Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×

Comment Re:Wny did they need the certificates? (Score 1) 95

Damn right they should. The CPS has a long section on the use of test hardware.

The problem is that all the original team that built VeriSign have been gone for years. A lot of us left before the sale of the PKI business to Symantec. The PKI/DNS merger was not a happy or successful partnership. The original point of the merger was to deploy DNSSEC. that effort was then sabotaged by folk in IETF and ICANN which has delayed the project by at least 10 and possibly 20 years. ATLAS was originally designed to support DNSSEC.

Unfortunately, in PKI terms what VeriSign was to IBM, Symantec is to Lenovo.

They apparently remember the ceremonies we designed but not the purpose. So they are going through the motions but not the substance.

One of the main criticisms I have heard is that we built the system too well. From 1995 up to 2010 it worked almost without any issues. So people decided that they didn't need things like proper revocation infrastructure. The only recent issue the 1995 design could not have coped with was DigiNotar which was a complete CA breach.

There are some developments on the horizon in the PKI world that will help add controls to mitigate some of the issues arising since. But those depend on cryptographic techniques that won't be practical for mass adoption till we get our next generation ECC crypto fully specified.

Comment Re:What is a pre-certificate? (Score 3, Informative) 95

A pre-certificate is created for use in the Certificate Transparency system. Introducing pre-certificates allows the CT log proof to be included in the certificate presented to an SSL/TLS server.

The CT system generates a proof that a pre-certificate has been enrolled in it. The proof is then added to the pre-certificate as an extension and the whole thing signed with the production key to make the actual certificate.

If the CT system logged the actual certificate, the proof of enrollment would only be available after the certificate had been created.

Comment Re:Why the hell would anyone use Go? (Score 2) 185

Why the hell would anyone use Go?

(Serious question, since our editors didn't tell us why Go was created, what Go's intended purpose was and whether or not anyone is actually using Go.)

As a software developer here that likes to fiddle with all languages, the second paragraph from Wikipedia seems to answer your question nicely: "It is a statically typed language with syntax loosely derived from that of C, adding garbage collection, type safety, some structural typing capabilities,[2] additional built-in types such as variable-length arrays and key-value maps, and a large standard library."

So from the first few words someone might know C and desire garbage collection to be handled for them? Golang might be a better selection for them than Java.

Personally for me, the built-in primitives for concurrency make it a great language for tinkering in realms of software design that were once onerous to me. But that's only one of a few of the language's goals.

Maybe a better set of questions would be for an elevator pitch on why someone should use golang? Or perhaps if they have dropped some goals of golang for others as development went forward?

Comment Re:Wisdom of naming it "Go" (Score 2) 185

There's already a game called Go, which has about a gazillion articles on how to program it. Couldn't you come up with a name that would be less ambiguous? Now, when you see a user group for "Go programming", you have no clue which one it is.

In conversation, I refer to it as golang. You are right on your point about potential for confusion but I don't think your example is apt anymore. Googling for programming go appears to yield only results about golang. Also, it is not without tangential benefits like being able to call Go developers "gophers."

I think when I first started programming Groovy long ago I stumbled upon a website promising that software development was groovy ... that's no longer the case when I google for groovy programming resources.

In short the success of your language is a big enough concern than the name of your language is negligible (with the exception of negative words). The search results will follow.

Comment Re:Everyone Is Guilty, Only Enemies Will Be Indict (Score 3, Insightful) 109

If you are a leftist, beating the shit out of private companies is well and good. Remember: corporations are evil! Prosecuting them is only a good thing. Are you a corporate shill?

I am neither a leftist nor a corporate shill. I believe in beating the shit out of private companies that deserve to have the "shit beat out" of them. You need only look at the lengthy history of consumer protection in the United States to find instances where this was and is necessary. Take, for example, Debt Collection Practices. Please, please, please "beat the shit out" of unscrupulous collection agencies. Please "beat the shit" out of the companies that call my grandmother to deliver unsolicited advertisements about a "warranty extension" on her car. There are plenty of private companies that should have this done to them. The issue I take with China's implementation is 1) that it will never target a state owned business and 2) the guidelines are by no means clearly laid out and can be ambiguously interpreted. Who will interpret them? When will they interpret them? Why just in time and by the same state body that made them. Please tell me, how can I prove that my product's advertising does not "Cause detriment to national dignity"?

Comment Do Not Conflate This With Individual Free Speech (Score 2) 109

Communists don't believe in free speech?

Shocking.

It's not that binary. The United States has its own truth in advertising laws that, in my personal opinion, are beneficial at both the federal and state level. Slashdot readers are free to go the Libertarian route and claim the free market would alleviate these issues on its own or perhaps point out how downright pedantic it can be at times. But the truth of the matter is that, as a consumer, we only have so many hours in a day to decide which of the thousands of products we consume in a year we should spend our money on. So it does come down to federal guidelines for what is "Grade A" or "Organic" or "Green" when there is a label espousing these properties and there are consumers paying a premium for this notion. Without those guidelines those words will mean absolutely nothing and there will be no way to tell where your product was made, how much cadmium it has in it or whether it is the end result of spewing carbon into the atmosphere. Without similar laws, you wouldn't be able to trust the nutritional information at the grocery store. Is it free speech to claim that my potato chips cure cancer and lead to weight loss no matter how many of them you eat? People will know that I'm lying? Cigarettes used to sooth sore throats. Trans fats used to taste awesome.

Speech used by an individual to express ideas is free speech. Advertisements -- especially advertisements representing a very large organization -- are not. Corporations should not have the same rights individuals have and I feel that free speech is one of those clear cut distinctions. There is a long history of consumer protection everywhere in the world -- learn about your own country's struggles with it. It's not a simple issue and advertisement should not be regarded as free speech.

Comment Everyone Is Guilty, Only Enemies Will Be Indicted (Score 5, Insightful) 109

Here is the full text of the newly amended law. Here is the WIPO listing the deltas with the older 1994 version of the law (click expand notes). It appears that this is the first change in this law since 1994. Also the WIPO provides a PDF of their English version which seems to be slightly different. I also found a definition of the extent of what is regulated advertising by the PRC. Here's the WIPO's full list of defined restrictions:

1) Overt or covert use of national flag, anthem or emblem of People’s Republic of China or military flag, anthem or emblem;
2) Overt or covert use of the name or image of national public institute or staff of national public institute;
3) Use of words such as “national-level”, “the most” and “the best”, among others;
4) Causing detriment to national dignity or interests, or disclosing national secrets;
5) Interfering with social stability, or causing detriment to social and public interests;
6) Harming personal or property safety, or disclosing privacy;
7) Interfering with social public order, or going against good social norm;
8) Containing obscene, pornographic, gambling, superstitious, terrifying, or violent content;
9) Containing discrimination based on nationality, race, religion, or gender;
10) Affecting protection of environment, natural resources or cultural heritage;
11) Other situations prohibited by laws and regulations.

Merely sounds like another tool for the Party to deal with companies that are not state owned. Most companies will be found guilty of some section of this but they won't be prosecuted until they run afoul of the Party. In China (and increasingly in the US) everyone is guilty of something but only those that the state wants to be prosecuted will be prosecuted.

So looking at the story, we have a new law enacted a month ago and whose head is on the chopping block today? Xiaomi? Well from wikipedia:

Xiaomi Inc. is a privately owned Chinese electronics company headquartered in Beijing, China, that is the world's 4th[4] largest smartphone maker. Xiaomi designs, develops, and sells smartphones, mobile apps, and related consumer electronics.[5]

Aaaaaand there's your problem. Wake me up when a state owned company is prosecuted under these new laws. Xiaomi's true crime was probably doing better than Huawei.

Comment Have We Lost the War to Quid Pro Quo Complacency? (Score 3) 359

Time and time again I see news articles that seem to herald the idea that users are willing to sacrifice something like privacy for the use of software. Take Facebook for an example. You get a robust and snappy storage and website for communication at the cost of control over your life and privacy. And as I try to explain to people the tradeoffs most of them seem to be complacent. Even I myself use GMail, there's just no better mail service. Even if there were, I'd have to run the server from my home to be sure that I'm in control in it and it's truly free (by your definition). So given that much of the populace isn't even prepared technologically to harness truly free software, don't you think they have slowly accepted the trade offs and that the pros of your arguments -- though sound -- are only possibly realized by those skilled enough to edit source code or host their own mail server from their home?

Comment Companies Selling Actually Free Software? (Score 5, Interesting) 359

I found your piece on selling free software to be pretty logical on paper. However, has it ever worked in the wild? Can you name companies or revenues that currently operate on this idea (and I'm not talking about services or support of the software)? I simply can't come up with a widely used monetized piece of software licensed under the GNU GPL whereby the original software was sold at a single price and shipped with the source code -- free for the original purchaser to distribute by the license's clauses. Can you list any revenue generation from that? I must admit I'm not exactly enamored with paying for free software (as in your definition of free) before it's written yet I cannot think of any other way this would fairly compensate the developer.

Comment Baidu Team's Apology Appended to Official Notice (Score 3, Insightful) 94

From the official announcement found in the NYT article (full of details we mostly already know) there comes an update with the team's response:

Message from the team in question:

Dear ILSVRC community,

Recently the ILSVRC organizers contacted the Heterogeneous Computing team to inform us that we exceeded the allowable number of weekly submissions to the ImageNet servers (~ 200 submissions during the lifespan of our project).

We apologize for this mistake and are continuing to review the results. We have added a note to our research paper, Deep Image: Scaling up Image Recognition, and will continue to provide relevant updates as we learn more.

We are staunch supporters of fairness and transparency in the ImageNet Challenge and are committed to the integrity of the scientific process.

Ren Wu – Baidu Heterogeneous Computing Team

So, while they deserve the year ban, the apology is nice. It's a shame we can never know what results a fair competition could have yielded ... and an even bigger shame that the media misreported Baidu as overpowering Google. I suppose the damage is done and the ILSVRC has made the right choice.

Perhaps I'm misunderstanding the classification problem but why isn't this run like most other classification problems (like Netflix and many other data challenges) where you get ~80% for training and the remaining 20% are held back for the final testing and scoring? Is the tagged data set too small to do this? Seems like wikimedia would contain a wealth of ripe public domain images for this purpose ...

Comment Re:You're Talking About a Different Scale (Score 5, Insightful) 276

Frankly put, I'm unaware of "American organized political trolling" that rivals this.

Americans are quick to believe the Official Narrative, no matter how absurd. Mass media is the professional 'troll' that gets people to fight each here.

Again, you're conflating two things that are significant enough that I don't see a simple one-to-one comparison here.

The clear difference here is that the trolls in the article are a nebulous entity whereas the media trolls are not. I know to laugh at Glenn Beck and Katie Couric. I know who they are. I recognize their blubbering stupid talking heads. They're a trainwreck of lies and half truths. On the other hand, you can't stop google from returning search results that confirm what you're looking for. When it's a "trending hastag" on Twitter, you can't figure out if it's legit or not. How do I know that podonski432 on Twitter is the same individual on Youtube named ashirefort posting videos of an explosion is the same person retweeting podonski432 and adding ashirefort's video to their tweet?

Mass media doesn't employ subterfuge and I sure as hell can stop reading the New York Post & Washington Times & CNSNews & Huffington Post and all that other drivel. I can't, however, identify easily that this account on Twitter is just the new troll account that tricked me last time.

You do know that it's news if the New York Times is caught lying or spreading known falsities, right? I watched Jon Stewart hold a "reporters" feet to the WMD fire on one of his recent episodes. There's no self-policing mechanism like that among trolls.

Comment You're Talking About a Different Scale (Score 5, Insightful) 276

It's just about time to drag the American organized political trolling on sites like reddit, twitter, and tumblr into the open too, right?

Well, astroturfing is no new tactic but ... I think what this article deals with is scale. 400 clearly skilled (bilingual at the least) individuals running multiple catfish personalities online day in and day out ... the whole thing on a budget of $400k a month? That level and size is probably unparalleled by ... say, Digg's conservative idiots.

You have one entity orchestrating the 12 hours a day work of 400 individuals on topics that are pro-Russian and tangentially pro-Russian. They are sophisticated enough to "hit play" at a certain time to unfold a natural disaster or assassination or anything to destabilize/confuse a region and they do so over many accounts on multiple social media platforms. They create video, screenshots, websites, etc. And they use proxies and sufficiently sophisticated means to appear to be disjoint at first glance.

They appear to have run an exercise on a rubber plant explosion in Louisiana for no other discernible purpose than to test out their new super powers or demonstrate their abilities to their customers/leaders.

Frankly put, I'm unaware of "American organized political trolling" that rivals this. This is paid. This is tightly controlled. This is prepared. This is unified. American organized political trolling is just a run-of-the-mill monkey shitfight with the occasional Koch Bros/Soros website (usually easily sourceable) thrown in.

Now if you can point me to a faked ISIS attack on American soil right before an election that was done by some political group stateside, I'd be interested to hear about it.

Submission + - Jason Scott of textfiles.com Wants Your AOL & Shovelware CDs (textfiles.com) 1

eldavojohn writes: You've probably got a spindle in your close tor a drawer full of CD-ROM media mailed to you or delivered with some hardware that you put away "just in case" and now (ten years later) the case for actually using them is laughable. Well, a certain mentally ill individual named Jason Scott has a fever and the only cure is more AOL CDs. But his sickness doesn't stop there, "I also want all the CD-ROMs made by Walnut Creek CD-ROM. I want every shovelware disc that came out in the entire breadth of the CD-ROM era. I want every shareware floppy, while we’re talking. I want it all. The CD-ROM era is basically finite at this point. It’s over. The time when we’re going to use physical media as the primary transport for most data is done done done. Sure, there’s going to be distributions and use of CD-ROMs for some time to come, but the time when it all came that way and when it was in most cases the only method of distribution in the history books, now. And there were a specific amount of CD-ROMs made. There are directories and listings of many that were manufactured. I want to find those. I want to image them, and I want to put them up. I’m looking for stacks of CD-ROMs now. Stacks and stacks. AOL CDs and driver CDs and Shareware CDs and even hand-burned CDs of stuff you downloaded way back when. This is the time to strike." Who knows? His madness may end up being appreciated by younger generations!

Slashdot Top Deals

"Here's something to think about: How come you never see a headline like `Psychic Wins Lottery.'" -- Comedian Jay Leno

Working...