Apple Releases CUPS 2.0

cmdrbuzz Re:I hope... (178 comments)

Just curious, what would be your favorite (laser) printer?

about 2 months ago

Ask Slashdot: Is Running Mission-Critical Servers Without a Firewall Common?

cmdrbuzz Re:Common? (348 comments)

With PCI you'd still need a host firewall. Daft but thats just how the "tickbox auditing" happens.

We have a DB host connected via FICON to the mainframe, and the DB box only has a FICON adaptor and the cable goes from mainframe => DB, not even via a switch.

We still needed a host firewall to comply with PCI and it wasn't worth arguing over that it was pointless, we did it anyhow. Admitted we are a large financial services company, but the rules apply across the board.

about 5 months ago

Google To Stop Describing Games With In-App Purchases As 'Free'

cmdrbuzz Re:Apple has 'done nothing'??? (139 comments)


The "Purchase app" within 15 minutes without re-prompting for a password (which is configurable) is a separate 15 minute timer to the "In-App purchase" one.

And you can easily set "ask for password for each purchase" in the settings, along with "disable in-app purchases"

about 4 months ago

IT Pro Gets Prison Time For Sabotaging Ex-Employer's System

cmdrbuzz Re:Duh... (265 comments)

To be honest, if my son was kidnapped, I'd do everything I possibly could to find him.

Anyone that says "You call your lawyer first", cannot possibly have children, or if they do, really need their priority sorting out!

Only thing that matters is finding your kid as fast as physically possible. If that means the police/FBI/whoever want to strip-search me to prove I had nothing to do with it, or search my house or whatever, I wouldn't care. Do whatever and however it takes to find my kid!

And I'm so, so sorry you and your family had to go through that. Holy cow, I cannot even begin to think how hard that must be.

about 7 months ago

You've Got Male: Amazon's Growth Impacting Seattle Dating Scene

cmdrbuzz Re:We need to fix the root cause (315 comments)

Totally agree, one of my younger sisters was /all/ about pink, princesses and fluffy girly things all the way when growing up.

She very recently graduated with her Masters degree as a Civil Engineer.

about 7 months ago

Microsoft Cheaper To Use Than Open Source Software, UK CIO Says

cmdrbuzz Re:Translation (589 comments)

Thats weird, because I work for a FTSE 100 financial services company and we had a few little issues when nearly 72,000 members of the public attempted to use our online services at the same time, when our usual concurrent volume is around 4,500.

We planned for a "worse-case" of 50,000 concurrent trades, but our system DDOS-ed itself at around 71,000 (gotta love fast-switch cluster failover, and back, and over, and back... Oracle FTW!!!)

Anyhow, before we could even think to phone Oracle and shout that our newest 1.2 million pound server wasn't handling particularly well, the head of Oracle UK phoned /us/ and offered us a team of their best engineers to help get us fixed.

I'd have thought we'd be smaller than a US gov agency, but hey ho, Oracle (plus Cisco, Juniper and EMC) parachuted people straight in, nothing too much to help.

Admittedly now we have bought a lot more kit, but they weren't to know that we'd do that considering the failure.

about 7 months ago

OpenBSD 5.5 Released

cmdrbuzz Heartbleed not fixed in 5.5 by default (128 comments)

Just an FYI, heartbleed is not fixed in 5.5 without extra (source) patches.

See http://www.openbsd.org/errata5...

  002: SECURITY FIX: April 8, 2014 All architectures
Missing bounds checking in OpenSSL's implementation of the TLS/DTLS heartbeat extension (RFC6520) which can result in a leak of memory contents.
A source code patch exists which remedies this problem.

about 8 months ago

Microsoft Issues Advisory For Internet Explorer Vulnerability

cmdrbuzz Re:IE6 (152 comments)

Yes, technically under Windows 2003 (Server) IE6 is "supported". Still sucks as a browser though.

about 8 months ago

Not Just a Cleanup Any More: LibreSSL Project Announced

cmdrbuzz Please change the name! (360 comments)

LibreSSL.... Please for the love of code, change the name!

about 8 months ago

Romanian Bitcoin Entrepreneur Steps In To Pay OpenBSD Shortfall

cmdrbuzz Re:There is always that *one* guy... (209 comments)

Then you'd be wrong.

Ever seen a Juniper switch, router, firewall?
How about a Citrix NetScaler?
Or maybe a NetApp filer?

BSD is inside a hell of a lot of kit, unless you work inside your mothers basement then chances are, you've seen BSD production systems.

about a year ago

MasterCard Forcing PayPal To Pay Higher Fees

cmdrbuzz Re:This woudl be ok, but... (260 comments)

PayPal have already tried the credit card thing, not that popular it seems.

That and they'd have to set up their own payment network to avoid MasterCard and VISA, or convince AMEX to carry them...

about a year and a half ago

Apple Posts Non-Apology To Samsung

cmdrbuzz Re:Contempt of Court (413 comments)

Its not contempt of court when you do what the court ordered.

And ordering Apple to say that Samsung didn't copy them when 2 other court cases (and anyone that has ever looked at their product) say different is a little rich.

more than 2 years ago

Apple Posts Non-Apology To Samsung

cmdrbuzz Re:This clearly goes against the ruling (413 comments)

If you are reducing this to getting your child to apologize, then the moment Samsung apologize for copying and free-riding from the work of Apple, /then/ you can start looking for Apple to back down.

more than 2 years ago

Apple Posts Non-Apology To Samsung

cmdrbuzz Re:The court didn't ask for an apology... (413 comments)

I'd suggest you re-read the Court's wording. It matches /exactly/ with Apple's notice.

Then underneath the Court's mandated wording, Apple have repeated some facts. It says quite a bit about your bias that you seem to resent the facts they quoted...

more than 2 years ago

Apple Posts Non-Apology To Samsung

cmdrbuzz Re:The court didn't ask for an apology... (413 comments)

Why don't you repeat all the ways they didn't comply? I cannot see anything that they did not comply with.

And whilst Apple may be hated by you, the rest of us grown-ups realize that all companies are good and bad and Apple are just reacting to Samsung copying a design that Apple popularized. That and Samsung trying to gouge other companies using FRAND patents.

more than 2 years ago

Poor SSL Implementations Leave Many Android Apps Vulnerable

cmdrbuzz Re:The certificate is not the problem; IPv4 is (141 comments)

Without SNI you can only have one certificate per IP address as the certificate is sent to the client before the client can send the Host: header to indicate which site he is trying to access.

The only way around this (apart from using SNI) is either wildcard certs or SAN attributes.

Once the server has sent the certificate the client will check to see if the certificate matches the DNS name it is attempting to access (either CN or SAN), however this is done by the client without the server knowing which DNS name the client is looking for. Hence the SNI requirements.

more than 2 years ago

UK Government Owns 16.9 Million Unused IPv4 Addresses

cmdrbuzz Re:Sell the Addresses? Don't Give Them Ideas (399 comments)

You do realize that DWP were assigned the addresses by IANA before RIPE even existed!

RIPE have no ability to take these IP addresses back as they have no contractual agreement with DWP.

more than 2 years ago

Why Are Operating System Version Names So Absurd?

cmdrbuzz Re:Easy (460 comments)

You have confused the solaris examples a little.

The 5 is the version of SunOS and Solaris started at version 2 (The SVR 4 version of SunOS) with Solaris 1 retroactively meaning SunOS 4.

So Solaris 2.4 is SunOS 5.4, then after 2.6 SUN dropped the 2.x bit to leave Solaris 7 (which is SunOS 5.7) and Solaris 8/9/10/11 being SunOS 5.8/5.9/5.10/5.11 etc.

more than 2 years ago

DOJ Says iPhone Is So Secure They Can't Crack It

cmdrbuzz Re:I don't believe it (454 comments)

It doesn't need to prompt before booting as it will only decrypt sensitive files once the passcode has been input. It is able to boot and connect to the cell towers without needing your passcode, however to get access to *your* data on the phone, it will need the passcode to get access to the decryption key and thus the files.

more than 2 years ago


