Olin is free for everyone, and there's a wave in the elite schools to set up payments so that students don't leave with loans. Mudd has a relatively small endowment, so probably couldn't function under that model.
583 karma · joined June 6, 2010
[ my public key: https://keybase.io/willscott; my proof: https://keybase.io/willscott/sigs/PZ8NuMrWgqNFjPVMgRH_vyDZ0MeRBUzm86niZH5JK2w ]
Olin is free for everyone, and there's a wave in the elite schools to set up payments so that students don't leave with loans. Mudd has a relatively small endowment, so probably couldn't function under that model.
The author decided to show that if he knew all but one character of his network password, he could bruteforce the missing character. To that end, he took all 256 possibilities for that character, and computed the resulting keys. Then tried connecting with those keys.
This shows a connection rate of 30 attempts/2 minutes which is 0.25/second. That is not practical for most attacks.
Is it possible that this is simply a tool to allow for USB debugging of the UI? Otherwise, are there details (how often, what) is getting sent back to the carriers or to this company?
Edit per the response: I don't think this is a threat model that you would care about in theory, but it seems like a scenario that can come up fairly often in the real world. Especially in family or school settings, someone else will often have short durations of access to your machine. These people aren't often going to be technically literate enough to install key loggers or really mess up your machine, but they may well be able to quickly set up forwarding of your email to their account.
http://svn.apache.org/repos/asf/shindig/trunk/features/src/m...
From the file: This code implements a safer random() method that is seeded from screen width/height and (presumably random/unguessable) mouse movement, in an effort to create a better seed for random().
Its aim is to solve the problem of gadgets that are relying on secret RPC tokens to validate identity.
I don't get what the motivation is for having another closed system when they could have added interoperability with their desktop client + aol + gmail at a very minimal cost.
Edit: I'm basing this on the keynote comment that it is based on the push notifications stack.
It's difficult to imagine that Google has been 'slashdotted' due to serving up a javascript widget...
There's a reason we have the scientific setup that we do, and it is to filer the noise, and protect the authenticity of the science. If these guys from Alberta are able to come back with good results on human trials, then other labs will independently confirm the result. The fact that drug companies aren't picking up research at a preliminary stage on a drug that won't be profitable shouldn't be surprising, but it also doesn't mean that the research won't go forwards.
The standard handshake looks like:
Syn ->
<- Syn / Ack
Syn ->
The 'split handshake' looks like:
Syn ->
<- Syn
Syn / Ack ->
<- Ack
As a result, the hypothesis is that the intermediary router could incorrectly flip the roles of client and server, and incorrectly forward untrusted packets from the outside 'client'.
This presumably alleviates a lot of the security concerns for that plugin, since it now has the same protection to exploitation as the rest of chrome, and security vulnerabilities might be able to be patched through chrome's auto-update(?)
http://code.google.com/closure/
You can look at the (compiled version) of the code by looking at the scripts tab of the chrome web inspecter. They're there :)
If there was a open source release of the gmail client code, it would force google into maintaining an API for that code for the foreseeable future, which would require additional effort.
The closest to this request that seems remotely likely is a client side API for gmail, so that browser plugins or third party services could extend it. I see a lot of cost to Google to actually release the code, and not a ton of benefit.
Here's the basic usage for chrome: (for firefox the event is MozOrientation, and values are radians rather than degrees)
window.addEventListener('deviceorientation', function(evt) {
var x = evt.gamma, y = evt.beta;
}, false);This will be a reasonable alternative to modal dialogs for chrome extensions initially, and eventually for web apps in general. (if it gets adopted by other browsers)
My guess is that the chinese publisher didn't want to pay royalties, and this was a convenient way to get a good quality copy of the book for printing without having to share profit.
I'm pretty sure we're talking about an HTTP protocol so a 302 redirect ought to work, and it seems like that would give the CDN way more control than trying to distribute traffic using a cached and not reliably localized DNS mechanism.
Edit: foobarbazetc has a good point, but it still feels like the CDN has reasonable ways to work around and do a better job of selecting the correct pop than DNS. Adding a layer of subdomains which force locality (us-ny.host.com) would keep urls readable & virtual hosts intact.
Is there any reasonable theory for how the choice of DNS changes download speed this dramatically?
I can see it taking longer to resolve the ip address of the download server, but that should only be a one-time thing - and the total impact should be a couple seconds at most. Unless the download is constantly flipping between servers, I don't see how DNS latency is going to make a noticeable difference in the time it takes to download / stream a movie.
The tie is for number impressions served to iOS versus android devices.
Not the total web ad impressions, nor even ads served on the respective platforms, since Google is serving a significant number of ads on iOS.
If Chrome OS costs less than than that yearly upkeep cost, and comes with perks of low maintenance and remote connectivity, I could see a lot of companies being very tempted to switch.
Here's a search for the 'client_id' that the author was afraid of: http://codesearch.google.com/codesearch?as_q=client_id&v...
It looks like a likely possibility is that the author is syncing his profile to google - in which case it makes sense that some ID needs to be stored in order to figure out which sync updates are coming from which browser.
On the klingon point: They theorized that the particular organization was a bunch of PHDs rather than farmed labor - and that it had learned from previous 'example answers' they had submitted. That particular organization, it was noted, was also an order of magnitude more expensive than the others.
Wouldn't allowing the flash ads to have a non-window wmode make it would be much easier for malicious websites to trick visitors into clicking on ads that they weren't aware were there?
You say two very different things in your post - that you've only taken two "real" CS classes, and that you know basic algorithms / data structures. A lot of what comes out of an algorithms or data structures class is the vocabulary surrounding those topics, and my experience was that the vocabulary is a significant part of the GRE.
The worst thing that happens is that you're out a hundred dollars for the registration fee, so you might as well find a CS GRE prep book and start studying. It is definitely more doable to cram for the CS GRE than for the Math or Physics tests.
http://blogs.discovermagazine.com/80beats/2010/10/25/a-robot...
Physicists are calling these materials 'granular media' - and there is a ton of research going into that field right now.
I know that the reason I wanted to work at Google was to learn how to solve problems involving scale and massive parallelism. There really isn't anywhere else that can teach you that stuff as well.
I have several friends who use Google to as a first editor of their grammar by making sure that phrases they aren't sure are correct return lots of search results. This seems like a convenient way for them to streamline that process.