959 karma · joined April 28, 2017
Easy peasy in KSP. No idea if it is possible IRL.
We could have had Lisp instead of JS, but no, that would have worked too well; management wants Java. We almost had a Scheme instead of CSS: DSSSL, which could also do structural transformations of the document tree. But once again, no. The simplicity multiplied by the flexibility of a Lisp, equaled unacceptable complexity, for some strange definition of complexity.
XML looks like it really, really wanted to be a Lisp, what with its orderly nesting of tags. I almost wonder if XML stumbled and fell, due to the supporting pillars of parens being knocked out or corrupted, left, right and center.
The block looks like this: https://dohanews.co/wp-content/uploads/2014/09/qatar-block.p...
If you can operate within those constraints, then you can build at a <$1 price point, and run on 2mW of power, less current than an LED. Heck, you could run the thing off of a joule thief, and pot the entire assembly in epoxy.
Fitting a pared down libC into that might be possible, but why bother? The system is so small and simple, that the rationale for a high level language doesn't really apply. Most of your code will probably just be bitbanging and setting control registers anyway.
But, most importantly, assembly is just plain fun, which is what will keep you coming back to the platform :)
Then, the onus would once again be on the legitimate ransomware developers to prove their ability to do business, and some sort of Ethereum based automated contract might be an ideal tool for that.
This is no reason to give up though! It is no excuse for not following best practices, consistently! That is malpractice, when done by a doctor! And their field is at least as complex as our own.
I am seeing an incredible resistance to this idea of increasing the situational awareness and capabilities of the people who provision and maintain large deployments. Perhaps it is too soon to propose solutions. Perhaps, today, we should just express solidarity with the victims, and try to warn operators of unaffected, but vulnerable systems to temporarily take them offline.
My apologies to those that I have offended. As a software developer who has struggled for years to articulate the need for transparency and simplicity in our systems, I feel very frustrated right now.
all software is vulnerable
This is false, and spreads FUD. It does a great disservice to those who do meticulously maintain their systems, to those who sacrifice convenience and beauty for stability and security, to those who take the time to scrutinize other people's work. It is possible to build and deploy secure software.Linux dominates the datacenter; we are a high value target, and have been for quite some time now.
We saw a fictional example of a scheme like this on Battlestar Galactica. Officers phoned and faxed orders around the ship, using simple devices that did not execute software. The CIC had its data punched in by radar operators, instead of networking with shipwide sensors. It was a lot of work, but it did keep working in the face of a sophisticated, combined malware/saboteur attack.
Those limits are constantly being pushed outwards, but they are not disappearing. Eventually, we might have cities and data centers covering the entire Earth, à la Coruscant. At that point, we will still be constrained by our ability to cool the system, by our ability to efficiently power it all with minimal waste heat, and by the speed of communications through congested networks.
One of the problems here, is that large organizations are reluctant to update software across a large population of computers. If those updates were smaller, more transparent, and could be separated based on whether they are a security fix, a new feature, or a new tool that allows a 3rd party to monitor user activity, then the sysadmins would be empowered to close security issues quickly, while introducing minimal risk.
In the end, the software that we depend on, must be reviewable by anyone who is concerned about it. A prerequisite for that, is that software should be as small, clean, and simple as possible, to encourage such scrutiny. IIRC, the real problem with heartbleed, is that the OpenSSL codebase was a mess, and no-one wanted to work on it.
If production is not limited, then we can instantly transform our solar system into a Dyson sphere, right now. What am I not understanding, of this theory?
My mother is in a similar situation. She is an elementary school teacher, and has little time for unrelated endeavors like this. What time she does have, is spent in the garden, as it should be.
Nevertheless, we are now seeing that the time-cost of closed source software, is greater than that of open-source software. My solution has been to prepare a KDE based distro for her, to work with her, side by side, whenever she needs to learn new tools. It is a good bonding experience, when both people can maintain a positive attitude about it.
The solution to the problem of malware, is education.
I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software.
I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against future attacks.