Comment So apparently.. (Score 3, Funny) 206
What DECAF giveth, DECAF taketh away.
What DECAF giveth, DECAF taketh away.
I'm a resident too, and I love this city to death, but I also know too well about Toddler Stroger and his antics.
When you say "local sheriff", it makes it sound like he's the sheriff of some small town. In fact, Tom Dart is the sheriff of Cook County, which contains Chicago, is the second most populous county in the U.S, and his department is the second largest in the U.S.
People claiming Dart is drumming up publicity are pretty much correct. Keep in mind, we're talking Chicago here, so consider the history of the political machine here. Dart also refused to evict renters from houses when their landlords lost the mortgage. In a way, this is an honorable thing to do, but the way it played out, everyone read it as once again more publicity for Dart. The Craigslist case just further proves his motives.
Does anyone else worry about sending sensitive information over a service like Twitter, which has had security issues in the past? And, assuming this works over DMs, what if a user instead accidentally uses a reply or just a straight Twitter post? What sort of information have they just inadvertently exposed?
You have to wonder why this kind of thing can't just be easily implemented using Twitter's API, instead of having to pay them for it.
Aside from the usual gripes about the efficacy of pen-testing, this gives pen-testing a bad name. The firm I work for does this exact same ploy, and so do teams from the Big 4 and various security firms, but they are always planned ahead of time. You have to do this sort of thing in a controlled manner (or as controlled as possible.) Usually, these things are dropped in a parking lot, the the payload is innocous, because a customer (or member in the case of a CU) can pick it up. These guys exposed themselves to a lot of liability and can screw it up for honest hardworking sellout hackers such myself and others.
Hasn't FlightStats.com been doing something similar for years, just without the trendy technologies?
I wonder what kind of Internet connection they have there?
So, sex offenders aren't allowed to use LinkedIn, but they're allowed to use AIM, Yahoo and chat rooms? Interesting approach; this is what happens when the government tries to regulate something they know nothing about, and take the easy approach of using overarching, way-too-generalized statements.
Please tell me you don't seriously think they did this to get away with not paying for parking.
I am guessing this was meant as a troll/joke, but, you may to actually put a real command in there.
Did you bother even reading the article? The code is in httpd.c, which obviously handled both types of connections. I almost hate SSL sometimes because people equate it with security -- but not encryption or integrity, but that somehow it's a magical fix-all for whatever the security flaw is. I see this kind of thinking in IT people in charge of the enterprise and it scares me. Security is not about having a setting enabled, and it certainly requires much more analysis than a simple dismissive suggestion.
TrackIt! seems to be very popular with my clients, but it is a commercial tool and may be overkill for your needs. Still, it may be worth a look.
But there have been many browser exploits recently, and they've been in virtually every component of the browser. This flaw has nothing to do with JavaScript itself, just the implementation. Flaws have been found in XML and HTML rendering engines, third-party components, URL handlers and many other pieces of the browser. If we're going to disable every feature that's potentially vulnerable, we might as well stay off the Web.
In my humble and largely anecdotal experience, Postini works well. We send out e-mail that can often be flagged as SPAM when we perform penetration testing, and Postini seems to be the toughest to get around. We see in-house devices such as IronMain, and outsourced services such as MXLogic and FrontBridge/hosted Exchange, but Postini seems to do the best at stopping illegitimate messages. The company I work for uses this it as well, and logging into my Postini inbox I see a lot of spam but no false positives. I think it's a pretty good solution if you don't want to handle SPAM in-house.
Remember, UNIX spelled backwards is XINU. -- Mt.