Oracle Database Redaction Trivial To Bypass, Says David Litchfield

Capslock118 Re:Put in a separate table (62 comments)

No, passwords, SSNs, PINs and Credit Card numbers should be hashed before inserting into any table. There is NO reason for anyone to save that data unhashed.

To compare data, just hash what the customer enters and compare the hashes. Why is this so hard for 99.9% of companies to understand?

ACH processing requires sending bank account information to the ACH along with how much to bill the individual. Many other forms of automated payment processing formats also require credit card numbers sent - this is all happening with flat files. If you expect credit card numbers to be hashed in your database, then you need to convince the receiving end of that data that they do not need the source to send that data.

about 6 months ago

A Year After Snowden's Disclosures, EFF, FSF Want You To Fight Surveillance

Capslock118 Re:No point encrypting if you're the only one... (108 comments)

I agree 100%. I'd say 50% of my communication is with my family, and there is not a single person in that group that would be able to handle GPG. And anyway, we are at the point of "every message on every device", and again most of my family communicates on their smartphones, not on a desktop or laptop. Even if they did use a desktop/laptop the message would still have to be easily read on all of their devices (including default apps). There is just no point in wasting my time with email encryption since I am not any kind of political advocate and no one I communicate with would be able to use encryption. Heck, I have S/MIME on all of my devices for email and that works great and it's automatic......but I am the only person in my circle who uses that even though it's arguable easier to use than GPG (because it's supported by most of the default email applications out there). Why even bother with trying to ram encryption into email when there are other secure communication protocols out there?

about 8 months ago

Researchers See a Post-Snowden Chilling Effect In Our Search Data

Capslock118 I took a different approach (138 comments)

I for one have only increased my search phrases to include "fundamentalist terror victim shoves anthrax-laden biochemical warheads into buttocks to appeal to president obama porn"

about 9 months ago

What percentage of your online communications are encrypted?

Capslock118 why no ssl love from slashdot? (186 comments)

one could argue the relevancy of privacy reading some news on slashdot... ...then again what percentage of the community is reading this right now while sitting at their desk in the office?

about 9 months ago

Smartphone Kill-Switch Could Save Consumers $2.6 Billion

Capslock118 Re:I can save Americans $4.3B/year (218 comments)

I don't completely understand this because I never bought insurance for a phone. Is this saying that even though some people buy phone insurance, those same people still have to pay out of pocket to replace the phone? What is the insurance doing for added-value?

about 10 months ago

Power Consumption of a Typical PC While Gaming

Capslock118 Re:I love kill-a-watt (211 comments)

I have a kill-a-watt as well. I have been increasingly obsessed with the amount of energy my house uses and I am proud to say we are staying under 440 kWh per month. While I have not tested out my machine thouroughly (I do not have it on much anymore) on Idle i was spending 450 watts. Now, this was between the power supply and the wall, so maybe the machine was using less power, but ultimately thats what it was drawing (the power supply is 450 watts so this makes sense to me). I can hardly believe that the router mentioned was using 8 watts, what is the time period there? I know the power supply on my linksys router is in the milliamps so, basic conversion would indicate to me that is not possible. I am probably thinking of something backwards though. But regardless, wouldnt the power supply dictate the amount of power used regardless of what the computer actually uses?

more than 6 years ago


