Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror

Comment So, let's just fix it (Score 1) 134

So, naturally, I wonder if there's an easy fix to this...

Maybe we can mod the Pi and include the missing resistor (this assumes that the solution is indeed this easy) ?
Or possibly just use a pass-through dongle inbetween the Pi and the USB-C charger that corrects the identification mistake?

I'm keen to see what the hacker hive come up with, since this is a product that is (at least half) aimed for these users.

Comment Is it even worth the time? (Score 1) 184

What's the minimum amount of runtime the script needs before it can return something useful (ie: profitable) ?

If a user comes and goes in 5 minutes, is there any benefit to mining for such insignificant amounts of time?
Or are they hoping some users will leave the browser open and forget about it, allowing the hours of mining.

Comment Why isn't the API secured? (Score 3, Insightful) 80

Putting aside all the victim blaming for a second...

This is meant to be a private (closed-source) application, with a private API interacting to the private server.

Why the hell can anyone (read: unauthenticated users) access private data via a public and unrestricted URL? I've read articles reverse engineering their API. It's terrible! This is another company who did not put enough time and effort into securing the application and API, and now users (read: non-technical, real people, some of which paid money, all of which trusted the company) are left exposed.

I really wish there was a way to force companies (ie: legislate) to place far higher importance on this. I've also been in situations where, as a developer, I've had managers scuttle or ignore requests to lock things down, in the interests of deadlines or cost or worse yet, "we'll fix it once it's up and running."

Comment Turn this into an opportunity (Score 1) 332

Sounds to me that this could provide some good news if Ubisoft wanted to. Instead of disallowing all DRM auth requests for the move period, why not have a cheap server that just authorises all requests for those few hours - legitimate or otherwise. Even extend this free period to be 24 or 48 hours, take the pressure off your server crew to get everything up and working against the clock. You might get people who haven't paid playing the game for free... big deal, after the free period they're disconnected/revoked. If you've planned it well, you could have a big "Buy now" notice appear at the end of the period. Let's see if they can convert freeloaders into paying accounts - surely that's a win/win for Ubi and gamers?

Slashdot Top Deals

If I have not seen as far as others, it is because giants were standing on my shoulders. -- Hal Abelson

Working...