Forgot your password?
typodupeerror

Comment Re:In "normal person speak" (Score 4, Informative) 19

In the slashdot post, the words automatically enrich are a hyperlink that point to a guide from NIST explaining the overall CVE process. It has a very prominent section that explains exactly what "enrichment" has historically done for CVE's once they are in the NVD...

The following is a general overview of the enrichment process for a given CVE:

  1. Enrichment efforts begin with reviewing any reference material provided with the CVE record and assigns appropriate reference tags. This helps organize the various data sources to help researchers find the relevant information for their needs. Enrichment efforts also include manual searches of the internet to ensure that any other available and relevant information is used for the enrichment process. NVD enrichment efforts only use publicly available materials in the enrichment process.
  2. A common weakness enumeration (CWE) identifier is assigned that categorizes the vulnerability. NVD enrichment efforts use a subset of the full list of CWEs that best represents the distribution of specific types of vulnerabilities. This subset is known as the CWE-1003 view and was created through coordination with the MITRE CWE team.
  3. CVSS V3.1 exploitability and impact metrics are assigned based on publicly available information and the guidelines of the specification if a CVSS score has not already been assigned. If an existing score is noticed to not be supported by CVSS guidelines or publicly available information while performing other enrichment activities, an enrichment team member may choose to provide a score. Users of NVD data may also request the NVD to provide a score.
  4. A Common Platform Enumeration (CPE) Applicability Statement is associated with the vulnerability. The CPE match criteria are generated to identify potentially vulnerable software and/or hardware for the vulnerability. For example, an application may have several versions affected or must be running on a specific operating system to be vulnerable. Automated processes can reference match criteria within the applicability statements against the CPE dictionary to assist in identifying vulnerable products within an organizationâ(TM)s information system. Every effort is made to identify all vulnerable software, but gaps may exist and feedback is encouraged to improve this information.
  5. Enrichment effort results are given a quality assurance check by another experienced team member prior to being published to the website and data feeds.

Comment "positive impacts" vs "concerns" (Score 3, Insightful) 64

People who sell Face Eating Leopards: "Face Eating Leopards going to have a massive positive impact on society! Everyone should start integrating Face Eating Leopards into every aspect of their daily lives as soon as possible"

People with faces: "I have some concerns about how Face Eating Leopards will impact my life."

Comment How long is long enough? (Score 1) 177

... a long-lasting mouse that could potentially serve customers "forever," ...

I got a Logitech M-BA47 from my work around 1999/2000. I used that mouse continuously, with 10+ different computers, and a new job, until ~2022 when one of the micro switches stopped responding. I could have repaired it, but for only a little more then the cost of the replacement switch I was able to find a "new" (still sealed in box) M-BA47 on e-bay. I kept the old one for parts, but I expect this "new" one to last longer then me. WTF would I need a mouse that lasts longer then that?

Submission + - Facebook subpeona'd for information on a teen's abortion leads to arrest (vice.com)

An anonymous reader writes: In this post-Roe world, the effects of the decision are being felt far and wide. A recent Facebook subpeona reveals that Facebook provided information on private chats regarding abortion. That evidence was then used to seize the girl's computer and phone and the evidence from that used to charge the girl and her mom for performing an abortion, now illegal in Nebraska.
Medicine

Scientists Identify New Organ In Humans (livescience.com) 112

Scientists have classified a new organ called the mesentery, which connects a person's small and large intestines to the abdominal wall and anchors them in place, according to the Mayo Clinic. Until recently, it was thought of a number of distinct membranes by most scientists. It was none other than Leonardo da Vinci who identified the membranes as a single structure, according to a recent review. Live Science reports: In the review, lead author Dr. Calvin Coffey, a professor of surgery at the University of Limerick's Graduate Entry Medical School in Ireland, and colleagues looked at past studies and literature on the mesentery. Coffey noted that throughout the 20th century, anatomy books have described the mesentery as a series of fragmented membranes; in other words, different mesenteries were associated with different parts of the intestines. More recent studies looking at the mesentery in patients undergoing colorectal surgery and in cadavers led Coffey's team to conclude that the membrane is its own, continuous organ, according to the review, which was published in November in the journal The Lancet Gastroenterology and Hepatology. The reclassification of the mesentery as an organ "is relevant universally as it affects all of us," Coffey said in a statement. By recognizing the anatomy and the structure of the mesentery, scientists can now focus on learning more about how the organ functions, Coffey said. In addition, they can also learn about diseases associated with the mesentery, he added.

Submission + - Copyright Troll's Property Seized to Pay Bankruptcy Debts (ktetch.co.uk)

ktetch-pirate writes: Copyright troll firm Prenda may be gone, but one of it's principles — Paul Hansmeier — is starting to feel Karma's burn. In a bankruptcy hearing on the 3rd, Judge Sanberg ordered it converted to Chapter 7, requiring assets be seized and liquidated to pay the 2.5M+ in debts including judgements from courts around the country, as well as proceeds from the sale of Hansmeier's 1.2M condo in Minnesota. She justified it saying he had a practice of deceiving the courts with his extortionate schemes.

Comment Actual Article about it Actually being a hoax (Score 1) 135

This was posted to slashdot after the "go live" time of the app/website, but only links to articles posted prior to the launch that speculated it was a hoax.

One of the authors (Alfred Ng) of one of those articles wrote a follow up piece *after* the launch, with the actual details of what the hoax actually was (A marketing stunt) and what registered users saw when they used the app at launch...

When the website went live at 5 p.m. on Monday, the app asked users to sign in using their Tinder, LinkedIn or create a new account. It matched all users up with a fighter named Dudecati. The user wouldn't be able to do anything but type back at the automated response. At the end of it, the bot tells users:

"ok in all seriousness though you're wasting your time here," and then redirects you to the group's website.

Submission + - This App Lets You Piggyback Facebook's Free Internet to Access Any Site (vice.com)

sarahnaomi writes: In countries like Zambia, Tanzania, or Kenya, where very few have access to the Internet, Facebook is bringing its own version of the net: Internet.org, an app that gives mobile users free access to certain sites such as Google, Wikipedia and, of course, Facebook.

While the initiative has clearly positive goals, it’s also been criticized as an “imperialistic” push for Facebook colonies, where novice Internet.org users will grow up thinking their restricted version of the web is the real internet.

To fight against that possibility, a 20-year-old developer from Paraguay is working on an app that tunnels the “regular” internet through Facebook Messenger, one of the services free to use on Internet.org’s app. This allows Internet.org users to establish a link to the outside, unrestricted internet, circumventing restrictions.

Submission + - Terrorists used false DMCA claims to get personal data of anti-islamic youtuber

An anonymous reader writes: German newspaper FAZ reports (google translated version) that, after facing false DMCA claims by "FirstCrist, Copyright" and threatened by youtube with takedown, a youtuber running the german version of islam-critic Al Hayat TV had to disclose their identity in order to get the channel back online, in accordance with youtube policy. Later, the channel staff got a mail containing a death threat by "FirstCrist, Copyright", containing: "thank you for your personal data. [...] take care your house gets police protection!". As the staff had already suspected that "FirstCrist, Copyright" were in fact islamists, they had tried to convince youtube youtube to find another way, but in vain.

Submission + - 'Police detector' monitors emergency radio transmissions (driving.co.uk) 1

schwit1 writes: Now it’s law enforcement that has nowhere to hide, and that may or may not be a good thing. A Dutch company has introduced a detection system that can alert you if a police officer or other emergency services official is using a two-way radio nearby.

Blu Eye monitors frequencies used by the encrypted TETRA encrypted communications networks used by government agencies in Europe. It doesn’t allow the user to listen in to transmissions, but can detect a radio in operation up to one kilometer away.

Even if a message isn’t being sent, these radios send pulses out to the network every four seconds and Blu Eye can also pick these up, according to The Sunday Times. A dashboard-mounted monitor uses lights and sounds to alert the driver to the proximity of the source, similar to a radar detector interface.

Submission + - Solar plant sets birds on fire as they fly overhead (www.cbc.ca)

Elledan writes: Federal investigators in California have requested that BrightSource — owner of thermal solar plants — halt the construction of more, even bigger plants until the impact of these plants on wildlife has been further investigated. The BrightSource solar plant in the Mojave Desert which was investigated reportedly kills between 1,000 and 28,000 birds a year with the concentrated solar energy from its 300,000 mirrors, charring and incinerating feathers of passing birds. This isn't the first report of negative environmental impact by this type of solar plant either.
Image

Murder Suspect Asked Siri Where To Hide a Dead Body 160

An anonymous reader writes A Florida man currently on trial for murder reportedly attempted to use Siri to garner ideas about where to bury the body of his dead roommate. According to police allegations, a University of Florida student named Pedro Bravo murdered his roommate via strangulation in late September of 2012 over a dispute involving Bravo's ex- girlfriend. According to a detective working the case, Bravo subsequently fired up Siri on his iPhone and asked it "I need to hide my roommate."
Blackberry

BlackBerry's Innovation: Square-Screened Smartphones 139

EthanV2 sends word that BlackBerry, having finally caught up to a world dominated by smartphones, is now trying to push the envelope by developing a smartphone with a square screen. The BlackBerry Passport has a 4.5-inch screen with a resolution of 1440x1440. The phone has a physical keyboard as well. In a blog post about the new phone, they show a picture with it side-by-side with an iPhone and a Galaxy S5 — the Passport is slightly taller than the iPhone, and significantly wider, as you'd expect. The Passport is a play for BlackBerry's "traditional" work-oriented user base, where the earlier BlackBerry Z10 and Z30 were efforts to break into the post-iPhone consumer smartphone space. Though the Passport may well be preferable for spreadsheets and word processing, that square screen will be much less useful for widescreen movies, and its wide, blocky design will entirely prohibit one-handed use. The Passport is expected to appear later this year, and it will launch with BlackBerry 10.3 (at least, according to early hands-on previews).

Submission + - Oracle's attempt to copyright its Java APIs (groklaw.net)

An anonymous reader writes: The remarkable outpouring of support for Google in the Oracle v. Google appeal continues, with a group of well-known innovators, start-ups, and those who fund them — innovators like Ray Ozzie, Tim O'Reilly, Mitch Kapor, Dan Bricklin, and Esther Dyson — standing with yesterday's group of leading computer scientists in telling the court that Oracle's attempt to copyright its Java APIs would be damaging to innovation.

Slashdot Top Deals

RAM wasn't built in a day.

Working...