473 karma · joined June 6, 2010
Key and cipher negotiation could easily be shoehorned into the three-way-handshake already used to establish connections. AES with a CTR block mode would be the obvious cipher choice since each packet would be handled separately. With TCP you could even just use the sequence number as the counter, although this would be harder at the IP layer.
But yeah, none of this would have been available at the time. Still, given today's technology it would not be difficult to future-proof, especially if the trust machinery is left to the application.
My coworker runs his own MX, but bounces all his mail through Google just for the spam filtering.
No, the entire premise is in the title: Don't encourage kids to drop out. If they want to do it, they'll do it, and good on them for it. The last paragraph even argues against "extreme points of view" which would suggest that interpreting the article as "they say drop out, don't do it" is totally wrong.
> Where might we be if some of the 'usual celebrity dropouts' hadn't dropped out?
Worthless speculation. We'd be somewhere different, yes, but no less interesting and no worse off.
The work factor is an input to the digest function, both when creating and when validating the password. Normally it should be stored alongside the digest itself so you can increase the work factor over time without disrupting existing passwords. So you are correct. It might theoretically be possible to correctly balance the work factor to counter variation in password info entropy so that all passwords take about the same time to crack, and this would be very cool and impress members of the opposite sex, but it would not improve security at all.
Making a probabilistic password checker is also a superficially interesting idea. Maybe my mind is too small to explore it completely, but it seems that at best it would be no better than just increasing the work factor.
Collision attacks don't apply to many situations but are much easier to execute, for example a MD5 pre-image attack requires approximately 2^128 steps but a collision attack requires only about 2^64 steps. This is why MD5 is totally unsuitable for collision resistance, and in fact has already been successfully exploited to fabricate a real-world CA certificate, but still puts up mild resistance to password cracking. Not that I'm recommending you use it or anything -- do what the nice gentleman says and just use bcrypt already!
I know this was a rhetorical question, but I'll answer anyway: It isn't possible. Not only is there no way to read latent data normally from a drive that has been zeroed (drives that fail this test are called "defective"), but it is currently understood that recovering data from a modern drive that has been overwritten with a single pass of random data is impossible at any expense.
http://www.cs.auckland.ac.nz/~pgut001/pubs/secure_del.html#E...
However, data can still leak out of cloud stores in the same way that it leaks out of solid-state disks and even magnetic disks: there's no guarantee that a given logical block will always be mapped to the same underlying hardware. A mirrored drive may be fail and thrown in the trash with data still on it, or written blocks might be mapped to different places in an array for any number of reasons. This shouldn't result in leakage to other customers although it is up to the vendor to make sure this doesn't happen.
Depending on the implementation, vendor-supplied encryption may or may not mitigate this risk, but customer-supplied encryption always will because the customer knows where the dividing line stands.
Also, there are block modes that are seekable and thus could be parallelized if you had a big enough backlog, CTR mode in particular, but parallelizing individual streams is not likely to reap big enough rewards to justify the complexity.
Doesn't say anything about the name. Trademark law and copyright law are related but very distinct. If Oracle owns and enforces the trademark "Hudson" in the context of continuous integration software, and they say "Stop using the name Hudson", you must comply regardless of any copyright licensing in effect.
Compare Firefox which has a free software license but prohibits use of the Firefox name if any modifications are made to the code. This is why it's called Iceweasel on Debian -- as I understand it, even a security patch is technically enough to violate the contract.
* You can nest classes and methods. This is ugly, so I never use it except in testsuites where declaring a mock class right in the test method is the best way to do it, but it's great to have "self" be the testcase and "xself" be the mocked method.
* There's no such thing as a magic variable. Every name you can reach is declared somewhere, either locally, globally, or from `__builtins__`. If self were automatic, then it would be invisible like the builtins, but it would change depending on where you used it from. The consistency is worth the minor inconvenience, IMHO.
In any case, I think this design qualifies as "quantum" because zener diodes at 5.6V and less work through quantum electron tunneling ;)
The right to keep people OFF my property and do with it what I like.
> the right to an attorney; the right to a trial by jury; the right of a speedy trial; protection from unreasonable search and seizure; the right to confront your accuser?
The right NOT to be hassled or detained by the government unnecessarily.
Oversimplified explanations yes, but I don't see any of those as requiring others to step up and fulfill my own rights. Police keep people off my property using the implied threat of violence not because that is the only way to fulfill it, but because the alternative -- me enforcing it with overt violence -- is less palatable both to myself and to the police.
Whether the proposal by this website falls does fall under "positive rights" depends on the interpretation but I gave up on trying to read it so I can't say. If they call for the right to obtain access to the internet without interference (censorship, etc.) then I respect that although I don't necessarily stand behind it. If they call for the right to have free WiFi across every square millimeter of Earth then I don't think anyone who gave more than a cursory thought would agree.
You are not a vegan. You are not an atheist. You are not the car you drive or the contents of your wallet. You are a human being, and nothing that is within your power to change should be exempt from introspection.
Good point, but
> they could start up a counterfeit one and collect your password.
you missed the part where I disable password logins on all of my boxes :-) The important point was that the system was already secure enough due to the key requirement, and moving the port was indeed just to stop the "doorknob rattling". If I suddenly find that a box I control is asking me for a password, I'm not going to just type my social security number in and hope for the best.
One could argue that using a port < 1024 makes it easier for the scanners to find, but frankly anything other than 22 (or a frequently scanned port) would work well enough.