196 karma · joined January 22, 2010
Getting this fixed was already on our to-do list. This incident has moved it up to near the top of the list (competing with a few other security-related tasks).
Panel passwords are safe, BTW. The only passwords that we believe may have been compromised are UNIX user passwords (e.g, FTP/SFTP/SSH users).
> x264 - core 112 - H.264/MPEG-4 AVC codec - Copyleft 2003-2010 - http://www.videolan.org/x264.html - options: cabac=1 ref=3 deblock=1:0:0 analyse=0x3:0 me=hex subme=7 psy=1 psy_rd=1.00:0.00 mixed_ref=1 me_range=16 chroma_me=1 trellis=0 8x8dct=1 cqm=0 deadzone=21,11 fast_pskip=1 chroma_qp_offset=-2 threads=6 sliced_threads=0 nr=0 decimate=1 interlaced=0 constrained_intra=0 bframes=3 b_pyramid=2 b_adapt=0 b_bias=0 direct=2 weightb=1 open_gop=0 weightp=0 keyint=250 keyint_min=24 scenecut=40 intra_refresh=0 rc_lookahead=40 rc=crf mbtree=1 crf=22.0 qcomp=0.70 qpmin=10 qpmax=51 qpstep=3 ip_ratio=1.41 aq=1:1.00
The release of this code isn't really all that exciting, as there's already a free reverse-engineered implementation in libav. (It might not support all the modes described in this source release, though.)
Also, it isn't encrypted. So there's that too.
That being said, the fullscreen mode in Pages actually seems like a pretty nice compromise between features and non-distraction. Apple's obviously been taking some notes. :)
Speaking from experience, there are a lot of edge-case bugs remaining in aufs. It's usable enough for livecds and whatnot, but trying to use it on a server is a recipe for disaster.
Ascii85 (http://en.wikipedia.org/wiki/Base85) uses a similar concept, but using the majority of the printable ASCII characters. It gets a hard-to-beat 20% expansion on binary data (4 bytes in 5 chars) without requiring bigint math.
* Infinite lookahead - the type for a tagged netstring doesn't appear until the END of up to 100 MB of contents.
* Large intermediate memory usage - a string of the form 9990:9985:9980:9975: <...> ]]]] may consume a very large amount of memory for substrings during parsing.
* An int() implementation which exactly matches Python's.
* Ambiguity.
Bencode (http://en.wikipedia.org/wiki/Bencode) has been around much longer, and is considerably better thought out. There's no reason to not just use that instead.
Probably not; they're likely using a SOC with integrated memory.