No they won't, because it would kill the web. That little bit is ownership: branding and control. There's no Adblock for their app. Their app isn't called Firefox it's Company Name. There's no dev tool for the app, so less chance to find out all the insecure ways it siphons my data. They control updates, so their ActiveX-style monstrosities are always going to be displayed the same. Get the idea?
I think one thing clear is that anyone who follows the news will be hard press to use technology that doesn't implement open source encryption. That's the only way we can be sure there isn't a black door. I think we should let every major tech company know that this isn't the time to reinvent the wheel or roll out their own in house solution, but to work on bettering proven open source technologies.
I don't think they mean legitimate as professional or industry recognized, but more as a way to distinguish from an actual bad guy hacking for criminal intents and then claiming he is a researcher and should have carte blanche.
It's stupid to use plain text for something that demands rich formatting and where you expect others to read, like a research paper or book, especially when there are great alternatives out there. Why not use Markdown, which can be written and read in a text editor, and compiles as a PDF or HTML and reads as easily as any Word doc. Or even learning LaTeX, which gives you even richer formatting than Word yet allows you all the benefits of writing plain text.
If the attack happens as described, and those two repos are aimed at Chinese people, why doesn't Github just block all requests to those pages that come from outside China?
It takes over 100 hours to brute force a 4 digit PIN.. I'm not impressed. For further security, everyone should use a longer PIN along with Touch ID, that is what I do.
Why dont browser makers add a function where the browser would tell you if your SSL connection is being intercepted? It's trivially easy to check, all you need is a known good site to sign a message with the cert of a specific CA, and if the browser sees it's signed by anything else, it would throw a warning. Chrome already does something similar with cert pinning.
Thanks for the feedback! The page is brand new, and yes the professional services we'll be offering are upcoming, so sales will make sense then. I will work on adding more information on the front page itself. The demo is also setup so you can at least view products and tickets without registering, although adding a demo login is a good idea, I'll do that now.
Same, using computers every waking moment, no wrist issue. Personally I attribute it to the way I type. I never learned to type 'properly', instead I use two fingers and my hands move all over the place. I still type very fast. No issue, tho.
What kind of fucked up site has 10+ iframes per page, let alone hundreds? And the example site he uses takes 530megs to load even without addons. I'm sensing the issue is somewhere other than Adblock Plus.
Kinda reminds me of LaTeX. It's my favorite way to write documents ever since I learned the language, it's so much more precise than word processors, but most people still defaults to them.
I'm glad to hear an actual scientist in this field also think what I've thought for a long time, which is that time is a human invention. I can't really explain it, but I've always felt like the universe doesn't really have a concept of time, that everything is just right now, hence why I don't believe in time travel either. Time is just a way for us to say 'something was' or 'will be', but in reality what was isn't anymore, it's not that it's in the past, but that the object was changed into what it now is.
I know it's an old argument, but they don't have an attack vector and thus no known infection, because iOS is locked down, so only jail broken devices would be at risk. Say what you will against Apple's tight control over their ecosystem, but between keeping the NSA out of our phones data and things like that ineffective, it'll keep being a plus for me.
I think a big portion of the problems Linux has these days is how unbelievably bloated and overconvulated distributions have become. Every single function has three, four or more ways to do the same thing, often with different results. When trying to get something working I never know if I should run the /etc/init.d script, restart the service manually, edit a config file, use the command line config until or use the GUI settings option. Sometimes you edit a config file and get the thing to work, only to find out some other utility will overwrite it next reboot. Other times you get strange errors or just nothing at all, because it's a deprecated method and you should have used the brand new tool-du-jour instead. It's a mess.
I think the most likely outcome of this is valet items being given preferential treatment on eBay. Just wait until your items are a tiny spot at the bottom while the valet items take the main spots, and that 30% commission will be the least of your issues.
Actually it would be good if the webmaster behind this reboot got SSL set up. Especially if this is going to be the new most authoritative download source.
The whole message on the site makes no sense and I think that's on purpose. What likely happened is the US gov found the TC authors, then used their weight to try and get them to back door the binaries. Authors didn't want to, but couldn't publicize the letters without going to jail, so they made up the most ridiculous story for why they were giving up on the project, the best possible outcome so that they wouldn't go to jail and wouldn't subject users to the required back door.
Actually I disagree. The NSA is all about spying. If they can't decrypt what you do without going to you and asking you for the keys (or throwing you in jail) then I would say it -is- a major pain for them. Remember we're talking about an agency who routinely targets one person in the hope to find dirt on others.
In this particular case, the bit about IDS isn't that ground breaking, it's just that the IDS checks for the malformed heartbeat request at the start of a packet, so instead he sends it at the end of a packet, namely appending it to the SSL handshake request. It's not like any hacker ever won't figure it out. I do agree with responsible disclosure for actual security holes, but this isn't it.
He was unlucky and didn't think things through too much, especially when dealing with such imporant files, but I agree with him that the way it's implemented is silly. If you provide a program that syncs your documents, with the name of your files, to your local system, people expect these files to be your actual documents, not empty links. Every other online storage system works that way. If you move a file out of your skydrive or Dropbox sync folder you have the actual file, not an empty link.
This is kind of glossing over the point. We all know SSL is good and should be used everywhere. But the simple fact is that to have a fully capable SSL server you need two things: A certificate and a unique IP. There are firms now offering free certificates, but not everyone has the choice to select them. And IP certainly aren't free on most hosts. Sure there are always solutions, like moving to a self hosted model and so on, but it is a significant inconvenience for most.
Apple says no money changed hands, and that's probably true. Just like no money changed hands in the Android KitKat deal. Still doesn't make either transactions not about the money.