331 karma · joined December 14, 2011
Heuristics don't work against ransomware because they act like a well behaved program. Search for files, open file, overwrite file. All could be done as non-privileged user.
Ransomware is truly scary but the proper advice is: 1. Don't run untrusted software 2. Proper backups (e.g. not just a mirror) 3. Proper permissions on network drives that are mapped. Ransomware is devastating to small offices.
I don't understand at all why monopoly is the universal board game that every kid learns. It's a horrible game that drags on for hours. Even though I don't particular care for Catan it'd make a much better universal board game.
As someone else points out, all statically linked binaries are immune to this technique since they don't load preloads.
Another warning is don't muck around with /etc/ld.so.preload unless you know what you're doing. It's possible to get in a state that everything you executes segfaults.
Also with proper hardening you can prevent the kernel from being modified even by root. Things like FreeBSD securelevel that once enabled blocks writing to kernel memory and raw disk devices.
File integrity is also a pain in the ass. You have to keep a database of good file hashes and it can't be stored on the server (or the attacker modifies the known good hashes). Generally you also should not even have the file integrity software on the live server filesystem.
Similarly Network IDS has the flaw that you must have well defined profiles of "normal behavior" so it can identify abnormal behavior. The other option is signature-based but that would only detect known exploits.
If your cabin in the woods is getting broken into, you won't secure it by putting a lock on the front door. You'll just get robbed and have a broken window.
The real problem is users accepting and running installers that install crapware. You effectively give it permission to do anything it wants.
Water shortages could be addressed with large scale desalination. Shipping/transportation would become real cheap without significant fuel costs. Food issues could be addressed by commercial hydroponics.
Maryland also doesn't want the NSA to leave since federal money is a huge part of the state economy. Also denying state contractors from providing support could cause massive disruptions. I imagine a lot of basic services at government facilities overlap (custodians, food services).
Unfortunately the states don't really have any legitimate tools to punish the federal agencies. I suppose since the NSA is under the DOD they could rollback state benefits to military but that'd be very unpopular. They could also go NJ style and close down roads outside their headquarters.
10 years from now, how are you going to run those XP apps that aren't compatible with even windows 7, let alone three more cycles of ugprades.
There is nothing in advertising that requires all of that. I'm perfectly fine with static locally hosted ads. But the whole industry is based around something else. I continue to use adblock plus despite their "Acceptable Ads" program because I consider it reasonable in requirements.(2) I think there's a lot more room for compromise in allowing ads but no extension makes it easy to address my concerns.
Citations: 1. https://help.yahoo.com/kb/SLN22569.html?impressions=true 2. https://adblockplus.org/en/acceptable-ads
Also Obama's numbers have really dropped compared to Bush: http://porngram.sexualitics.org/?q=bush%2Cobama
If you're in the business of making content, you want to join the trend early and get out before everyone realizes it's a fad. A truly great movie can buck trends, or even change them, but there are few truly great movies. Or you could just ignore this all and make the perennial favorites, generic romance or action movies.
What if it's so energy intensive that a future dyson sphere can only power it once a year. It doesn't matter how cheap the machine is, if the resources are expensive.
dnssec protects mostly from poisoning between nameservers. It does little to protect between a host and their namserver.
But in reality dnssec is not a solution, it's a problem. It will never be adopted in a meaningful way without major overhaul in spec.
I already accept a lot of places that I should let machines handle a task for me. I drive an automatic transmission rather then shift myself. I have traction control that overrides my foot to give me better control of the car. I fly in planes that are mostly flown by autopilot.
Assisted driving will only be a short stopgap. It will be quickly gotten rid of because of cost to maintain two systems and because the ugliness of a "drivers seat". Interiors will look nothing like they do now. There will be no drive-shaft (fully electric) so no big bump or center console in middle of car. No steering column, no mirrors and a completely different arrangement of seats then now.
In other words a fully automated car looks nothing like an assisted driving car. I doubt people are going to want to pay more and sit in less comfortable cabin, just for the opportunity to override the computer driver.
I just don't think adding bureaucracy is the solution. If I want someone to go to school I don't manage it on the individual, you'll spend half your money on administration. I spend it by subsidizing tuition.
Some people will drink themselves to death, but they already do that in our current system. How does that matter? The only difference I see is they'll have a lot more free time. Maybe they'll waste it, maybe they'll improve themselves.
All those things you want cost money to verify and adds massive administration costs. Another point of universal income is it's cheap to administrate.
If you want to "pay" people for taking college, just subsidize it.
If streamers could maintain 30ms of network latency then it's just a minor difference from the system baseline.
If the streamers are smart they could colocate with the game servers. Then that 30ms of network latency is there regardless, home system or streaming system. It effectively adds no lag for streaming.
John Carmack made a comment that he could send a packet to europe faster then he could send a pixel to a screen: http://superuser.com/questions/419070/transatlantic-ping-fas...
But it could be exploited. If a person walks out in front of a truck, the automated truck better stop. Which an unguarded truck would become easy to rob with little risk. A flat tire would mean the truck calls in for help and is stranded defenseless on the side of the road. That said a fair amount of loss could probably be absorbed with the savings.
I expect long haul truck drivers instead to turn into truck captains. They're present but not for the driving. The truck can drive through the night while they sleep. The captain will handle weigh-ins, emergencies and other road tasks.
Also people are already free to use devices during loading and unloading. Your complaint is that people don't have common courtesy, but that can't be regulated by FAA (and isn't currently)
Again, due to the robustness principle, just because a host does not define MX records does not mean they can’t accept mail. Mail servers will often fall-back to A records to try and deliver mail. That’s why we go one step further than just a DNS query, we ping the Mail Exchanger to make sure that it actually exists."
Plenty of boxes don't respond to pings (icmp). Can I assume you're doing a tcp scan on mail ports?
The first two are legal by rfc but not allowed by the individual providers. The third is not legit by rfc 2606 because example.com is a reserved domain.
If it was just a RFC validation then it should validate all of those (except maybe example.com). But they go beyond that: "Furthermore, the validator is ESP specific, so we can go way beyond valid syntax checks, bring in specific requirement for Gmail vs. Yahoo vs. Hotmail."
Passwd = "password" /usr = "slash user"
If someone doesn't understand you, then you explain and move on. But the industry has based around this jargon and removing/redefining it just creates separate standards.
Some machines only have python 2.4 and others 2.7. So /usr/local/python is not a good answer for python scripts in /project/x/bin (network mapped). Worse someone puts gnu coreutils in /project/x/bin, but for sparc architectures, so PATH becomes touchy if you're on a x86 server.
I've resorted to having my bashrc build my path by scanning uname for architecture/platform and conditionally adding path entries to these network folders.
All organization scripts on network drives now have caveats "This only works on linux x86 servers" or "This only works on server X". Not because it can't work elsewhere, but because the PATH and #! management problems when the dependencies are installed at different places on different servers.
Blegh </rant>
Things I'd like to see: 1. Highlight sites that have changed terms recently. 2. The discussion links should show how active the discussion pages are