Eagle scout. Idealist. Drug trafficker?
nytimes.com
nytimes.com
I just now tried with Safari, after turning off JavaScript. No problem viewing the entire article, including pictures. Of course I reset Safari before opening the URL, just to make sure there were no existing cookies, etc.
I love the NYT paywall. The only way they could have made it easier to bypass would have been to include directions on how to disable JavaScript at the top of every page! BTW this is deliberate. It's not like they're idiots. They intentionally decided to make the paywall easy to get around.
Never attribute to cleverness what can be adequately explained by incompetence.
Edit: Afterwards. I'd be more inclined to believe them if they had said it from the start.
http://paidcontent.org/2013/02/11/new-york-times-plugs-big-l...
"While critics say the gaps highlight flaws in the newspapers' new business model, the Times says the holes are deliberate and meant to encourage openness across the Internet."
http://abcnews.go.com/Technology/paywall-york-times-readers-...
Also remember reading a couple quotes by NY Times execs/spokespeople that it was intentional.
Of all the things that I spend money on each month, though, the $15 that I send to NYT is easily the one I feel that I get the most value from.
This exists, it is called pamusb[1] and it allows you to automatically log in and log out using a usb stick. It would be simple to add password as well. The problem is, if your machine is still powered on, they can patch into the PCI bus and dump your RAM using DMA[2]. Most disk encryption stores the master key in RAM, so if they can dump your RAM they can decrypt your harddrive. GAME OVER!
You really want something that cuts power to your laptop so all state is lost. It's not hard to build such a thing:
1. Setup your laptop to use full disk encryption,
2. remove the battery from your laptop,
3. pull the power cord to "instantly log out".
One could even attach a string from the power cord to the door so that the laptop loses power if the door is opened. Cold-boot attacks[3], where they remove your RAM before it loses state, could be a concern, but they would have to disassemble your laptop very very quickly (within 30 seconds, perhaps longer if they just threw the laptop into a tub of liquid nitrogen). A counter measure would be to epoxy your laptop together to prevent quick disassembly (or use a macbook air those things are impossible to take apart quickly and the RAM is soldered in place).
It should be standard operating procedure to randomly overwrite all non-OS data stored RAM when a user logs out. Maybe someone with most experience in disk encryption can tell me which products do this.
[1]: http://pamusb.org/
Then again, encrypting your drive and making sure the encryption key is safe might be slightly more sane than turning your macbook into a puddle of aluminium.
For instance they get anything in RAM (files being edited, program state, passwords, emails, web cookies).
Maybe you played a RAM intensive video game that overwrote everything or perhaps you just finished writing a quicken books entry for your counterfeiting operation. Do you feel lucky?
* You can patch your kernel so that DM-crypt uses Tresor, so it is possible. I don't know how it handles the inode keys. http://www1.informatik.uni-erlangen.de/tresor?q=content/read...
What a security-conscious user really needs is laptop storage that can be quickly destroyed. An SSD would be the easiest to destroy with a strong acid or base (fuming nitric acid will just decap the epoxy). Perhaps someone here knows which would work best.
Couldn't you just turn the circuit upside down and use a diamond tip drill (Dremel would do) to drain the acid?
I think sticking with full disk encryption would be a more reliable choice.
"surround" in my dictionary means all directions.
Didn't even Dell sell servers with a small amount of explosives so that the disk and memory go boom on unauthorized open? (amount comparable to the amount in in airbag -- yes, your airbag has explosives) At least one of the brand names did, as I recall.
There's an essay by Aleister Crowley, 'Cocaine', where he argues that free drugs (even hard ones) are better for the society as a whole.
I'd rather that we just get down and dirty, in an honest and direct manner. We often sacrifice progress on many issues by getting set back by social rules. Let's stop doing that.
Do you (or anyone else) oppose having armed guards protecting a data center? Armed guards protecting a data center means that someone might get killed to protect a website.
(You can draw other moral distinctions, and I'm not defending this guy in particular. I'm just pointing out that the specific argument you are making is most likely incorrect.)
Right, that would be to tptacek's point.
The only reason I can think of to have armed guards at a data center is if the people working there are at a real risk of armed attack, not the computers.
edit - also if your site security and uptime is dependent on some people with guns at a datacenter, then you are doing it wrong.