Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Comment Re:Disclosure Process (Score 1) 73

Yes, there is a "master list" - as I mentioned, its primarily the hyperscalers and OS vendors. That's how I got pulled in personally, it was one of the F/OSS OSes that wanted some insights into a particular CPU architecture where I had expertise plus a full testing lab to do all the validation testing quickly.

Comment Disclosure Process (Score 4, Interesting) 73

"Telcos likely received advance warning"

Yes, there is a semi-secret mailing list of organizations that are informed of CVEs before public disclosure. Without being on the inside of this particular vulnerability, I can say with 99% certainty that this is indeed the case.

I was brought on as a contractor to help evaluate one of the "sudo" privilege escalation attacks years ago, to test it on a number of platforms. I had about one to two weeks advanced notice of the CVE before it went public to help evaluate potential risk, which is where the "scores" come from. Note, in this context, a platform is more than just a single vendor or single OS, I was brought on as the subject matter expert for a particular CPU architecture and F/OSS operating system combination to see if the exploit was valid there as well. Testing required seeing if the same exploit worked across OS revisions, patch levels, CPU architectures, and comparing it to other OSes with similar hardware configurations.

There is a whole community behind the scenes of people who are deeply passionate about security doing this work behind closed doors. Many of these people are industry professionals at the hyper-scalers and OS vendors (both open and closed source) and push out patches there first before anything goes public.

Comment "TikTok" (Score 2) 36

Yes, "TikTok" (the application not controlled in the USA) is the problem, but not anything from Google/Alphabet (YouTube), or Meta (Facebook/Instagram/Threads), or "X" (Twitter), or the multitude of other platforms all with USA centric interests.

Yes, I realize other platforms are listed way WAY down in the article, but seriously, count the number of times TikTok is referenced compared to any other platform.

Comment OTA TV (Score 1) 186

Ahhhh yes, I'm "stealing" the freely available over-the-air digital TV signals available here in the Seattle area. Darn those pesky corporations producing pirate airwaves that anyone and everyone can freely tap into with their TV or a box like HDHomeRun! Absolutely horrible.

Comment Content (Score 2) 138

broadcast tv is still shit-tier bitrate 1080p (or even sometimes 720p/1080i still). streaming platforms are marginally better bitrate, but still rarely even have 4k content. there are 4k blu-ray movies. but honestly, im not sure i've seen any 8k content ANYWHERE!? im sure if i explicitly search for it, i can find it, but the casual content around me is 4k or lower.

and beyond that, we're also at the point of diminishing returns. we're at the point where the production cost of the convent vs the demand makes "no sense" from the business side of things. the extra storage, extra bandwidth, extra processing for 8k content is quite significant, and the market demand for it is near-zero. its an e-penis pissing competition to brag that you got 8k content rather than an otherworldly better experience. in the real world, it is a marginal perceptual increase in quality, compared to something like better HDR spec has a much larger noticeable increase in the overall experience.

mind you, i'm saying this as a super geeky person who would absolutely fucking LOVE to have a high refresh rate 8k monitor for my primary workstation.

Comment Re:who's using C ? (Score 2) 187

the rankings are fucking bullshit, no matter which language you think should be top or bottom.

their "metric" is "we went to google, and used google's estimated number of pages referencing this language"

that's it. that's the entire fucking index. google de-listed a fuckton of older pages on the internet. google changes their algo all the time. this "popularity" contest has absolutely fucking nothing to do w/ actual usage, and is entirely at the whims of google's day to day enshitification of their search engine results.

Comment Re:Microsoft writing off "air gapped computers"? (Score 5, Informative) 99

I'm guessing you don't know all the ways to activate Windows then.

Standard Windows keys require Microsoft for activation. MAK (multi-activation keys) also require MS. However, KMS (Key Management Service) however does not. KMS uses a locally controlled server for activation. This is quite common in large organizations that deal with a high quantity of machines (think fortune 500 orgs w/ 100k+ employees w/ laptops). This would of course also cover the military. Do you think the DoD was using phone activation this entire time for their air-gapped machines? No, they have the private DoD network w/ this type of infrastructure (at least, this is my assumption)

Comment "Not Invented Here" Syndrome (Score 4, Interesting) 233

How may different compatibility deployments are there for IPv6?

6in4? 6to4? 6RD? NAT64, 6over4? Teredo?

Think any of those are fake names? Try again!

And that's just ONE piece of IPv6. Practically everything in the "spec" has at least 2 variants minimum, and its just a royal clusterfuck. When it is described as "protocol by comity", this is exactly the result, and its been a total pain in the ass to have anything reliable at scale.

You may be on one of the lucky ISPs that has a sane deployment and want to reply with "Well, it works for me!" - that's awesome, and I wholeheartedly mean it. That IS really awesome! But for the rest of us dealing w/ multiple ISPs in multiple regions, its a fucking shitshow to get anything reliable going consistently.

One IPS I deal with about 18 months ago entirely dropped IPv6 "support" - and now we can pull a single /128 address with no routing table at all. So we have an address that is entirely fucking useless, instead of having a normal block allocation which it was previously. Another ISP I deal with still uses PPPoE, and then uses 6RD over that, so the MTU is trash because both reduce the MTU size.

IPv6 is a fucking mess, and it pisses me off every day!

Comment Calculator In Your Pocket (Score 2) 39

"You won't be walking around with a calculator in your pocket all day when you're an adult!" - teachers in the 90's and earlier.

"NO, you can't have a global communications network with the sum of all human knowledge attached to a tiny super computer in your pocket!!!!!" - teachers today

Slashdot Top Deals

You are false data.

Working...