Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!


Forgot your password?

Comment Re:What is the point of OSX server? (Score 4, Interesting) 365

docs were read. mass-googling was done. I'm talking about apple's utilities... `networksetup` in the instance of the LOM and the network port bonding. There's no consistency in the docs about what they mean by "Service Name" which is what they call the "interface." However, there are 2 names for the interface... the user-specified one ("Ethernet 2") and the bsd name ("en1"), but the docs call them both the servicename. The only way I was able to figure out which gets used where is by trial and error.

in many cases, apple has provided their own tools that completely replace the standard toolset. hdiutil and networksetup are 2 prime examples.

another thing I forgot to bring up is ipmitool which mostly works unless you try to do serial-over-lan (sol) connections; it's completely unusable and you have to go to sourceforge and build your own ipmitool to do that stuff.

I mean, I'm not an OSX n00b. Typically I'm a linux engineer, but I've been OSX on the desktop since the developer previews and the server I've had running at home for a while and I've done contract server set up on versions going back to jaguar... the thing is that this is the first time that I've had to do seriously low-level shit (building a large xserve infrastructure with customized management and deployment tools) and it's like running into a concrete wall headfirst every time a new task comes down the pipe.

Comment Re:What is the point of OSX server? (Score 4, Interesting) 365

Apple has no real interest in the enterprise market.

And this is terrible news.

Content providers for apple MUST provide video files in Apple ProRes fileformat which is ONLY able to be encoded using apple's tools which only run in OSX. I don't know how apple expects large content producers to encode high-volumes of videos for them without the xserves. MacPros are not an option as they are not enterprise ready (single PSU, no management port, they're HUGE and must be de-"racked" in order to swap drives, etc). MacMinis are not suitable for this as they don't have enough CPU/RAM. The xserves weren't even that great, but they were the right form factor.

Apple's been seriously fucking up with regard to the enterprise lately. I've been running into issues with their commandline admin utilities --they don't give access to everything that you can do with the GUI. You can't configure which port to use for management from the CLI (the docs say you can, but it doesn't work), it renames your interface when you bond network interfaces by appending " Configuration" to the name, which doesn't happen in the gui... and now, 10.6.6 doesn't properly image using System Image Utility (http://support.apple.com/kb/TS3665)

Now, they're bundling OSX Server into OSX Lion. Who knows whether they'll continue to support ALL of the non-home user features of server like OpenDirectory. WTF.

Comment Re:Cool idea (Score 1) 286

apple's mobileme has had this since at least 2003. It was the one feature (but not the only reason) that has kept me from migrating my email over to gmail or other provider. They have an email aliasing feature which allows you to not only create new aliases for your main account, but you can choose what address is in the reply-to field in Mail.app or through the web app.

This has been great since I signed up for MobileMe (then, .Mac) in 2000 when I was 19 and used spike666 as my moniker, and was able to use a more professional name when the time came without needing to create a separate account.

I really wish gmail would add that. There's no way to change my google account's login (according to their faq) and I'm not about to get a new account and lose my entire search history and everything else that's tied to that account.

I would use an email address on one of my domains, but after having the same email address for 11 years, it's kinda hard to switch.

Comment proper use of hashing algorithms (Score 5, Informative) 217

So this also proves that, ultimately, this list of passwords was not properly hashed.

People jump up and down and scream that SHA1 and MD5 are broken, but if properly used, they still offer significant password security. One trick is to use salts when storing passwords in the database.

password: 'foo'
salt: '2010-11-16T08:39:05Z - some_random_string$#@!'
password-hash (md5): 14e80778512f578a5fe263abe4b58e9c

that increased the amount of time required to brute-force the password significantly. Also, the use of a database of hashes is largely worthless since each password in the list would have a completely unique hash. for the sake of brute-forcing the data, short passwords don't matter (on the other hand, brute-forcing login to the application is not affected). Having a different salt for each password makes the time spent on each other password completely worthless once the cracker gets to the next item in the list.

to improve that, we can say... hash the result 1000 times in a row. For someone trying to brute force the hash, they would spend 1000x the CPU resources creating the hash. It's mostly not a big deal to run that hash 1000 times when creating the information for the database or authenticating the user.

of course, SHA1 and MD5 are still broken when it comes to file integrity checking (when it comes to tampering) since there are documented collisions. For this case, cryptographic signatures are where it's at. You can guarantee that not only was the file not tampered with, but also that the person who supplied the signature was who they say they were. Gotta love public key encryption.

Comment Re:What automobile ? (Score 1) 1141

hooray for public transportation!

since moving to NYC in 04, I haven't had a car and it's AWESOME. no more insurance, worrying about people breaking in, parking, oil changes, cleaning it, gas, etc etc etc.

plus I walk like 10x more than I used to. it's great.

I'd get a bike, but I've been hit by a car on my bike in the past and I don't want to deal with that again. I value my safety too much.

Comment Re:IE? Seriously? (Score 2, Insightful) 142

The worst thing is that, when it comes to upgrading their browser, their assumption IS valid. They shouldn't HAVE to install a 3rd party browser. I'm not saying that there shouldn't BE 3rd party browsers, but the browser that comes with your OS should at least work properly.

One of my semi-techie friends saw those Chrome commercials and said to me "you told me that google was NOT a browser, but look, it is! You don't know what you're talking about!" I seriously think that it's a conspiracy to confuse consumers lately. Between confusing branding (Motorola Droid vs HTC Droid Incredible vs Android OS vs "Droid Does" and this whole 4G thing) and confusing metrics that are difficult (if not impossible) to explain to non-technical users (4MP vs 8MP camera, it's possible that the 4MP takes better pictures... and the difference between 4" and 5" display, when the 4" has higher pixel dimensions). And don't get me started on the difference between a fast internet connection, fast network connection, fast computer and fast browser.

So now you have uninformed users throwing terms around that they think they understand, you've got companies leveraging these misunderstandings to sell overpriced, sub-par electronics, and all these inexpensive electronics that you buy every year that are incompatible with each other (chargers, data cables, etc).

Keep consumers in the dark and confused so you can sell them whatever you want.

Comment Re:IE? Seriously? (Score 1) 142

Although I still feel that way, I've been forced on several occasions to make things look and function in IE (8 or newer only, luckily). One customer hounded us to get their site working in 6, and after we spent a week building a system to detect the browser and output different HTML and were only 1/2 done, they changed their minds.

It's sometimes difficult for non-technical customers to understand that each version of IE is a different beast and requires you do do much of the front-end work over again for each version.

If it was up to me, I'd just say that we don't support IE, but a good chunk of windows users on the public internet have not installed an alternate browser. I just don't get it.

Comment Roller Coaster (Score 1) 422

My old Nokia fell out of my pocket whilst riding the roller coaster (Medusa) at Six Flags. It fell about 30 feet onto the sidewalk and the only issue with it was that the casing kinda split a little and the bottom 4 rows of pixels on the screen stopped functioning. I stuck some tape on the thing and it kept chugging along for about another 6 months before finally failing.

Comment Re:hmm (Score 1) 381

I have a feeling that this part hype, part inept programmers who don't actually understand SQL, or database optimization.

This is part of the problem... similar to PHP, most people learn some examples that teach some bad habits right off the bat (sticking SQL in your view, etc) because it's so easy to get started, but you've gotta get a grasp on the tech before you can do anything big.

Also, I feel that one of the root causes of the hype is that SQL and RDBMSs in general don't solve all your problems and sometimes get in the way of your application design. Between rigid schema definitions and the SQL language that has a bit of a learning curve when you start dealing with nested queries and handling shards/partitions/etc, I think that's the reason we're starting to see more non-RDBMS databases.

At work, we had a project that we started building on MySQL, but was falling short because we were constantly making schema changes. We begun to build a system where we could have arbitrary attributes attached to arbitrary objects, but then our queries were getting REALLY nasty. We discovered MarkLogic which is an XML database server and uses XQuery to query the data. We were ingesting around 100MB of XML a day, and we needed to be able to handle just about any XML that went into the system. MarkLogic was a natural fit since we needed to put XML in and we wanted XML out most of the time.

We're still using MySQL for tracking the ingestions and managing the frontend to the system (which is built on Rails), but having XQuery at our fingertips has been a godsend.

There's a lot to be said about new technologies that solve needs and get around shortcomings of the more ubiquitous technologies, but, as with anything that people see as a solution, it's not a silver bullet. You've gotta be careful not to get trapped in "everything looks like a nail" syndrome.

Comment Re:Warning Bell (Score 1) 173

It really depends what kind of service(s) you're launching on the cloud. If you're building generic infrastructure to cover some area of the market that AWS doesn't cover well or at all, then you may be in for a rude awakening in the future. This doesn't mean that such a service should not be built, it's just that one should realize what kind of risks are involved when developing something like that.

There are plenty of services that build on top of AWS that will probably be safe from competition well into the future. Those include services that are very specific such as Heroku's Rails app hosting, which will actually benefit from additions such as this MySQL instance type and the price cuts of EC2.

Also, when building apps that essentially turn you into a reseller of AWS services, although there may come a time when amazon starts competing directly with you, you've got your app built. If you built it properly, it should not be difficult to re-wire your backend to utilize some other service or build your own cloud infrastructure. If you're big enough and have the necessary capital, it may actually be a cost savings to do such a thing.

Comment Re:First pirate! (Score 1) 762

The "try before you buy" excuse ... Pure bullshit. Honestly, it's difficult to take people that say these things seriously.

Being someone who has done his fair share of pirating, I have another theory about this.

I, and other people I know who pirate games (Xbox360, wii, etc) will actually download and install/burn EVERY piece of software that comes out. I have friends who have binders and binders of games that they never play. Frequently, we play even less of the game than would be available on the demo.

Now, this correlates with the article in that it's only been a week since they released the title and they're having an 80% piracy rate. This is because these people are downloading and installing every single game that's coming out, playing it a bit, then moving on to the next game. Assuming that piracy was unavailable, I doubt that they'd have even tried this game.

I think the guy is jumping the gun on his conclusions and should wait a month or two and post and update on his piracy findings. I'm certain that the numbers piracy rate will drop.

Slashdot Top Deals

Everyone can be taught to sculpt: Michelangelo would have had to be taught how not to. So it is with the great programmers.