Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror

Comment Unix 'file' is not sufficient (Score 5, Insightful) 74

Sadly Unix's 'file' utility is not sufficient for security purposes. Generally, file only checks for magic numbers near the beginning of the file. Many file formats remain valid, even with prepended data. For example, Python programs with several source files can be archived into a single zip file and still be executed, but you can stick a shebang onto the beginning, and still have Python (or most zip programs) recognise the archive as a zip file. There's a good video on youtube about this kind of thing: https://www.youtube.com/watch?... tl;dr: This is security. It goes wrong in amusing and unobvious ways.

Comment Secure blogging (Score 1) 108

As an alternative (particularly if a DIY type), the OP could write a blog that is presented using only static HTML. I have a fairly simple set of Python scripts that compile a set of pages into a (if you can forgive my lack of visual design skills) presentablely formatted website: http://techmeology.co.uk/ This would avoid the potential for security vulnerabilites that might come from using a dynamically generated CMS like Wordpress.

Submission + - FBI Considers CALEA II - Mandatory Wiretapping on End Users' Devices (freedom-to-tinker.com) 1

Techmeology writes: In response to declining utility of CALEA mandated wiretapping backdoors due to more widespread use of cryptography, the FBI is considering a revamped version that would mandate wiretapping facilities in end users' computers and software. Critics have argued that this would be bad for security, as such systems must be more complex and thus harder to secure. CALEA has also enabled criminals to wiretap conversations by hacking the infrastructure used by the authorities. I wonder how this could ever be implemented in FOSS.
Medicine

Submission + - Most GPs Prescribe Placebos (bbc.co.uk)

Techmeology writes: "In a survey of UK GPs, 97% said they'd recommended placebo treatments to their patients, with some doctors telling patients that the treatment had helped others without telling them that it was a placebo. While some doctors admitted to using a sugar pill or saline injection, some of the placebos offered had side effects such as antibiotic treatments used as placebos for vial infections."
Your Rights Online

Submission + - New Pirate Bay Proxies (torrentfreak.com)

Techmeology writes: "Just days after the UK Pirate Party was forced to kill its proxy service Pirate Parties in Argentina and Luxembourg have created their own proxies. In a statement, the Pirate Party in Argentina said: “We wish the UK Pirate Party best of luck in their continued fight for free access to culture and knowledge. We have put up our own Pirate Bay proxy which is accessible from anywhere in the world, including the UK and other places where it has been censored.”"
Your Rights Online

Submission + - BPI Threatens to Sue The UK Pirate Party over Proxy (torrentfreak.com)

Techmeology writes: The BPI has threatened to sue the Pirate Party for allowing people access to The Pirate Bay through its proxy service. The leader of the Pirate Party UK, Loz Kaye said his party would go to court over the issue. Kaye said that he was determined to defend his party's principles even in the face of an expensive legal battle.
Your Rights Online

Submission + - Automated DMCA Takedown Notices Request Censorship of Legitimate Sites (torrentfreak.com)

Techmeology writes: "Microsoft has sent automated DMCA notices to Google demanding the removal of several legitimate URLs from its search results that it claims were facilitating the distribution if illegal copies of Windows 8, including links to BBC news articles, Wikipedia pages, US government websites, and even Bing! The erroneous DMCA notices are being sent automatically by rights holders, who are increasingly using such techniques."
United Kingdom

Submission + - UK Ministers' Private Communications Subject to Freedom of Information Act (bbc.co.uk)

Techmeology writes: "Emails and texts sent from UK ministers' private accounts could be subject to the Freedom of Information Act, which means copies could be requested by members of the public. New guidelines to be released by the government say that the key factor is "the nature of the information and not the format". This development comes amid a two year dispute caused when a newspaper used the act to obtain and publish an email sent from the education minister's private email address."
Your Rights Online

Submission + - EU Court Asked To Rule On Private Copying (torrentfreak.com)

Techmeology writes: "The Dutch Supreme Court has asked the European Courte of Justice to decide whether downloading copyrighted material for personal use — even from illegal sources — is legal. At the heart of the debate is whether the European Copyright Directive requires that any new legal copy of material must have originated from a copy that is itself legal. The case tests the law in the Netherlands, where copyright holders are granted a levy on blank media in exchange for the legalisation of private copying."

Slashdot Top Deals

You will lose an important tape file.

Working...