Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
Bug

HTML5 Storage Bug Can Fill Your Hard Drive 199

Dystopian Rebel writes "A Stanford comp-sci student has found a serious bug in Chromium, Safari, Opera, and MSIE. Feross Aboukhadijeh has demonstrated that these browsers allow unbounded local storage. 'The HTML5 Web Storage standard was developed to allow sites to store larger amounts of data (like 5-10 MB) than was previously allowed by cookies (like 4KB). ... The current limits are: 2.5 MB per origin in Google Chrome, 5 MB per origin in Mozilla Firefox and Opera, 10 MB per origin in Internet Explorer. However, what if we get clever and make lots of subdomains like 1.filldisk.com, 2.filldisk.com, 3.filldisk.com, and so on? Should each subdomain get 5MB of space? The standard says no. ... However, Chrome, Safari, and IE currently do not implement any such "affiliated site" storage limit.' Aboukhadijeh has logged the bug with Chromium and Apple, but couldn't do so for MSIE because 'the page is broken" (see http://connect.microsoft.com/IE). Oops. Firefox's implementation of HTML5 local storage is not vulnerable to this exploit."

Comment Re:Nokia E70 (Score 1) 374

Yup. Very nice device for ssh use. Software still has a few bugs (== random reboots), which aren't getting fixed. The navikey joystick thing also breaks quite easily (I'm currently on my third E70 in 18 months, fortunately the warranty is two years :) ).
Still, it has a real keyboard and the screen is big enough for a reasonably sized terminal (with a smallish font, but I have good eyes ;) ). Means I don't _have_ to carry a laptop around.
Communications

Single Photons Bounced Off Orbiting Satellite 131

KentuckyFC writes "If we're ever going to benefit from the perfect security of quantum communication, we're going to need ways of transmitting entangled photons around the globe and certainly further than the current record of 144km through the atmosphere. Anton Zeilinger at the University of Vienna and colleagues have taken an important step towards this by bouncing individual photons off the Ajisai geodetic satellite (essentially a space-based disco ball) which is orbiting at 1400km. The group says the experiment is an important proof of principle for satellite-based quantum communications."
Security

Submission + - Archive Formats Kill Antivirus Products 2

nemiloc writes: From F-Secure website: "The Secure Programming Group at Oulu University has created a collection of malformed archive files. These archive files break and crash products from at least 40 vendors — including several antivirus vendors...including us." It is not new anymore that security producs have have security problems... What makes this special is that antivirus software is a perfect target. They are run on critical places with high privileges and autoupdates keeps versions coherent. More information: Test material by OUSPG and Joint advisory by CERT-FI and CPNI

Slashdot Top Deals

When the bosses talk about improving productivity, they are never talking about themselves.

Working...