×

Announcing: Slashdot Deals - Explore geek apps, games, gadgets and more. (what is this?)

Thank you!

We are sorry to see you leave - Beta is different and we value the time you took to try it out. Before you decide to go, please take a look at some value-adds for Beta and learn more about it. Thank you for reading Slashdot, and for making the site better!

Comments

top

Debian Talks About Systemd Once Again

Sipper Re:Ian Jackson (522 comments)

Ian Jackson is a man of principle, and the way the final vote was done within the TC [Technical Committee] was certainly objectionable: he was in the middle of discussing what should be on the ballot when Bdale Garbee called for an immediate vote on the same subject but with a totally different ballot. Then when the vote came to a tie, Bdale used the "casting" vote, meaning he had two votes where all the other TC members had only one. Furthermore Bdale's friend and close business partner Keith Packard had just recently joined the TC.

Furthermore this GR [General Resolution] isn't about reversing the TC decision nor in changing the default init system for the Jessie release -- it's about giving the other init systems a fair chance by making them possible to use by making the bugs in packages causing them to break RC [Release Critical]. That's all.

And he did bring this GR up in March, but at that time the Debian community was more hopeful that support would continue for the other init systems, but instead support for everything else has waned -- Ubuntu immediately decided to switch to systemd and drop upstart, and there have been issues with support for other packages concerning the standard sysv-rc init -- all of which Ian had expected to happen.

The main objection from Debian developers concerns the timing of this GR only because the Jessie release is nearing, but ... Ian did bring this up in March...

about 2 months ago
top

Previously Unknown Warhol Works Recovered From '80s Amiga Disks

Sipper Re:Amiga Floppies (171 comments)

You apparently never had to put your C64 power supply in the refrigerator.

The C64 power supply used a 5v linear regulator rated for 0.2A - 0.3A less current than the C64 itself drew through it, so the part would have premature failure because it was underrated. Apparently/supposedly the difference was expected to be dumped as heat, and the supply was potted which made it very difficult to get to the part that failed and replace it... but doing so was necessary because the replacement supplies had the same design flaw. I did that replacement and after doing so the power supply looked terrible (I left it ripped open), but with a linear regulator that had a sufficient current rating it never failed again (whereas the replacement supplies all did).

Putting the power supply in a refrigerator sounds terrible (but dedicated), but then, so was the "correct" fix. ;-)

about 8 months ago
top

Previously Unknown Warhol Works Recovered From '80s Amiga Disks

Sipper Re:Amiga Floppies (171 comments)

I've heard of drilling through the potting material to remove and replace a fuse buried in there, but never that. What was the hope behind the refrigeration of the "brick"?

Yes, the C64 power supply was potted -- and after digging through it what had to be replaced wasn't a fuse, it was a 5v linear regulator. The problem with the C64 power supply was that the Linear regulator was designed for 1A, but Commodore was using it to pass 1.2A. This shortened the life of the part, and when it failed it required a huge effort to dig through it to find the part that was bad and replace it.

But I did exactly that. And unfortunately one generally had to do that if they wanted to end up with a reliable supply, because the replacement supplies had the same design flaw and would thus fail in the same way. Once I replaced the 5v regulator with one that was rated for 1.5A, it never failed again. :-)

about 8 months ago
top

Microsoft Confirms It Is Dropping Windows 8.1 Support

Sipper Re:Slashdot is ridiculous (575 comments)

I am the wrong person to get into the nitty gritty of it, but I believe this is handled by Side-by-Side dependencies (SxS) in windows. I have only very rarely seen dependency problems on Windows, even going back to the days when XP was new and 2000 still roamed the earth. Linux dependency problems are less common but theyre definitely a bigger issue than Windows ones.

Well, I was speaking of modularity in design terms, not about dependencies per se. Vista and above are known to be "more integrated" than previous Windows versions, and simultaneously nowhere near as modular for the base OS as most Linux distributions. [And as such I agree that dependencies are a bigger issue on Linux than Windows. ;-)] What I'm getting at is that on Linux a bug such as the OpenSSL problem can be quickly narrowed down to a particular package, whereby the code that needs looking at for a fix is much smaller that way. On a more integrated system the source of the error is likely harder to find, and once found more complicated to fix, than a modular system.

However this is speculation on my part, as I'm not familiar with nor involved in the design of Windows OSes, nor have I looked at any of the Windows source code, and I also don't otherwise have a way of making a "Linux vs Windows" side-by-side comparison.

about 8 months ago
top

Microsoft Confirms It Is Dropping Windows 8.1 Support

Sipper Re:Slashdot is ridiculous (575 comments)

The SSL flaw has been fixed and rolled out very quickly, it was not the first and will not be the last. How many known Security flaws for windows, IE and many other Microsoft products are out there, unfixed?

Could you explain why "Microsoft has a bigger problem with having to support old platforms" than anyone else? They seem to have vast resources and should actually be able to react quicker than others.

Best
-S

This is probably obvious, but the larger they get and the more "integrated" their system is (i.e. I'm thinking of the new level of system integration with Vista versions and above), the slower they're likely to be able to create correct fixes. I don't know this for a fact, but it seems as though the Windows system itself isn't terribly modular compared to other systems (Debian Gnu/Linux for instance) that have packages and dependencies. On a modular system focus can be placed on the "one package" that has a problem (if you can debug the issue down to the package level), but on a very integrated non-modular system where the source code itself is a guarded secret, that sounds like a difficult problem to deal with.

about 8 months ago
top

Microsoft Confirms It Is Dropping Windows 8.1 Support

Sipper Re:Wanna give up on these guys yet ? (575 comments)

At least it fails gracefully with a clean error code. In Linux world it would show up as a dialog with corrupted text and a mysterious "Invalid argument" error message written in some log. ;)

I wouldn't call "erorr 800F0092" to be a "clean" error code -- more like a bizarre confusing unintelligible error code. The errors in Linux can sometimes be frustrating too, or might even be hidden in a log like you pointed out, but they're never designed to be as unintelligible as many of the Windows system error messages are. On Windows there seem to be two kinds of error messages: ones for developers and ones for users; "error 800F0092" vs "check the cable", and there doesn't seem to be a whole lot in-between. At least on Linux systems you get a full range of them. ;-)

about 8 months ago
top

Microsoft Confirms It Is Dropping Windows 8.1 Support

Sipper Re:Bullet, meet foot (575 comments)

Or linux.

I wish that were so... unfortunately Windows still has the Desktop userbase majority by a wide margin, and that doesn't seem to be changing despite Microsoft's many steps towards making computer owners' lives more difficult. "Windows Genuine Advantage" that limits your ability to change hardware in a computer running Windows, licensing confusion concerning running Windows in a Virtual Machine, version confusion ("home", "professional", "enterprise", "ultimate", etc), UI confusion with Metro and the Office "banner"... and so on.

I wish Linux were "the answer" to this, but I've been running it on the Desktop since 1998 and I know it's not. A user trying to switch first has to go through a painful process of figuring out what programs they can use to do their daily tasks -- because they're not going to be running Internet Explorer or Outlook anymore, and the new programs have a different menu layout and (for the most part) different shortcut keys. If you've been working with a Linux desktop you've probably forgotten just how painful this transition was -- and it's not trivial. For people that are "stuck in their ways" and get anxious when they feel lost, this in itself is sometimes an insurmountable challenge.

Also the Linux ecosystem is very different, mostly relying on volunteer efforts with a few paid developers on the side. Being that this ecosystem represents less than 5% of the market, it's not an ecosystem that would be able to cope with the other 95%+ of the market suddenly needing support. And because it's mostly volunteers that help, users first need to figure out where to report issues (which isn't always easy), then there are issues concerning user demads vs helper pushback, sometimes leading to rudeness and communication breakdown, occasional elitism or ignoring problems, etc. It's "a different world" than Windows users are used to in that respect too.

And when you say "Or Linux", if the users given that advice knew to they'd ask "which one?" (i.e. which distribution?) Yeah... that problem too. Which window manager / desktop environment? That too. Etc.

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:If GNUTls is unneeded, then create a NO-OP libr (144 comments)

It is. There are many tools out there that implement it. It's the whole reason that we use CAs -- not that they're an ideal solution to the problem, but without some way to verify the authenticity of the public key you're using to bootstrap the key exchange, any PK-based key agreement protocol is subject to MITM attacks.

MITM can be an issue. More detailed information about the state of things at the link below.

https://wiki.exim.org/lurker/m...

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:If GNUTls is unneeded, then create a NO-OP libr (144 comments)

I feel like I'm spelling out the obvious, but: mail server A opens a TLS connection to mail server B to transfer mail, which starts with a TLS handshake, requiring B to send its public key A. The attacker intercepts the message and sends his public key to A, and completes the handshake with both sides, then proceeds to happily pass the data through reading all of it, since he has the session keys on both sides.

You've skipped over the PFS key exchange portion used in TLS.

https://en.wikipedia.org/wiki/...
https://en.wikipedia.org/wiki/...
https://en.wikipedia.org/wiki/...

Maybe the MITM exploit you're talking about is possible, I don't know.

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:If GNUTls is unneeded, then create a NO-OP libr (144 comments)

No, but I understand why you'd think this, as it seems to be a common misconception. If you have a specific example to illustrate this case, that would help.

MITM attack.

That's not a specific example related to TLS or encryption, it's a vague attack classification. The reason I'm asking the question is to find out if there is an actual issue, and so a vague answer like this cannot help our understanding any.

Oh well. OpenSSL apparently has a vulnerability too. sigh :-/

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:If GNUTls is unneeded, then create a NO-OP libr (144 comments)

And the reason I think that's true is that one isn't required to purchase a CA-signed certificate to get that working. If we all had to purchase a CA-signed certificate, I think it would become more rare to see TLS transfers to/from privately-held servers.

I think you're arguing that would be a bad thing, but in reality it'd be a nearly-irrelevant thing.

No. The word "reality" doesn't apply here, because what you're describing isn't what's being actually done for SMTP.

Without authentication, encryption protects only against the most casual of snoopers, most of whom wouldn't be able to sniff the packets anyway.

No, but I understand why you'd think this, as it seems to be a common misconception. If you have a specific example to illustrate this case, that would help.

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:If GNUTls is unneeded, then create a NO-OP libr (144 comments)

If what you say is true (and it probably is) then the state of e-mail security is even worse than I thought it was. Most mail providers don't support TLS anyway, but without authentication it doesn't really matter if they do.

Actually it's quite common for email providers to support TLS transfers today. And the reason I think that's true is that one isn't required to purchase a CA-signed certificate to get that working. If we all had to purchase a CA-signed certificate, I think it would become more rare to see TLS transfers to/from privately-held servers.

If you look at the mail headers for email you receive, you're likely to find "smtps" or "esmtps" in the Received: lines which indicates that it was sent via a TLS transfer. Most mailing list traffic is often done without TLS, though there are exceptions -- Debian's mailing lists still use TLS transfers, which is good.

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:Wow, that made it seem 10 times worse, thanks! (144 comments)

So tell me, why cant we have the parts we know are insecure issue a log each time they are run?

I understand what you're trying to get at; you'd like to have a log of the failure. However unfortunately that wouldn't tell you what you needed to know in this case; if you did have logging on this, the result you'd get would be "client authenticated" even though it was possible that the authentication actually didn't succeed. :-(

The unfortunate truth is that software bugs happen, and bugs that report success are harder to find than bugs that cause a failure.

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:If GNUTls is unneeded, then create a NO-OP libr (144 comments)

There are several places in which GnuTLS is used for encryption but not authentication such as MTA (email) transfers over TLS (at least most of the time).

Huh? Even for SSMTP, certificates can -- and must! -- be checked.

I think you mean ESMTPS. And no, usually TLS certificates are not checked by default (they can be, optionally); many TLS certificates used for ESMTPS are not signed by a CA, so there's nothing to check them against. There's also a new DANE protocol where domains that are using DNSSEC can specify TLS certificate details for mail in the DNS record for the domain, but this is currently not popular (supposedly only about 20 domains are using it). Other issues with this are that a number of DNS servers haven't implemented DNSSEC, and a number of MTAs haven't implemented the DANE protocol either.

And we don't want the situation where mail domains have to have thier TLS certificate signed by a CA, because that gets back into the mess of "which CAs are trustworthy" for mail purposes, paying fees for SSL certificate signatures, and so on. It's better to at least have encrypted email transfers than to only allow encrypted transfers from authenticated senders.

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:If GNUTls is unneeded, then create a NO-OP libr (144 comments)

Create a library with that name that does nothing, or logs errors for any entry points. Why is something being shipped that is insecure. I understand that the builds have to be changed. But the library could be replaced with a skeleton right now, can't it?
And maybe we would see that its not quite as in-active as people think.

There are two distinct part of SSL/TLS; encryption and authentication. In this case it's only the authentication portion that has an issue, not the encryption portion. There are several places in which GnuTLS is used for encryption but not authentication such as MTA (email) transfers over TLS (at least most of the time).

As for why GnuTLS exists, AFAIK it's mainly because of licensing issues -- compiling a GPLv2+ program against OpenSSL gets into licensing troubles, so there needed to be a GPL compatible alternative.

about 8 months ago
top

Not Just Apple: GnuTLS Bug Means Security Flaw For Major Linux Distros

Sipper Re:Old news (144 comments)

Most Linux distributions use OpenSSL for TLS. Even if a program links to GnuTLS, it may not use GnuTLS for certificate validation, and if it doesn't, then it's not affected by this bug (one example is Google Chrome). It's not like iOS where everything is required (by App Store rules) to use SecureTransport.

Another (non-issue) example is MTA (email) transfers; typically on Linux systems MTAs such as Exim use GnuTLS for TLS transfers, but purposely don't do certificate verification (but can be specifically configured to do so).

This is still a serious security issue for anything that does use GnuTLS for certificate verification of course, but off the top of my head I don't have a specific example of where this is done on the Linux platform. [There probably is an example to be found somewhere though.]

about 8 months ago
top

Doctors Say New Pain Pill Is "Genuinely Frightening"

Sipper Re:Higher potency? (294 comments)

Damn, that doesn't sound like much fun. Sorry you had to go through that. :(

No, definitely wasn't.

Thankfully I'm okay and I don't think I'm worse for wear. For a time I was worried that I might have gotten brain damage from it (I know a couple of people that got brain damage from high fevers), but after this happened I went back to college and was able to complete a masters degree in electrical engineering with a high GPA, so I think I'm fine. ;-)

about 10 months ago
top

Doctors Say New Pain Pill Is "Genuinely Frightening"

Sipper Re:Higher potency? (294 comments)

Thanks for the warning. I don't take it often enough to probably hit that. The ibuprofen dose is only 200mg, which is one OTC pill.

I pretty much take maybe 1 or 2 a week at most as needed, but they keep me out of the hospital or urgent care place so it's worth it.

(Annoys me that pain pills are hard to get for people who really need them because some people abuse them...)

I believe I was taking 2 200 mg pills every 6 hours for a full week straight. (Even if I had to get up in the middle of the night if necessary to take another 2 pills.) Unfortunately that's what it required to make the unbearable headache pain subside. I tried only taking 1 pill, that wouldn't cut it. I've never experienced a headache like that before or since.

Heat stroke also messes up your electrolytes too, so I had to eat bananas nuts and sports drinks for several days, during which everything tasted like metal until I got the electrolytes back. And during that time my face was still drooping from palsy, so drinking without spilling it out of my mouth onto my shirt was a challenge. I can look back on it now and laugh a bit, but at the time it was frightening. Also couldn't whistle, drinking from a straw was extremely difficult too because one side of my mouth couldn't close.

If you're only taking an Ibuprofin here and there I'm sure you won't run into what I did. ;-)

about 10 months ago
top

Doctors Say New Pain Pill Is "Genuinely Frightening"

Sipper Re:Higher potency? (294 comments)

I take Vicoprofen (for migraine pain). It's mixed with Ibuprofen instead of Tylenol. It still makes me sick all day after taking it. No idea why people abuse it.

For me it comes down to a choice between being in horrible agony all day or having no pain but stuck in bed feeling dizzy and like shit all day. I'll take that over the pain.

Now there may be some anti-nausea I can take to counteract some of the negative affects, but I haven't asked my doctor about that because the effects now ensure I won't abuse it and I don't want to know otherwise I guess.

I ended up having temporary facial palsy (i.e. half my face drooped and didn't work) after taking Ibuprofin for a week for severe headache pain related to heat stroke. I also felt dizzy and sick while taking the Ibuprofin, but the headache pain without meds was unbearable. After the headache pain from effects of heat stroke passed I was able to stop taking Ibuprofin, and a week later the facal palsy went away. I can't know for sure that the Ibuprofin caused the palsy, but some number of people that take Ibuprofin report having palsy from it.

The nastiest thing about the facial palsy was that on the side of my face that had the palsy the eyelid didn't "auto-blink" anymore, so the eye would get dry. It was especially noticable on long drives. To wet the eye I would have to consciously close both eyes at once -- for whatever reason that still worked. It's a bit mentally draining to have to constantly remember to close both eyes to wet them.

Hopefully you'll never run into this problem.

about 10 months ago
top

Ubuntu, Kubuntu 13.10 Unleashed

Sipper Re:"promised big changes" (143 comments)

...

I personally have run Arch+KDE4 for the past few years and have loved it. Why? Because it works for ME, and I can customize, adjust, etc. things just the way I want them, which is very likely unique to my needs and probably wouldn't be great for someone else to use. But that's the beauty of running Linux on the desktop, you can configure the 'appliance' for your specific need rather than be confined to what someone else thinks is the best way to run a GUI.

I'm mainly a Debian user, I'm also running Arch (in a VM, for Desktop use, with LUKS/cryptfs) and I'm very pleased with what I find with it so far. However one thing I do notice is that for Daemons, Arch upgrades seem to create ".pacnew" configuration files that sit alongside the original configuration files and outputting a warning, somewhat similar to how RPMs upgrade with ".rpmnew" files. I don't particularly like that -- I much prefer the prompts for administrator input that the APT/dpkg system brings up when .deb packages are upgraded that have user-modified configuration files. It's way too easy to miss the text warning that flies by on the screen saying there's a ".pacnew" file somewhere during a "pacman -Syu" upgrade.

about a year ago

Submissions

Sipper hasn't submitted any stories.

Journals

Sipper has no journal entries.

Slashdot Login

Need an Account?

Forgot your password?