140 karma · joined May 5, 2014
Twitter: @HackinOut
The "decrypt one file for free" feature seems to be specific to CryptoWall which, some have reported, do not use symmetric encryption like CryptoLocker. CryptoLocker stores symmetric keys for each file on the infected machine, encrypt those with a public key and when the payment is received, send the private key from the C&C Server. I would say it's very unlikely CryptoWall would store remotely a private key per file. That could mean a lot of information to be transferred over the wire. Probably because of using only asymmetric (slow) encryption, CryptoWall apparently only encrypt small files completely, and only a piece of the larger ones. One way the "decrypt one file for free" feature might work is by actually uploading the file (or the the encrypted piece of file) to the C&C Server, decrypting it remotely and sending it back. But the feature is definitely worth investigating.
https://blog.fortinet.com/post/cryptowall-another-ransomware...
http://stopmalvertising.com/malware-reports/cryptowall-behin...
http://stopmalvertising.com/malware-reports/cryptowall-behin...
If this is the case, I would surprised if they would download the private key for the one free decrypt feature. If they encrypt only small files they might do the decryption on the remote C&C Server?
It's worth investigating anyway.
They're stating their mission and then asking for donations. At least that's how I see it. There is no endeavor that is guaranteed to succeed. Money isn't the only problem they are facing.
I personally greatly prefer that statement to something like "if the money runs out, we'll have to close IA. Please donate." which somehow sounds like blackmailing. EDIT: The former doesn't feel like marketing to me, might lead more people to donate and I would expect most of us (like you and me) to understand that they do not make any promises, except doing their best.
[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in
[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in
Fingerprints are neither. As several people mentioned in this thread, the only thing I see a fingerprint suitable for is replacing a username.
EDIT: So does Kinect for Xbox one.
It's great work, I hope the fact that you can make a copy from a simple HD photo will bury people's ideas about fingerprints security for good.
Furthermore, it seems to me that with the Paper White's light guided "on the surface of the display", the light shines as much in towards your eyes as it does towards the screen...
EDIT: I probably should have said "without the built-in light" but wanted to include devices that do not have one to begin with. I am still using one of these :)
"They spent five days reading from a paperback and five days from an iPad.". If only iPads were used, I don't believe the word e-reader is appropriate.
If you use an e-ink display without a built-in light, there are no reason this would be any different then using a book (as mentioned in the article but it's not only about "the original kindle"). Also there were tons of studies about the effect of light on sleep and especially blue light emitted by LCDs, most e-reader makers use a warmer light if I'm not mistaken.
EDIT: elaborating
If you ban (for your whole program) some components then I guess you would loose some expressiveness.
Also I don't know if you can categorize "components" as more or less readable. For some problems a "component" might be highly readable while totally inappropriate for another problem. I see some cases where using more components makes the code more readable.
This is an art of using language features (paradigms etc...) and design patterns that will be the most readable while powerful enough to solve your problem. I love doing it with Lisp or Ruby which are languages with a very modular syntax. But it's time consuming so I'm doing it only for substantial projects I really care about. It's much more efficient to use conventional well established programming style (think RoR for example) and less bug-prone (more secure etc...) because it's well tested by many.
It's extremely easy to do LOP with Lisp thanks to s-expressions (all those parenthesis :). But you can be much more expressive with LOP.
EDIT: elaborating
With it you can basically choose your level of expressiveness while you develop your program (with different levels for different parts of your program). The frustrating trade-off between expressiveness and readability[2] is the main reason I love this paradigm. Unfortunately LOP has never been really trendy. Hope it will change soon.
[1] http://en.wikipedia.org/wiki/Language-oriented_programming
[2] For programming languages I would rather speak of readability (as opposed to analyzability) because a program is often not written in stone but "alive" (it's modified, enhanced over time...). It probably does not apply to the other fields discussed in the article though.
The screen you are referring to probably uses the exact same technology (designed while she was CTO?). It's not e-ink but indeed amazing. Too bad we don't yet put a lot of resources into this kind of projects.