it at IndyMedia.
It's evolution at work (Score:3)
Clearly this is a perfect strategy: Those ship-based NT systems that are less reliable will drown while those that work will survive to breed with other ships thus improving the species....
Simon
Mod this UP !!! (Score:1)
Excellent.
Re: Funny... (Score:2)
Re:Buffer vulnerabilities (Score:5)
Then there's proper unit testing, which should include full coverage testing. Unit test should be written so that they provide all sorts of legal and illegal input. Most software shops do not have the resources to do this properly within their deadlines. They might fore up the tools if they see som insane memory leaks or if the program crashes.
But again, I'd think Microsoft has all the resources they need. Judging on the poor quality of their software they probably have figured that the (lack of) quality of their software has no detrimental effect on their sales, so they probably leave the testing to GUI monkeys, and hope for the best. Even a 0.5 trillion $ company can make a few bucks extra by spending a few pennies less.
Quality isn't the point (Score:3)
Now, I don't think they will, because it would cost a lot of money and not make them much. They know their priorities - make money and dominate the market - and they know how to achieve them. They won't work hard on quality until we really start cutting into the desktop market. And at that point it will probably be too late.
My point is, quality is not now and never has been the point of free software. It is an important point for open source, which is basically about getting business to try free software, even if it's not all that free. If you're trying to convince executives who don't give a rat's ass about freedom, you have to put it in terms they can understand. The open source movement has gotten a lot of people to open up their code and use other people's free software, who otherwise would still be dismissing GNU as a bunch of left-wing wackos not living in the real world. Which they decidely are not, but sometimes you have to take a lateral approach to make people see that.
Free software is, and always has been, about freedom. The fact that it tends to result in better quality code is a fortuitous side effect. It's not the reason it exists, and it's not why I use it.